Hi,
I'm deploying new a Maestro setup. I have it configured in tandem with our existing 3200 A/S cluster. The IP addressing is identical - on the Maestro interfaces I'm using an available IP address in the subnet as the interface address i.e. 254. I want set up a few IPSEC VPNs to remote peers to test connectivity. The existing 3200 has active IPSEC VPNs to these peers. Upon cutover, the new Maestro will assume the VPN domain on the 3200 cluster. In the interim for Maestro testing, I was considering creating a dummy network object using an available network to use as the VPN domain for the new Maestro (SMO) gw object, and NAT the outbound internal host traffic to this network. My concern is that the order of operations when packet arrives at interface will not allow this to work i.e. the natted traffic will not be considered interesting traffic so will not initiate phase 1 negotiation.
Regards,
Simon