FD.io VPP
v19.04.1-1-ge4a0f9f
Vector Packet Processing
|
One NAT node actively manages traffic while the other is synchronized and ready to transition to the active state and takes over seamlessly and enforces the same NAT sessions when failure occur. Both nodes share the same configuration settings.
Session synchronization traffic is distributed through an IPv4 UDP connection. The active node sends NAT HA protocol events to passive node. To achieve reliable transfer NAT HA protocol uses acknowledgement with re-transmission. This require the passive node to respond with an acknowledgement message as it receives the data. The active node keeps a record of each packet it sends and maintains a timer from when the packet was sent. The active node re-transmits a packet if the timer expires before receiving the acknowledgement.
The two NAT nodes have a dedicated link (interface GE0/0/3 on both) to synchronize NAT sessions using NAT HA protocol.
+-----------------------+ | outside network | +-----------------------+ / \ / \ / \ / \ / \
+------—+ +------—+
GE0/0/1 | Active Passive | GE0/0/1 |
---|---|---|
GE0/0/3 | ----------------— | GE0/0/3 |
sync network | ||
GE0/0/0 | GE0/0/0 |
+------—+ +------—+ \ / \ / \ / \ / \ / +--------------------—+ | inside network | +--------------------—+