03-12-2024 04:09 AM
Hi,
We have 2 Secure Email Gateway C690 devices Version: 15.0.1-030.
Is it possible to create a cluster if the connection between them is using Firewall Cisco ASA on which is configured NAT (host to host)?
Thank you.
03-12-2024 04:37 AM
clustering possible below resources help you, the NAT part depends on you want to load-balance each other ? when the incoming traffic coming from out side to inside.
03-12-2024 04:59 AM
Carefull here, you will find issues while natting due the TLS required for POV/Quarantine delivery.
The following ports are needed for SMA <-- --> ESA communication :
PVO:
1) ESA --> SMA (7025)
2) SMA --> ESA (7025)
Spam Quarantine:
1) ESA --> SMA (6025)
2) SMA --> ESA (25)
General Connectivity / Tracking / Reporting:
1) ESA --> SMA (22)
2) SMA --> ESA (22)
03-12-2024 05:10 AM
03-12-2024 05:30 AM
Is it even possible to create a cluster if ESA1 and ESA2 devices are connected to each other through a Cisco ASA firewall on which NAT (host-to-host) is configured?
04-28-2024 04:22 PM
theoretically it should work if we think about ESA leverages SSH for Clustering and I don't think SNAT might cause trouble for SSH session. But I highly recommend to deploy two test ESA virtual machines and check cluster through the firewall+SNAT.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide