| Great info, Ahriakin. However, I can't get it working.
Perhaps a little clarification...
Vlan 241 --- ASA --- Vlan 222 --- Core 6504 --- Vlan 199
So the servers are rebuilt in the 241 range, and have NDS set to, say, 241.122. Our actual NDS server sits in Vlan 199, say, 199.212.
Putting the NAT rule in place {static (DR-HA,Core) 199.212 241.122} on the ASA appears to rewrite the packet, but as the 199 subnet is not directly connected, I have to assume that's my issue. The Core subnet is a 172.22.0.0 range, while vlan 199 is on the other side of the Core 6504. In this case, Natting doesn't appear to do the job as I expected, as it does with port forwarding on the Linksys.
Routing is in place throughout, and the 241 servers can ping the 199 server.
Hope that helps... cause I'm baffled.
Oh, and yeah, AD was complicated. I have a DC at DR, but it cannot see the HA subnets, so we are still able to bring up servers both here and at DR.
__________________
There are only 10 kinds of people... those who understand binary, and those that don't.
|