10-21-2022 09:10 AM
If the general rule is to use CLIP as management interface for Fabric Engine with Segmented Management Interface when using L3 BEB or L3 non-fabric how can a connection be established using a NAT enabled Firewall?
Would we add a Mgmt VLAN and add it to the uplink to the Firewall so that it can be NATd?
I think this is the only option and would allow access to the CPU using a mgmt VLAN. We can have multiple management interfaces after all. With L3 enabled switch the mgmt VLAN would not be accessible from other local VLAN IP interfaces.
10-24-2022 05:40 AM
10-24-2022 12:22 AM
You either use mgmt VLAN or mgmt CLIP.
If you use CLIP, there is no need to add a VLAN on the firewall, just a route would be needed (+ security policies).
Be carefull with Natting mgmt interface because it is the one used for Radius and XIQ-SE snmp communication.
You can also work with the same mgmgt VLAN for all your switches but again, the NATting could cause trouble with Radius and XIQ-SE snmp communication.