cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
528
Views
0
Helpful
1
Replies

(ACI MSO) NAT In FW

George-Sl
Level 1
Level 1

image.png

If we're not doing the NAT with those firewalls(at each site), this scenario would be very easy to be implemented, my questions is about the traffic steering that's supposed to be happening to the appropriate compute leaf, how can that be accomplished for the traffic returning from external EPG(internet), with a destination that's NATed previously(fabric isn't aware of that ip space), in other word destination of the returning traffic is not the same as the outside interface of the FW neither the inside epg.

Thanks

1 Reply 1

jiarchen
Cisco Employee
Cisco Employee

Hi, George 

With your question I suppose you wanted to asked about scenarios when Destination NAT happend on FW for Multi-Site with changing of EPG,contract, etc. Checked some materials that suppose DNAT is not currently supported since everything has changed on its way back.   
If you wanted to know more about the PBR with Multi-Site, below materials would be helpful. 

https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-743107.html#Introduction

 

------------

If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.

You can also learn more about Cisco ACI through our live Ask the Experts (ATXs) session. Check out the ATXs Resources [https://community.cisco.com/t5/data-center-and-cloud-knowledge/cisco-aci-ask-the-experts-resources/ta-p/4394491] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Save 25% on Day-2 Operations Add-On License