cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
547
Views
0
Helpful
1
Replies

ACE one arm mode issue

parveesm123
Level 1
Level 1

Hi all,

As we all know ACE one arm mode change the Client src IP address to the NAT pool IP of the server VLAN.

they way if we are using SMTP behind the ACE , we cannot restrict some IPs in the SMTP relay configuration.

Is there any way to implement ACE one arm mode  with out altering the source IP address ?

I know then the purpose of having one arm mode itself is a question. but our client requires this feature.

Can some one help?

-Parvees

1 Reply 1

Cesar Roque
Level 4
Level 4

Hi Parvees,

The source nat in One-Arm mode is to force the response of the servers to come back to the ACE and from there to the client.

You can use the ACE as the default gateway of the servers or connect the servers directly to the ACE, that way the traffic will have to pass thru the ACE before going to the client.   The important is to force the response of the server to go back to the ACE.

Cesar R

--------------------- Cesar R ANS Team

Review Cisco Networking for a $25 gift card