cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
0
Helpful
1
Replies

Firewall Load Balancing (FWLB) w/ CSM: NAT issue

tjcho
Level 1
Level 1

I know that firewalls cannot perform NAT when CSS do FWLB.

Then, what about CSM?

Does CSM support performing NAT on the firewalls when it acts as FWLB?

If someone has experience or sample config, let me know.

Thanks in advance.

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

yes, you can do nat on the firewall with csm.

2 Solutions I can think of.

First, assuming you nat the source.

You can do loadbalancing based on the destination on the frontend CSM [this address won't changed after going through the CSM] and you loadbalancing based on the source ip address on the backend CSS [this address was the destination on the frontend]

Another solution is to use reverse-sticky.

http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a008020927a.shtml

Regards,

Gilles.

Review Cisco Networking for a $25 gift card