05-10-2022 04:47 AM
Hi,
I'd like to confirm that the attached scenario is viable. According to documentation, there is dynamic NAT support within the Nexus3000 family (
However, I haven't seen anything neither in these documents nor browsing the internet for sample configs when vPC is involved. As you can see, I have to Nexus 31108 running HSRP on the NAT inside VLAN and vPC on the NAT outside interface. At present time, this scenario works fine without adding and configuring the NAT feature.
Does anybody have experience with Nexus3K vPC and dynamic NAT?
Thanks in advance
Kind regards
Octavio
05-10-2022 06:03 AM
Look at the Limitation :
HSRP and VRRP are not supported on a NAT interface.
05-10-2022 06:19 AM
Thanks a lot, BB.
I know what it says the document, but I've also found this limitation in another Nexus family only applied to the outside interface, as if HSRP/VRRP was effectively supported in the inside. In the end I want to test it in a lab, but first of all I was looking for somebody who succesfully tried to configure it.
Thank you
Octavio
05-11-2022 03:50 AM
Sure you most welcome as Cisco tester, as Cisco does some testing before post the document,. in this case you need to go to TAC with your outcome since they clearly say not support, nothing much as community can do here.
If i were you, if the NAT is Must, i use different interface which is not part of FHRP running.
05-16-2022 12:16 AM
Thank you, BB. I'll try to test it in any case, as it's a bit confusing feature in different Nexus models. Reviewed with a Cisco SE, he recommended a lab test first. I came to the community looking for people having lived the same confusing situation. Unfortunately, Cisco documentation is not what it was 20 years ago in terms of its reliability.
I take note of your recommendation of using a different interface, as it would be a valid option according to the resources we have.
Thank you
Octavio
05-10-2022 06:46 AM - edited 05-10-2022 09:05 AM
as Mr. @balaji.bandi mention
""HSRP and VRRP are not supported on a NAT interface.""
why you are looking for NAT in NSK and not push the NAT to edge router ?
05-16-2022 12:18 AM - edited 05-16-2022 12:18 AM
Hi BB,
Those routers are transit routers responsible for eBGP. We try to keep them as 'clean' as possible. Of course that is our last resort, but we try to explore every alternative we would have before having to configure NAT in them.
Thank you
Octavio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide