cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
485
Views
0
Helpful
1
Replies

Where best to NAT for DMVPN Internet connection

carl_townshend
Spotlight
Spotlight

Hi All

We are currently working on a site which will connect to our IWAN, using MPLS and and Internet connection.

Most the sites will have the firewall and NAT running on the Internet router.

However on one site, we have some firewalls sitting behind these routers.

What would be the best option, just do NAT on the Cisco Internet router only, or use the firewalls behind and do double NAT so on the firewall and router

cheers

 

1 Reply 1

ghostinthenet
Level 7
Level 7

Personally, I'm never a fan of double-NAT. It introduces additional management overhead and additional troubleshooting requirements. If possible, I would run the firewalls in parallel with the DMVPN router, using the DMVPN router as the default gateway and redirecting traffic to the firewalls as required. Of course, that's based only on the information provided and with no understanding of the underlying business and technical requirements. With more information, I could probably provide better advice.