Showing results for 
Search instead for 
Did you mean: 

vSZ behind router, add 2nd node to cluster

New Contributor III

Hi all,

We have a vSZ running with 3 interfaces behind a router.

Now we want to add a 2nd node to this cluster, also with 3 interfaces. This 2nd node is at a remote site and also behind a router. What ports should we forward in order to have te cluster interfaces to communicate?


I'm not sure clustering is supported behind nat. I'd be very surprised if it works at all. As others mentioned, a vpn is your best bet as I don't think the clustering interfaces are nat aware -as opposed to the main AP-facing nic. 

In SZ 5.2 a 1-to-1 NAT is supported and it can be configured under the cluster config.

Hi Trevor, that's great to know. Is it supported for all 3 interfaces? It used to be the case that it was only for the AP facing NIC if memory doesnt fail me.