10-23-2019 08:33 AM - edited 02-21-2020 09:37 AM
Hi Experts, Please check and suggest, if the attached design is a workable solution.
Currently, working on migrating existing Apps to public cloud, since the customer dont want to change the public IP for the apps,resources, looking to forward the customer (VPN and Internet traffic) using the existing onpremise ASA to public cloud. Kindly advice.
Thanks in advance
Sreeraj Murali
10-23-2019 08:54 AM
I would check with your AWS/Google/Azure solutions architect.
10-23-2019 11:41 PM
Yes, done that. Have doubt, that can we achieve, the below NAT configuration on ASA. Please suggest and advice,if below static NAT and NO NAT is configurable on ASA.
Internet
============= Private Dedicated =============| /<-------->Internet users
10.20.32.0/21 | <--------------> 10.240.5.4 --|Cisco ASA Fw |---1.1.1.1 <--->
============= circuit ============ | (pub ip) \<--------->Customer DC
site to site (10.90.10.0/24)
vpn
ASA static NAT
10.20.32.2 --1.1.1.2
10.20.32.3 --1.1.1.3
10.20.32.4 --1.1.1.4
No NAT
10.20.32.0/24--10.90.10.0/24
10-24-2019 02:32 AM
It seems workable and fine. You also have to look for the Routing part on the Private Dedicated Cloud connecting to ASA.
HTH
### RATE ALL HELPFUL RESPONSES ###
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide