Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ERTK
Contributor

Vpn remote acces mab agains cluster with only private addres

Hi,

A customer had a cluster only with private range addres. 

On this cluster it had configured vpn remote acces making Nat on isp provider.

Recently they need to move Nat from isp to this cluster....but client cannot reach. 

Is it possible to make than this cluster make also this kind of Nat ( public interface is not configure on this cluster but isp provider route one public ip address for.thqt purpose)?

0 Kudos
8 Replies
G_W_Albrecht
Legend
Legend

If the ISP routes a public IP to a cluster, the cluster needs a WAN interface with that public IP that also should be part of the Remote Access community.

CCSE CCTE SMB Specialist
0 Kudos
ERTK
Contributor

i understand. maybe creating an cluster interface with this public ip address like vip.....and configuring rules and vpn link selecction could it be.

 

0 Kudos
G_W_Albrecht
Legend
Legend

Otherwise, the cluster will not feel responsible for this public IP...

CCSE CCTE SMB Specialist
0 Kudos
ERTK
Contributor

I just create a dummy cluster interface with this public ip address like via pf this dummy....it is a internal interface..it means than the traffic must in for current transport interface between isp provider and this cluster. 

Vpn client connect but...after a few minutes it disconnect

0 Kudos
G_W_Albrecht
Legend
Legend

Afaik this can not work with an internal interface. Look into GW and RA client logs to see the reason the connection is lost!

CCSE CCTE SMB Specialist
0 Kudos
ERTK
Contributor

sorry, the topology interface config like an external....i want to say that this interface is behind firewall in flow....

0 Kudos
G_W_Albrecht
Legend
Legend

Should be the external/WAN VIP interface of the cluster according to Remote Access Admin Guide. I would suggest to contact TAC as there may be a special config making this possible.

CCSE CCTE SMB Specialist
0 Kudos
ERTK
Contributor

i'll do. Thanks

 

0 Kudos