cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
375
Views
0
Helpful
2
Replies

GSLB with CSS behind a firewall

davidbuit
Level 1
Level 1

Hi all

I have my CSS's located behind firewalls on a private subnet. The firewall is performing NAT for external translations to my VIPs. I am implementing GSLB for failover and want to know if it is possible to do this with this configuration or if I need to have the VIP's configured with public IP addresses. How will the CSS present the DNS responses if the CSS in behind a firewall?

Thanks

2 Replies 2

Gilles Dufour
Cisco Employee
Cisco Employee

your firewall must do dns fixup in order to translate the dns response.

The CSS will respond with the private address.

All Cisco firewalls come with the nat fixup function.

Gilles.

Thanks Gilles. That makes sense.

D