I have a number of sites with 2 x MXs on each. Each site has two Internet connections, which enter a switch through which they are shared between the MXs, so MX1 has WAN1 and WAN2, and MX2 likewise has WAN1 and WAN2 connections. The sites need to be set up to deliver load balancing auto-VPNs in a full mesdh....SD-WAN. The devices delivering WAN1 and WAN2 are NAT-ing, so upstream of the WAN1 and WAN2 devices there is a public address on each WAN, while downstream (at the MXs), there is a private (RFC1918) address on the uplink for EACH MX. Both WAN1 and WAN2 devices have the capability to support multiple addresses, so for instance WAN1 supports private addresses a.b.c.1 and a.b.c.2, and WAN2 supports private addresses x.y.z.1 and x.y.z.2 so unique private addresses are configured for each MX. I've shown this below. Question is: do I need two public addresses, one for each MX at each WAN device (total 4) or can I rely upon NAT overload so one WAN address is NATed to two LAN addresses. Alternatively, have I misunderstood the whole thing? I've been through the documentation and I'm just not happy I understand the requirements Thanks Jim
... View more