Hi all,


I have a question around VLANs in a Merkai site that is for a Vendor and their equipment. 


This VLAN has an IP range not routable and is is isolated from the rest of the Corporate Network.  Corporate hosts would need to be NAT'd from Corporate IP's to the Isolated VLAN IP's in order to access services.


Client host(10.1.x.x)  ->  Pre NAT IP's in Routable IP Range(10.2.x.x)  ->   Static NAT  ->  Isolated host on isolated IP  Range (10.2.x.x).


Given what I know of the MX and MS devices I don't see a way to have an Isolated VLAN that fits the above scenario.


Is that correct ?


Many thanks for your help



It would have to be connected via a WAN port on an MX.

