cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
1120
Views
5
Helpful
8
Replies

NAT problems

DVRK
Level 1
Level 1
I'm looking at about 30 branch offices connecting to one HQ through VPN(using pat). The internet becomes very slow quickly and upon checking NAT the translations are getting to 131062 fast and capping there. What might be the problem?
8 Replies 8

30 Site connect to HQ via VPN and you dont use Direct Internet Access that sure make HQ slow, 
all site when need to connect to Internet it send traffic to HQ. that bad idea.
I think the VPN is route-based, so you need to config Direct Internet Access in Branch Site (if they have FW or Zone FW) in Site edge.

Thank you for the response. All  the branches have to connect through the HQ for internet.

I am assuming you are tunneling all traffic through the HQ.  So, what device is the VPN being terminated on at the HQ and is this also the internet gateway?  How fast is your internet connection at the HQ office, and at the branch sites?

If you have not scaled your hardware and internet connection to accommodate for this amount of traffic then the connection will be slow.

If you have scaled your hardware and internet connection properly, then there might be a few users that are either streaming videos or downloading off the internet. 

--
Please remember to select a correct answer and rate helpful posts

Yes all traffic is channeled through HQ and the device is Cisco router 4321. I guess the hardware have to be scaled to handle the traffic.

Do you have the HSEC license for you 4321 router?  Without the HSEC license you will be limited to 85 Mbps VPN traffic.

--
Please remember to select a correct answer and rate helpful posts

IP_Cartel
Level 1
Level 1

bro, 30 branch sites I would say it is time to design SD-WAN.  You can use inexpensive WAN links for SD-WAN and have smarter redundancy.  

Ideally a new design would be the solution, but this would also mean a whole different price tag.  The HSEC license would better the situation as of right now, but for the long run a new design would be best.

--
Please remember to select a correct answer and rate helpful posts

alirafaleiro
Level 1
Level 1

Network Address Translation (NAT) therefore was introduced to overcome these addressing problems that occurred with the rapid expansion of the Internet.

Review Cisco Networking for a $25 gift card