cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
833
Views
0
Helpful
4
Replies

Bridging mode: ¿can servers be reachable by their real IP addresses?

rogelioalvez
Level 1
Level 1

Hello team.

Customer is asking me to load balance a farm of servers for clients in the same subnet, so I am going to configure bridge mode.

In parallel, customer is asking me to have visibility of the real IP addresses of each of the individual servers in the farm, for management purposes. I do not know if this possible, but I would assume that ACE will bridge packets from client to destination server´s real IP address in cases like this. ¿Am I right?

I do not know if this is feasible by default or if I need to put policies in place to allow it.

Your help will be greatly appreciated.

Best regards

Rogelio Alvez

Argentina

2 Accepted Solutions

Accepted Solutions

sivaksiv
Cisco Employee
Cisco Employee

Hi,

If you are hitting a virtual ip (for loadbalancing) then you need to apply the policy on the inbound interface and src nating might be required. If you are hitting directly the real server ip then ACE would just bridge the traffic.

-

Siva

View solution in original post

Hi Rogelio,

You are right. SRC nat not required if they are in different vlan or in a different segement.

-

Siva

View solution in original post

4 Replies 4

sivaksiv
Cisco Employee
Cisco Employee

Hi,

If you are hitting a virtual ip (for loadbalancing) then you need to apply the policy on the inbound interface and src nating might be required. If you are hitting directly the real server ip then ACE would just bridge the traffic.

-

Siva

Hi Siva, thanks a lot for your quick answer!

Let me please check something else about your answer. You say that SRC NAT might be required. I assume that you warn me of this IF clients and servers are in the same VLAN.

But IF clients are in VLAN X and servers are in VLAN Y (both vlans bridged by the ACE), then the ACE won´t need SRC NAT to disguise clients´ addresses, since clients and servers are physically joined thru the ACE.

I would appreciate your confirmation on this SRC NAT subject.

Thank you very much in advance again

Best regards, Rogelio

Hi Rogelio,

You are right. SRC nat not required if they are in different vlan or in a different segement.

-

Siva

Excellent! Then it works just as I expected.

I have not had a chance to get a hold yet into these boxes (I am going to do it soon), so I wanted to double check the design.

Thanks a lot!!

regards, Rogelio

Review Cisco Networking for a $25 gift card