New Member

NAT question

I am thinking hard to find a suitable solution, but did not figure out yet.

thanks in advance for your input.

my diagram like T1 link-----R2-----application servers servers

traffic from to application servers (like www etc) should go T1 first

if T1 is unavailable, traffic from will go to VPN between FW1 and FW2, however, must be translated to and application servers' IP must be changed as well. (so VPN interesting traffic is from to

e.g, while using T1 link, one application server, server1(IP is, server2( while using VPN link, application server still is server1, but IP is, server 2 will be etc

I am looking for an automatic failover solution.

also, we don't have any DNS server internally, so using hosts file now, your suggestion for any DNS solution is appreciated as well

thank again

New Member

Re: NAT question

Here are my first thoughts.

On the router R1 have two static routes. The first is

ip route {ip of r2}

the second is

ip route {ip of FW1} 200

This makes the first route the preferred one, unless the T1 is down and then it sends the traffic to the firewall. The firewall then needs to be configured to do the NAT translations as needed for both source and destination addresses (if these are PIX or ASA that is fairly straightforward to achieve).

DNS is an application, I do networks (only L1 to L4) :-)

Hope that helps.

