We are deploying a SD-WAN project that the controllers are hosted in customer Data Center.
Customer request that all controllers needs to sit behind firewall and real controller IP needs to be hidden so as to meet security compliance.
Here is the high level diagram.
All controller will assign private IP, it will do 1:1 NAT(private IP to private IP NAT) on Server firewall. then will have another 1:1 NAT(private IP to public IP NAT) on Internet firewall.
Will this solution work?
