I have two design questions that I would like to get answered if at all possible. I don't need config help but just an understanding of how this is accomplished.
In an enterprise network that consists of direct internet access at the corporate or main location with multiple branch offices and remote locations whose traffic has to come back to corporate before going to the internet, how is layer 2 trunking and VLANs supported?
How do I get a vlan at the corporate office to reside at a branch location while traversing several routers over L3? Say I needed one port on a switch at the branch office to be the 'Public' VLAN because they wanted to place a public facing server there. Or, I wanted to extend a management VLAN across the entire network. How is this accomplished across the routers?
This brings me to my next question on NAT. Please refer to the diagram. I have a firewall that NAT's traffic for public servers residing on the inside interface. Say I have a private WAN that connects a remote location that is accessible from internally only? How would I NAT a public address to a server that doesn't reside on the inside network? Is it possible?
As for the NAT, not quite sure i fully understand. You can NAT any private address to a public IP address. As long as that private address is reachable from the firewall and the firewall is reachable from the private address it doesn't matter how many routers/switches etc. are between the firewall and the private address.
Thanks for the info. As for extending VLANs across a routed network, I thought it was simpler than that and that I was just missing something. Are there other tactics that enterprises would use or do they just generally not extend VLANs through the organization?
As for NAT, I assumed that the address on the private side of the firewall had to be attached to the inside interface. It sounds like it just has to be pingable though and it should work.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...