cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
579
Views
0
Helpful
2
Replies

Should ACE VIPs be Nated By a Firewall?

dmbergen
Level 1
Level 1

Cannot seem to find the answer to this question for what the Best practice is or would be. Should the VIP privet ip be NATed at the firewall for internet access? IE,  Internet firewall NAT ------> Privrt WEB server farm VIP.

thanks

2 Replies 2

ajayku2
Cisco Employee
Cisco Employee

Yes, VIP private IP should be NATed at the firewall for internet access. You can point the default gateway on ACE as firewall interface IP address.

Also in order to accept the incoming connection you may have to use NAT on firewall.

Thank you, However, will this not effect incomming sticky using source IP? Firewall will be seen as the source, not the public IPs access the WEB site?

Having a Public DMZ using all public IPs , protected by a firewall, but not preforming "NAT", Just for a layer of security , this seems the way to go.

thank you

Review Cisco Networking for a $25 gift card