I have two CSS configured with an external VLAN and a public redundant-vip. I also have an internal VLAN with private subnet and servers directly connected, CSS have a redundant-interface on this side.
My servers are dual-homed and their default gateway doesn't point to the redundant-interface.
Using source destination group, I'm able to NAT the source IP of ingress traffic to the redundant-vip address, in order to get the reverse traffic back through the CSS'. But this is not the behavior I want.
I would like the source IP for ingress traffic to be translated to the redundant-interface's IP (the CSS private address) so that the servers reply back to this address that is in the same subnet.
Is this possible?
Thanks in advance.