<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing Config Issue in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956691#M192833</link>
    <description>&lt;P&gt;All-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make it easier to explain my problem, I am attaching the network diagram. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R1 is remote site that runs IPSec VPN and it setup the accordingly primary and failover L2L VPN to R2 and R7. R2 and R3 are in the data center, and R6 and R7 are in the seondary data cenetr. R3, R4, R5, and R6 are all connected to the MPLS cloud via BGP. All the router are running eBGP here, except the remote router R1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R 2 and R7 are running the static route for the subnet in the remote site. My issue is...when the primary VPN down, the failover VPN switches as an actived mode. On the router R5, supposed the route to the subnet in the remote site R1, should be R5-&amp;gt;R6-&amp;gt;R7-&amp;gt;R1, but the route still goes R5-&amp;gt;R3-&amp;gt;R2-&amp;gt;R1.The crypto Phase I is up, but it appears there is the routing issue. Please advice how to adjust the routing so we can reach the remote site when the primary is down through the backup VPN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joe &lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2019 00:45:05 GMT</pubDate>
    <dc:creator>Joe Lee</dc:creator>
    <dc:date>2019-03-05T00:45:05Z</dc:date>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956691#M192833</link>
      <description>&lt;P&gt;All-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make it easier to explain my problem, I am attaching the network diagram. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R1 is remote site that runs IPSec VPN and it setup the accordingly primary and failover L2L VPN to R2 and R7. R2 and R3 are in the data center, and R6 and R7 are in the seondary data cenetr. R3, R4, R5, and R6 are all connected to the MPLS cloud via BGP. All the router are running eBGP here, except the remote router R1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R 2 and R7 are running the static route for the subnet in the remote site. My issue is...when the primary VPN down, the failover VPN switches as an actived mode. On the router R5, supposed the route to the subnet in the remote site R1, should be R5-&amp;gt;R6-&amp;gt;R7-&amp;gt;R1, but the route still goes R5-&amp;gt;R3-&amp;gt;R2-&amp;gt;R1.The crypto Phase I is up, but it appears there is the routing issue. Please advice how to adjust the routing so we can reach the remote site when the primary is down through the backup VPN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Joe &lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 00:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956691#M192833</guid>
      <dc:creator>Joe Lee</dc:creator>
      <dc:date>2019-03-05T00:45:05Z</dc:date>
    </item>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956692#M192834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since R2 and R7 are using static routes to the remote subnet, when the route (VPN) goes down, they dont withdraw it from the routing table, causing a black hole in your network towards R1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what you have to do is simply set up an &lt;STRONG&gt;IP SLA Echo &lt;/STRONG&gt;that pings your R1 ip address constantly, and then bind the IP SLA tracker to your static route. &lt;/P&gt;&lt;P&gt;this way when there is reachability issues, such as link failure or whatever, your static route is withdrawn from the routing table and the other VPN takes control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;plz Rate if it helped, &lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt;Soroush.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2012 20:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956692#M192834</guid>
      <dc:creator>smehrnia</dc:creator>
      <dc:date>2012-06-21T20:30:48Z</dc:date>
    </item>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956693#M192835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Soroush. Which router should I setup the IP SLA? Can you please provide me some detail on setting up the IP SLA Echo? Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2012 21:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956693#M192835</guid>
      <dc:creator>Joe Lee</dc:creator>
      <dc:date>2012-06-21T21:09:37Z</dc:date>
    </item>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956694#M192836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;R 2 and R7 are running the static route for the subnet in the remote site. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;as you said, R2 and R7 are responsible for R1 (remote) connection. so you have to set the &lt;STRONG&gt;ip sla&lt;/STRONG&gt; on R2 and R7. then on both of these routers attach the ip sla to the static routes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt; (but with different IOS versions the commands might slightly be different, you could look them up in cisco.com):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!! we assume that;&amp;nbsp; R1 = 10.1.1.1&amp;nbsp; -&amp;nbsp; subnets behind R1 are: 172.16.0.0/16&amp;nbsp; !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;config t&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip sla 1&amp;nbsp; &lt;/STRONG&gt;&lt;EM&gt;OR&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp; ip sla monitor 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; icmp-echo 10.1.1.1 source-interface &lt;/STRONG&gt;[if you need to source icmp-echo from a specific ip]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; timeout 2000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; frequency 2 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; ! the frequency at which ping is sent, the smaller value, the faster networks knows abt the failure&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip sla schedule 1 life forever start now&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;track 1 rtr 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip route 172.16.0.0 255.255.0.0 10.1.1.1 track 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;plz Rate if it helped,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Soroush.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2012 21:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956694#M192836</guid>
      <dc:creator>smehrnia</dc:creator>
      <dc:date>2012-06-21T21:27:03Z</dc:date>
    </item>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956695#M192837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Soroush. couple questions/concerns. 1) R1 is the customer router, most of them, we can't ping their router ip address. 2) Can we setup ip sla on&amp;nbsp; R2 to ping the R7 router, and on R 7 to ping the R2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 17:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956695#M192837</guid>
      <dc:creator>Joe Lee</dc:creator>
      <dc:date>2012-06-26T17:56:53Z</dc:date>
    </item>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956696#M192838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anytime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for ip sla (echo) to work you have to use the links that u r concerned about, because this ping simply checks connectivity and if it is lost, route is withdrawn. if you dont use R2 - R1 and R7 - R1 links in ur ping, ip sla is no use then. you can ping anything that makes it pass those links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it Helps, &lt;BR /&gt; &lt;BR /&gt;Soroush.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 18:47:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956696#M192838</guid>
      <dc:creator>smehrnia</dc:creator>
      <dc:date>2012-06-26T18:47:35Z</dc:date>
    </item>
    <item>
      <title>Routing Config Issue</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956697#M192839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Soroush again. Due to unable to ping the router in seattle site, any options to solve my issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 15:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/routing-config-issue/m-p/1956697#M192839</guid>
      <dc:creator>Joe Lee</dc:creator>
      <dc:date>2012-06-27T15:45:19Z</dc:date>
    </item>
  </channel>
</rss>

