03-11-2007 07:51 PM
Hi all
I have my CSS's located behind firewalls on a private subnet. The firewall is performing NAT for external translations to my VIPs. I am implementing GSLB for failover and want to know if it is possible to do this with this configuration or if I need to have the VIP's configured with public IP addresses. How will the CSS present the DNS responses if the CSS in behind a firewall?
Thanks
03-12-2007 01:29 AM
your firewall must do dns fixup in order to translate the dns response.
The CSS will respond with the private address.
All Cisco firewalls come with the nat fixup function.
Gilles.
03-12-2007 03:22 AM
Thanks Gilles. That makes sense.
D
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide