An Azure network security service that is used to protect Azure Virtual Network resources.
Autoscale won't help here, and that's the main thing worth knowing. Scale-out doesn't key on SNAT at all. From Azure Firewall performance: "Azure Firewall gradually scales out when the average throughput and CPU consumption reach 60% or if the number of connections usage reaches 80%. Scale out takes five to seven minutes."
SNAT utilization isn't in that list. The monitoring reference says: "when the firewall scales out for different reasons (for example, CPU or throughput) more SNAT ports also become available." Extra ports are a side effect of scaling, not a response to running out of them.
So to your four questions: no, high SNAT utilization alone won't trigger a scale-out. Yes, instances multiply capacity, since the allocation is per instance: "Azure Firewall provides 2,496 SNAT ports per public IP address configured per backend virtual machine scale set instance (Minimum of two instances), and you can associate up to 250 public IP addresses." And yes there's a lag of five to seven minutes, but only once something other than SNAT crosses its threshold.
Worth knowing what exhaustion actually does, because it isn't a hard cliff: "If SNAT ports are used more than 95%, they're considered exhausted and the health is 50% with status=Degraded and reason=SNAT port. The firewall keeps processing traffic and existing connections aren't affected. However, new connections might not be established intermittently."
Both documented fixes are deliberate rather than automatic. Add public IP addresses, each worth 2,496 ports per instance, or put a NAT gateway in front: "Use a NAT gateway when you need dynamic SNAT port allocation across the subnet. It provides up to 64,512 SNAT ports per public IP address." The NAT gateway also allocates dynamically across the subnet rather than fixing ports per instance, which suits spiky traffic better.
For finding what's consuming the ports, enable the Top Flows log. It "shows the top connections that are contributing to the highest throughput through the firewall", it's off by default and turned on through PowerShell, and it lands in the AZFWFatFlow table with source IP, destination and port. That gets you the "which VM, which destination" answer directly.
Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.