This concept explains how Network Address Translation (NAT) supports mobility tunnels between peer controllers in a mobility group, including scenarios in which one or both controllers are located behind a NAT device.
NAT support for mobility groups is a mobility architecture enhancement that
-
enables mobility tunnels between peer controllers, even when one or both peers operate behind a NAT device,
-
translates public and private IP addresses to maintain connectivity between controllers, and
-
requires proper configuration of both addresses for NAT peers to ensure seamless mobility communication.
Additional information
Depending on the placement and number of NAT devices, translation might be required at one or both ends of the tunnel.
When you configure a NAT mobility peer, configure both the private IP address (the address used inside the network before the NAT device) and the public IP address (the address visible on the external network).
If a firewall is present between mobility group controllers, ensure that the following ports are accessible:
-
Port 16666 for mobility control messages
-
Port 16667 for mobility data messages
Ensure that ports 16666 and 16667 are accessible through any firewalls between peer controllers.
This figure illustrates how public and private IP addresses are translated to establish a mobility tunnel between controllers behind NAT devices.