cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
315
Views
0
Helpful
1
Replies

2 Servers behind a single nat - not your normal request

sdawson35
Level 1
Level 1

So we have 2 servers (domain controllers) that exist in a security zone on an ASA firewall. One is a backup for the other (Only 1 live at any one point in time).

The client can only use a single ip address , so we want to (somehow) sit the 2 domain controllers behind a single natted address and somehow track which server is alive.

 

Is this even possible ?

 

 

Regards

 

Scott.

 

 

1 Reply 1

GioGonza
Level 4
Level 4

Hello @sdawson35

 

This is not possible, the only way you can do that is to perform a PAT on the ASA but the traffic should always be initiated from the DC and not from the users, if you do the static NAT for 2 IPs it will always take the first one even if the server is down and it wouldn´t use the backup. 

 

HTH

Gio

Review Cisco Networking products for a $25 gift card