<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Services with different IP address subnets over CSS 11500 se in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674077#M33737</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Esteban,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing wrong with this topology, it will work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, there is one thing you need to take into account. You need to make sure that the traffic from the servers back to the clients is going through the CSS so tha the NAT from the real server IP to the content rule IP can be done. If traffic goes back to the clients directly, connections will break.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a few ways to achieve this, some more complicated than others, but the most common ones are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use policy-based-routing to send the traffic to the CSS. In this case, however, since there are two hops between the servers and the CSS, you would have to configure PBR on each of the FW, which can become a bit messy&lt;/LI&gt;&lt;LI&gt;Configure the CSS to apply NAT to the client IP by using a source-group. This way, the servers would see the request as coming from an IP owned by the CSS, so they would just need a route back to it. &lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 May 2011 07:15:23 GMT</pubDate>
    <dc:creator>Daniel Arrondo Ostiz</dc:creator>
    <dc:date>2011-05-13T07:15:23Z</dc:date>
    <item>
      <title>Services with different IP address subnets over CSS 11500 series</title>
      <link>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674076#M33736</link>
      <description>&lt;P&gt;Hi all folks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two CSS 11500 series...&lt;/P&gt;&lt;DIV class="txtDiv border3d" id="targetTxt" style="text-align: left; direction: ltr;"&gt;In just a few months i will have ready a DRS (Disaster Recovery Site), where i will have 2 more servers to add to the environment.&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;But this servers will be in a different subnet from that today i have for the servers who are configured in the current services of my CSS.&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;So then the doubt i arises is:&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;Is correct to add two new services with these servers, but using the IP addressing of the DRS site???, and including on the CSS a static route to this network, (of the DRS) in order to reach them?? is it correct, it will work well?&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" id="targetTxt" style="text-align: left; direction: ltr;"&gt;This would be so....&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;P class="txtDiv border3d"&gt;&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ________________LAN to LAN_____________________&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;|------SITE A------|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |------SITE B------|&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [Firewall] ===============IPSEC============= [Firewall]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;[CSS-A]-[CSS-B]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [SWITCH]&lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="text-align: left; direction: ltr;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [SWITCH]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;[srvA] [srvB] [srvC]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [srvD] [srvE]&lt;/P&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;So, at [CSS-A] &amp;amp; B, i will put a static route to firewall that know the subnet of site B through the IPSEC tunnel.&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;So In the CSSs, i will add the new services for the Servers "D" &amp;amp; "E" with the IP address of Site B.&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;DIV class="txtDiv border3d" id="targetTxt" style="text-align: left; direction: ltr;"&gt;This should be seen as well:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;!*************************** GLOBAL ***************************&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;ip route 0.0.0.0 0.0.0.0 [IP FIREWALL]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;ip route SITE B [IP FIREWALL]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;!************************** SERVICE **************************&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;service srvA &lt;BR /&gt;&amp;nbsp; ip address A.A.A.x &lt;BR /&gt;&amp;nbsp; port 8080 &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;service srvB&lt;BR /&gt;&amp;nbsp; ip address A.A.A.x+1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;&amp;nbsp; port 8080&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;service srvC&lt;BR /&gt;&amp;nbsp; ip address A.A.A.x+2&lt;BR /&gt; port 8080&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;service srvD&lt;BR /&gt;&amp;nbsp; ip address B.B.B.y&lt;BR /&gt; port 8080&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;service srvE&lt;BR /&gt;&amp;nbsp; ip address B.B.B.y+1&lt;BR /&gt;port 8080&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;****************************************************************&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;I know that this practice is not the most desirable, in fact should use"Basic Global Server Load Balancing Site Redundancy Using the CSS with DNS&lt;!--googleoff: index--&gt;&lt;!--googleoff: snippet--&gt;", but I don't have much time to change the entire environment today, and in this first stage i have to begin with this poor but quick solution that i thought and i wanted to be validated if there is posibliidades this to work&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;&lt;DIV class="txtDiv border3d" id="targetTxt" style="text-align: left; direction: ltr;"&gt;Within their experiences that they say? Will operate?&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;Thanks in advance!&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;Regards!&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;Esteban &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;</description>
      <pubDate>Thu, 12 May 2011 19:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674076#M33736</guid>
      <dc:creator>estebanpini</dc:creator>
      <dc:date>2011-05-12T19:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Services with different IP address subnets over CSS 11500 se</title>
      <link>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674077#M33737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Esteban,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing wrong with this topology, it will work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, there is one thing you need to take into account. You need to make sure that the traffic from the servers back to the clients is going through the CSS so tha the NAT from the real server IP to the content rule IP can be done. If traffic goes back to the clients directly, connections will break.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a few ways to achieve this, some more complicated than others, but the most common ones are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use policy-based-routing to send the traffic to the CSS. In this case, however, since there are two hops between the servers and the CSS, you would have to configure PBR on each of the FW, which can become a bit messy&lt;/LI&gt;&lt;LI&gt;Configure the CSS to apply NAT to the client IP by using a source-group. This way, the servers would see the request as coming from an IP owned by the CSS, so they would just need a route back to it. &lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 May 2011 07:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674077#M33737</guid>
      <dc:creator>Daniel Arrondo Ostiz</dc:creator>
      <dc:date>2011-05-13T07:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Services with different IP address subnets over CSS 11500 se</title>
      <link>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674078#M33738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel!&lt;/P&gt;&lt;P&gt;Sorry by delay!&lt;/P&gt;&lt;P&gt;Thank you so much for you time for reply.&lt;/P&gt;&lt;DIV class="txtDiv border3d" id="targetTxt" style="text-align: left; direction: ltr;"&gt;You have given me a great help to this doubt!&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;But..using "source group" let me know..&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;I can´t undertand the really difference between NAT with ACls as you can see at this link: (&lt;A href="http://www.cisco.com/en/US/products/hw/contnetw/ps789/products_tech_note09186a0080093dfc.shtml"&gt;http://www.cisco.com/en/US/products/hw/contnetw/ps789/products_tech_note09186a0080093dfc.shtml&lt;/A&gt;)&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;and&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;this other link, using NAT (from the piont 5), (&lt;A href="http://www.cisco.com/en/US/products/hw/contnetw/ps789/products_configuration_example09186a0080093dff.shtml"&gt;http://www.cisco.com/en/US/products/hw/contnetw/ps789/products_configuration_example09186a0080093dff.shtml&lt;/A&gt;)&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;where the NAT is configured under a method different from the previous one..&lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt; &lt;/DIV&gt;&lt;DIV class="txtDiv border3d" style="text-align: left; direction: ltr;"&gt;So.. for this scenario described above, which would you recommend using? I would think that the second is the most indicated truth? What do you think?&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance again!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have nice day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Esteban.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 16:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674078#M33738</guid>
      <dc:creator>estebanpini</dc:creator>
      <dc:date>2011-05-17T16:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Services with different IP address subnets over CSS 11500 se</title>
      <link>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674079#M33739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Esteban,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both are perfectly valid methods. The main difference is that, if you use ACLs to specify the NAT, you have a lot more granularity, because you can define different NAT configurations based on combinations of source/destination IP addresses. As a drawback, it's also more cumbersone to configure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With normal source groups, you can just define the NAT address to be used based on the server to which the connection is going to be sent to. This is more limited in terms of possibilities, but it's also much easier to configure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your setup, I don't think you need any complicated NAT configuration, because you are just trying to send the return traffic back to the CSS, so I would recommend you to just use source groups for the configuration, forgetting completely about the ACLs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 10:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/services-with-different-ip-address-subnets-over-css-11500-series/m-p/1674079#M33739</guid>
      <dc:creator>Daniel Arrondo Ostiz</dc:creator>
      <dc:date>2011-05-19T10:20:15Z</dc:date>
    </item>
  </channel>
</rss>

