cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
516
Views
0
Helpful
3
Replies

ANM behind a NAT

omarmontes
Level 1
Level 1

Hi guys!

Is there an implication of having an ANM server behind a NAT? When configuring an ACE module from the ANM server, it configures its IP address as the SNMP server (the local address). I guess for this you have to get directly into the ACE module and change this to the NAT address. But is there something am I missing? should it work?

thanks in advance

3 Replies 3

Daniel Arrondo Ostiz
Cisco Employee
Cisco Employee

Hi Omar,

Whenever possible, I would recommend keeping direct connectivity between the ACE and the ANM server, preferably on a management-only vlan, because otherwise, even though most of the ANM functionality would still work (assuming that traffic is able to flow bi-directionally through the NAT) some features may not work properly.

Just to give you an example, when parsing syslog messages, ANM will use the IP address sent inside the syslog message to identify the ACE that generated the message. If this address is being natted, ANM won't be able to determined to which ACE the messages belongs and will assume that the corresponding device was not imported, resulting in the syslog message being ignored.

As you also mentioned, there are some configurations pushed by the ANM (syslog, SNMP...) that would have to be modified manually after being pushed by ANM, which is more error-prone.

Regards

Daniel

Thank you Daniel..

Do you know of other features that might not work?

Hi Omar,

Apart from what I already explained, I don't think there would be other issues, but I cannot confirm it

Regards

Daniel

Review Cisco Networking for a $25 gift card