08-04-2025 11:08 AM
When we add new ironport cluster member that using NAT, the new member communicate using real ip rather that NAT IP.
In clusterconfig > COMMUNICATION, i can change the ip that used for cluster communication. When i change the IP address do i need to commit the changes?
Thanks
Solved! Go to Solution.
08-13-2025 06:45 AM
Are these 2 ESA(s) already in cluster and the plan now is to change the communication IP address? or are you adding a brand new ESA to an existing cluster and you are looking to use the NAT IP for communication?
If its the latter, change the communication IP of the existing member in cluster, run a commit on the cluster.
Access the CLI of the new ESA, via clusterconfig select join existing cluster and add the NAT IP of the cluster member. This way when new member connects to the existing ESA, it will use the NAT IP. At the same time if the IP address of the new member goes through a NAT too, cluster member will see source as NAT IP (instead of the real IP)
08-04-2025 11:12 AM - edited 08-04-2025 11:12 AM
hello @justinus.budi , and yes, when u change the IP address under clusterconfig > COMMUNICATION, u do need to commit the changes for them to take effect. Until u commit, the new IP won't be used for cluster communication. Also, why not, make sure the real IP is reachable between members if NAT is involved, cluster communication typically uses the real IPs, not the NATed ones, unless u're doing some special routing or tunneling.
hope it helps..
-Enes
08-05-2025 07:14 AM
After add the new member, where should i do the commit, on the master cluster or on the new member. For example 10.204.111.1 is the existing cluster member 10.204.111.2 the new member. in which ip should i do the commit?
08-13-2025 06:45 AM
Are these 2 ESA(s) already in cluster and the plan now is to change the communication IP address? or are you adding a brand new ESA to an existing cluster and you are looking to use the NAT IP for communication?
If its the latter, change the communication IP of the existing member in cluster, run a commit on the cluster.
Access the CLI of the new ESA, via clusterconfig select join existing cluster and add the NAT IP of the cluster member. This way when new member connects to the existing ESA, it will use the NAT IP. At the same time if the IP address of the new member goes through a NAT too, cluster member will see source as NAT IP (instead of the real IP)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide