Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

CSS Natting

Is there any way to NAT all traffic comming from the server to the VIP address on a CSS 11500?

Basically my client wants to send out emails and FTP data from the server behind the CSS on the same IP as the incoming web traffic, however on the ASA I can only NAT the external IP to one address. I need to make sure that the traffic from the servers is natted to the VIP prior to sending to the ASA to allow correct nating.

Cheers,

Scott

1 ACCEPTED SOLUTION

Accepted Solutions
New Member

Re: CSS Natting

Create a source group:

group xyz

vip address a.b.c.d

add service svr1

add service svr2

active

The source group VIP can match the VIP in a rule. If you need source NAT'ing for clients hitting rules, then use "destination services" in a group. You still need regular [source] services in a group for NAT'ing when servers initiate connections.

1 REPLY
New Member

Re: CSS Natting

Create a source group:

group xyz

vip address a.b.c.d

add service svr1

add service svr2

active

The source group VIP can match the VIP in a rule. If you need source NAT'ing for clients hitting rules, then use "destination services" in a group. You still need regular [source] services in a group for NAT'ing when servers initiate connections.

206
Views
0
Helpful
1
Replies
CreatePlease login to create content