I have my primary and backup data center clusters in the same policy package. Basically, I am trying to find the easiest and simplest way to NAT to just these clusters in case we fail-over to our backup data center.
- You could clone your object and create the Auto-NAT for your secondary policy installation target there.
- Won't the first rule top down always get matched for the auto rules? If the clones are further down, will they ever get hit?
Could you give an example for each of these? I'm not sure what you mean.
- You could consolidate your policy installation targets into one big cluster.
- You could use a Mgmt_CLI script to change the NAT according to the policy installation target.