03-16-2021 07:32 PM
Hello,
We are looking to use the CSR1000V for multiple clients using IPSEC tunnels into our AWS Environment so we can manage 1000's of client end devices. To support this we wanted to setup NAT but were unsure on the best method being used by most organisations today.
How are others doing NAT on these CSR1000V devices, is there any automated method that is suggested for NAT solutions with clients devices or is it more a manual process.
03-17-2021 12:30 AM
When did you say Client devices? is this a site-to-site VPN or remote access VPN?
how about considering ASAv for remote access VPN solution? CSR Router most cases used for Point to Point VPN,(not that i can not be used, its bit manual task, )
ASAv you can use ASDM and manage things as easily as - when you doing from remote.
03-17-2021 03:02 PM
Hi,
The CSR's are for Point to Point VPN. (Essentially we will have 10-15 client Point to Point VPN's) and we will be supporting their client end devices via monitoring. Due to possible overlapping IP's we are investigating what the best possible NAT solution would be.
03-17-2021 06:31 PM
We do most of our automation with Ansible, works reasonably well, have had a play with the API module but looks like a lot of work to implement hopefully someone will write a terraform module for it in the future.
03-18-2021 03:20 AM
ok then CSR is good to go, you need to look for overlap IP with NAT or if possible VRF.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: