I have a situation where we need a destination nat to happen on ACE for an outbound flow that is redirected into SSLM modules, then coming back to the ACE and forwarded outward. There is a requirement to keep the SSLM module redirection so will not be able to achieve the encryption for the outbound connection by using the ACE.
I have a conflict when trying to implement as the real destination VIP (10.11.12.158 443) is being matched on two âmatch-anyâ class-maps. One is needed to direct traffic to the destination VIP via the SSLMs, and the other class-map is required to âstatic natâ the destination address when the flow leaves the ACE.
Any suggestion how to achieve the destination natting in this case?