<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Solution required in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977548#M80681</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi BSN,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The scenario is not clear with me. When you speak of Internet server, are you referring to Internet sites (ie &lt;A class="jive-link-custom" href="http://www.yahoo.com)" target="_blank"&gt;www.yahoo.com)&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And when you go through MPLS server, are you referring to an intranet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please clarify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K0rg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jun 2008 13:27:34 GMT</pubDate>
    <dc:creator>joseph.derrick</dc:creator>
    <dc:date>2008-06-17T13:27:34Z</dc:date>
    <item>
      <title>Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977547#M80680</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have following scenario&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router&amp;lt;-&amp;gt;Firewall&amp;lt;-&amp;gt;Core Switch&amp;lt;-&amp;gt;Server&lt;/P&gt;&lt;P&gt;   |_____________________|&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a direct link from router to core swich as well.  Router have two sub-interfaces for; Internet and MPLS.  To access internet Server must go thru firewall and to access MPLS server must go thru direct link to router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone guide how to accomplish this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;BSN&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 06:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977547#M80680</guid>
      <dc:creator>bsn1980in</dc:creator>
      <dc:date>2019-03-04T06:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977548#M80681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi BSN,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The scenario is not clear with me. When you speak of Internet server, are you referring to Internet sites (ie &lt;A class="jive-link-custom" href="http://www.yahoo.com)" target="_blank"&gt;www.yahoo.com)&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And when you go through MPLS server, are you referring to an intranet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please clarify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K0rg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 13:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977548#M80681</guid>
      <dc:creator>joseph.derrick</dc:creator>
      <dc:date>2008-06-17T13:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977549#M80682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does not make sense to bypass your security devices, however you could accomplish this (depends on platform/IOS of core switch) with Policy-based routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6599/products_white_paper09186a00800a4409.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6599/products_white_paper09186a00800a4409.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 13:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977549#M80682</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-06-17T13:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977550#M80683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like you wish to have regular IP traffic go through the firewall and label-switched traffic bypass the firewall. Is this correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 13:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977550#M80683</guid>
      <dc:creator>patrickvanham</dc:creator>
      <dc:date>2008-06-17T13:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977551#M80684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi K0rg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to access internet(www) and MPLS from Server.  Only difference would be, to access Internet, my server must go through firewall and to access MPLS it must go through the direct link between router and core switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds/bsn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 13:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977551#M80684</guid>
      <dc:creator>bsn1980in</dc:creator>
      <dc:date>2008-06-17T13:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977552#M80685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My requirement is to reach Internet and MPLS which are connected on my router.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Internet:&lt;/P&gt;&lt;P&gt;My LAN/Server must pass thru Firewall and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For MPLS:&lt;/P&gt;&lt;P&gt;My LAN/Server must pass thru the direct connection between Router and Core Switch and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried it thru PBR and it seems to be working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other way to do so??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds/bsn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 03:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977552#M80685</guid>
      <dc:creator>bsn1980in</dc:creator>
      <dc:date>2008-06-18T03:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977553#M80686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depending on your IP scheme, you could use your IGP to bypass the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 12:19:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977553#M80686</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-06-18T12:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977554#M80687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but depends if you are using any routing protocol or not. You can publish a default route from the firewall and the specific networks accross mpls from your edge router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 12:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977554#M80687</guid>
      <dc:creator>arunsing</dc:creator>
      <dc:date>2008-06-18T12:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977555#M80688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use PBR, EIGRP but it must be a routing protocol used to specify where the traffic goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic on the other end of the MPLS network might be 172.16.0.0/16&lt;/P&gt;&lt;P&gt;You could put in a static route for all traffic on your network to go out the directly connected link on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.16.0.0 255.255.0.0 &lt;OUTBOUND interface="" to="" router=""&gt;&lt;/OUTBOUND&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 &lt;OUTBOUND interface="" to="" firewall=""&gt;&lt;/OUTBOUND&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These 2 routes tell the traffic where to go.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 17:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977555#M80688</guid>
      <dc:creator>Rick Morris</dc:creator>
      <dc:date>2008-06-18T17:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977556#M80689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a normal configuration of PBR, I have created an extended access-list with source and desination subnets, then match it and set next-hop to be the interface directly connected to router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rest of the traffice will go to firewall using default route.  Also if my direct connection to Router fails, the next hop will not be reachable and all the traffic will then move through firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same configuration I have applied for incoming traffic from MPLS cloud on router as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;bsn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2008 07:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977556#M80689</guid>
      <dc:creator>bsn1980in</dc:creator>
      <dc:date>2008-06-20T07:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977557#M80690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your ACL has specific subnets in the MPLS cloud you could set up static routes to the MPLS cloud towards the directly connected interface to the router and a default route to the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2008 09:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977557#M80690</guid>
      <dc:creator>patrickvanham</dc:creator>
      <dc:date>2008-06-20T09:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977558#M80691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have encountered a problem with this scenario; let me explain this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside n/w: 10.10.10.0 /24 &lt;/P&gt;&lt;P&gt;MPLS remote n/w: 172.16.0.0 /16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have defined below static routes on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core Switch: &lt;/P&gt;&lt;P&gt;172.16.0.0 255.255.0.0 G0/0(i/f directly connected to Router)&lt;/P&gt;&lt;P&gt;0.0.0.0 0.0.0.0 G0/1(i/f connected to FW)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router: &lt;/P&gt;&lt;P&gt;10.10.10.0 255.255.255.0 G0/0 (if connected to Core Switch)&lt;/P&gt;&lt;P&gt;10.0.0.0 255.0.0.0 G0/1 (i/f connected to FW)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case my MPMS  traffic from 10.10.10.0 subnet goes out from directly connected interface to router and comes back.&lt;/P&gt;&lt;P&gt;But Internet traffic from 10.10.10.0 subnet goes out using default route and comes back from the directly connected interface between router and switch using more sepcific default route.  Hence not able to access internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing NAT on router for internet access.  The solution could be doing NAT on Firewall as well but with PBR this solution seems to be working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;BSN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2008 13:04:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977558#M80691</guid>
      <dc:creator>bsn1980in</dc:creator>
      <dc:date>2008-06-20T13:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977559#M80692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is because the route back is more specific directly towards the core switch. every packet towards 10.10.10.0 /24 will take the directly connected route. On the router you would need to use PBR and source-based routing in your situation i.e. if the source is the MPLS cloud use Gi0/0, everything else follow default route towards firewall. An ACL like "permit ip 172.16.0.0 0.0.255.255 any" could be used to determine egress interface on the router in a route-map. The route-map would be apllied in the internet and MPLS ingress interface(s)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2008 13:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977559#M80692</guid>
      <dc:creator>patrickvanham</dc:creator>
      <dc:date>2008-06-20T13:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Solution required</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977560#M80693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes...This the reason of using PBR.  I have only applied PBR on MPLS ingress interface as below.  Also, I have removed the more specific static route for subnet 10.10.10.0/24. Now, even if Gig0/0 goes down, all the traffic (MPLS &amp;amp; Internet) will follow path towards Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; ip policy route-map MPLS-Traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 172.25.243.0 0.0.0.255 10.10.10.0 0.0.0.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map MPLS-Traffic permit 10&lt;/P&gt;&lt;P&gt; match ip address 100&lt;/P&gt;&lt;P&gt; set interface Gig0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My query was, if I can use any other way out for this kind of situation OR PBR is the only option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;BSN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2008 13:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/solution-required/m-p/977560#M80693</guid>
      <dc:creator>bsn1980in</dc:creator>
      <dc:date>2008-06-20T13:31:06Z</dc:date>
    </item>
  </channel>
</rss>

