ACE; Dynamic SNAT in bridge mode without Dnat (VIP) needed

Answered Question
Feb 20th, 2008
User Badges:

Hi,

We are interested about the ACE NAT performance. We would like to use this module just for the SNAT feature and only in bridge mode (to facilitate the ACE integration in the current network).

the configuration could be similar to this one:

--

class-map PrivateSource

match source-address 10.0.0.0 255.0.0.0


policy-map multimatch SourceNat

class PrivateSource

nat dynamic 1 vlan X


interface vlan X (incoming traffic from the source)

bridge-group 1

service-policy in SourceNat

nat-pool 1 publicIP netmask A.B.C.D pat


interface vlan Y

bridge-group 1

--

Could anyone confirm if this feature is supported on the ACE and if the above configuration could be a good one?

--

Many thanks for your help.

Regards/Ludovic.

Correct Answer by Gilles Dufour about 9 years 2 months ago

Ludovic,


ACE does not NAT bridged traffic.

You could catch it with a catch-all-destination class-map


ie:


class-map all

match virtual 0.0.0.0 0.0.0.0 any


And use a transparent serverfarm sending all traffic to a unique default gateway.


That would work.


Gilles.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Gilles Dufour Wed, 02/20/2008 - 03:46
User Badges:
  • Cisco Employee,

Ludovic,


ACE does not NAT bridged traffic.

You could catch it with a catch-all-destination class-map


ie:


class-map all

match virtual 0.0.0.0 0.0.0.0 any


And use a transparent serverfarm sending all traffic to a unique default gateway.


That would work.


Gilles.

loudo Wed, 02/20/2008 - 04:45
User Badges:

Many thnaks Gilles, We will do as you suggested.

Regards/ludovic.

Actions

This Discussion