cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
263
Views
0
Helpful
0
Replies
Highlighted
Beginner

ASA S2S transition to new cluster with dynamic NAT address advertisement

OK, so I think I know the answer (i.e. it's not possible). However, I feel that there has to be a way to do this gracefully.

 

Here's the scenario. We're moving from and existing topology with a HA pair. There's 100+ S2S tunnels in place currently. I'm trying to find a way to transition them to a new HA pair in a graceful fashion. Thing is, nearly all of the remote peers are currently being NAT'd to a locally routed IP. Obviously doing this transition one at a time is going to be a pain. However, it occurred to me that there could be a more intelligent way of doing this. Being more of an R&S guy than an ASA/Remote Access guy, I figured there has to be a way to dynamically advertise the tunnel networks as they come up... using the rule of more specific routes to determine the better path (i.e. 10.0.0.0/24 via the old, and 10.0.0.0/30 via the new).... however these pools are, for the most part NAT pools.

 

So, the question is... is there a way that anyone can think of to dynamically advertise the NAT address(es) of a given tunnel as it comes up, via BGP?

 

Thanks in advance for any responses.

0 REPLIES 0