Inventory Inputs
Used in all VRF / VLAN / object names
.+1 HSRP · .+2 Agg01 · .+3 Agg02
New client: 5 · Extension: use next seq (e.g. 10)
Internet / Firewall
From inventory — not auto-derived
.1 HSRP · .2 Agg01 · .3 Agg02 · .4 FW · .5 standby
CIDR or range a.b.c.d-a.b.c.e
Advanced
Extension info
e.g. 04 → obj_CLIENT-04-VDC
Existing internet HSRP gateway (for FW route)
First NAT Inputs
First server — maps to existing
obj_CLIENT-NAT. No new public IP needed.
Used in object names and NAT command
The server private IP inside the VDC
Services — 80 & 443 default
Second NAT Inputs
Additional server — check inventory for a free public IP. A new NAT object will be created.
Used in object names and NAT command
The server private IP inside the VDC
Free public IP from the inventory sheet
Services — 443 & 80 default
Remote VPN User
Creates a remote-access VPN user bound to an existing tunnel-group / group-policy on the ASA.
Used for both
group-lock value and vpn-group-policy GroupPolicy_…Port Opening
Opens specific TCP/UDP ports to a client server via its public IP (object-group service + ACL).
Used in object-group name:
svc_CLIENT-IP-servicesPorts to open
MTN Connection
Connects a client VRF to the MTN USSD service over the MTN P2P link — prefix-list + ACL + route-target leak on Agg01, static routes on Agg02.
Used in vrf context and the downloaded filename
Added to prefix-list MTN-CUSTOMERS
Next free seq in MTN-CUSTOMERS
Next free line in access-list MTN_LINK
permit ip any <IP>/32 in MTN_LINK
Imported into vrf MTN_USSD (client side RT)
Auto-derived: customer network +2 — override if needed
Advanced
Imported into the client VRF
One per line. Bare IPs are treated as /32