ACE30: Connectivity between IP subnets on the same VLAN being NATed?
We have a subnet setup on the ACE as follows:
interface vlan 300
description CALLISTA Environment
ip address 2001:388:608c:8b8::fffd/64
peer ip address 2001:388:608c:8b8::fffc/64
ipv6 nd ra interval 30
ipv6 nd prefix 2001:388:608c:8b8::/64
ip address 126.96.36.199 255.255.255.192
ip dhcp relay server 188.8.131.52
ip dhcp relay server 184.108.40.206
alias 220.127.116.11 255.255.255.192
peer ip address 18.104.22.168 255.255.255.192
ip address 22.214.171.124 255.255.255.224 secondary
alias 126.96.36.199 255.255.255.224 secondary
peer ip address 188.8.131.52 255.255.255.224 secondary
access-group input ALLOW
access-group input ALLOWv6
access-group output ALLOW
access-group output ALLOWv6
nat-pool 1 172.16.25.231 172.16.25.231 netmask 255.255.255.255 pat
There is the primary subnet 184.108.40.206/26 and the secondary IP subnet 220.127.116.11/27
The nat-pool is configured to allow server initiated connections to their frontend VIP when necessary.
We are noticing that when a server on the 18.104.22.168/27 subnet needs to communicate with a server on 22.214.171.124/26, albeit on the same VLAN, the destination server sees connections with a source IP of 172.16.25.231, which is the NAT address. Is this expected behavior, where connections between IP subnets, albeit on the same VLAN are NATed?
Introduction This article will help you understand the steps on how to
download the UCS licenses from the Cisco Systems website and then
installing it on the UCS. The redacted (blue lines) just covers up
certain numbers for privacy please do not take them...
Introduction This article will help you understand and educate the
customer on how to clear their "expired licenses"
(license-graceperiod-expired) from their UCS-M. If a customer just
purchased a license and needs a step by step guide on how to download
Introduction Prepositioning is a powerful tools on the WAAS platform but
it is not always easy to figure out why your jobs are failing when
trying to retrieve the files.Here is a method that should help you to
figure out the reason why they are not succes...