<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conectar 2 ISP a router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859716#M28293</link>
    <description>&lt;P&gt;Not sure what License you have, other way is do NAT (but this limits auto fall back if ISP Fails)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VLAN3 network NAT with ISP1&lt;/P&gt;
&lt;P&gt;VLAN4 network NAT with ISP1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sense ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show license and show version can give us more idea what you have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2019 21:25:19 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-05-20T21:25:19Z</dc:date>
    <item>
      <title>Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859686#M28292</link>
      <description>&lt;P&gt;Hola, espero me puedan apoyar con mi siguiente caso:&lt;/P&gt;&lt;P&gt;Tengo configurado un firewalll fortinet, donde conecto 2 ISP de diferente proveedor, y en mi router 2900 hago que todo el trafico salga por la interfaz Gi0/1 ISP1.&lt;/P&gt;&lt;P&gt;Agregué otro ISP a la interfaz Gi0/2 ISP2.&lt;/P&gt;&lt;P&gt;Pretendo enviar algunas VLAN hacia el ISP2, pero no se si sea posible ya que he configurado PBR y no me funciona, vi que para usar PBR necesito una actualización en mi licencia del router.&lt;/P&gt;&lt;P&gt;Quisiera saber si hay otra manera a parte de PBR para que pueda lograr enviar unas de mis VLAN por el ISP2 y otras por el ISP1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gracias..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 20:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859686#M28292</guid>
      <dc:creator>CRUZPEREZ518</dc:creator>
      <dc:date>2019-05-20T20:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859716#M28293</link>
      <description>&lt;P&gt;Not sure what License you have, other way is do NAT (but this limits auto fall back if ISP Fails)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VLAN3 network NAT with ISP1&lt;/P&gt;
&lt;P&gt;VLAN4 network NAT with ISP1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sense ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show license and show version can give us more idea what you have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 21:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859716#M28293</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-05-20T21:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859718#M28294</link>
      <description>Ésta es la información que tengo:&lt;BR /&gt;License Info:&lt;BR /&gt;&lt;BR /&gt;License UDI:&lt;BR /&gt;&lt;BR /&gt;-------------------------------------------------&lt;BR /&gt;Device# PID SN&lt;BR /&gt;-------------------------------------------------&lt;BR /&gt;*0 CISCO2911/K9 FTX1529AHN3&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Technology Package License Information for Module:'c2900'&lt;BR /&gt;&lt;BR /&gt;-----------------------------------------------------------------&lt;BR /&gt;Technology Technology-package Technology-package&lt;BR /&gt;Current Type Next reboot&lt;BR /&gt;------------------------------------------------------------------&lt;BR /&gt;ipbase ipbasek9 Permanent ipbasek9&lt;BR /&gt;security None None None&lt;BR /&gt;uc None None None&lt;BR /&gt;data None None None&lt;BR /&gt;&lt;BR /&gt;Configuration register is 0x2102&lt;BR /&gt;&lt;BR /&gt;El ISP2 no lo usaría de manera redundante, solo lo quiero para unas VLAN, cada cierto tiempo darles mas velocidad hacia internet ésto porque el ISP 1 se satura y requiero mayor disponibilidad solo ciertos días para algunos equipos.&lt;BR /&gt;Si se requiere mayor información de mi parte me lo hacen saber.&lt;BR /&gt;&lt;BR /&gt;Gracias..</description>
      <pubDate>Mon, 20 May 2019 21:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859718#M28294</guid>
      <dc:creator>CRUZPEREZ518</dc:creator>
      <dc:date>2019-05-20T21:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859726#M28295</link>
      <description>&lt;P&gt;you can use this way also&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VLAN2 and VLAN3 NAt with ISP1, if ISP1 fails you can use ISP2 with NAT.&lt;/P&gt;
&lt;P&gt;using IPSLA and tracking&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 21:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859726#M28295</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-05-20T21:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859744#M28296</link>
      <description>Me podrías ayudar con algún ejemplo de configuración por favor, ya que soy nuevo en esto.&lt;BR /&gt;&lt;BR /&gt;Gracias.</description>
      <pubDate>Mon, 20 May 2019 22:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859744#M28296</guid>
      <dc:creator>CRUZPEREZ518</dc:creator>
      <dc:date>2019-05-20T22:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859895#M28297</link>
      <description>&lt;P&gt;Here is example : (take backup of config working one, understand the below config and apply as per the directions).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- configure interface&lt;/P&gt;
&lt;P&gt;interface Gi0/1 &lt;BR /&gt;description ISP1&lt;BR /&gt;ip address x.x.x.x 255.255.255.0 &amp;lt;- change as per the ISP1 IP address)&lt;BR /&gt;ip nat outside&lt;/P&gt;
&lt;P&gt;interface Gi0/2 &lt;BR /&gt;description ISP2&lt;BR /&gt;ip address y.y.y.y 255.255.255.0 &amp;lt;- change as per the ISP2 IP address)&lt;BR /&gt;ip nat outside&lt;/P&gt;
&lt;P&gt;- Route Maps for NATting traffic&lt;/P&gt;
&lt;P&gt;route-map backup permit 20&lt;BR /&gt;match ip address ISPInternet&lt;BR /&gt;match interface Gi0/2&lt;BR /&gt;route-map primary permit 10&lt;BR /&gt;match ip address ISPInternet&lt;BR /&gt;match interface Gi0/1&lt;/P&gt;
&lt;P&gt;- Configure Lan interface&lt;/P&gt;
&lt;P&gt;interface VLAN2&lt;BR /&gt;ip address z.z.z.z 255.255.255.0&lt;BR /&gt;ip nat inside&lt;/P&gt;
&lt;P&gt;interface VLAN3&lt;BR /&gt;ip address z1.z1.z1.z1 255.255.255.0&lt;BR /&gt;ip nat inside&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ip access-list extended ISPInternet&lt;BR /&gt;permit ip any any&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- Configure the two NAT statements&lt;/P&gt;
&lt;P&gt;ip nat inside source route-map backup interface Gi0/1 overload&lt;BR /&gt;ip nat inside source route-map primary interface Gi0/2 overload&lt;/P&gt;
&lt;P&gt;- your static routes:&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 x.x.x.x 10&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 y.y.y.y 20&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;EEM Script to Clear the NAT :&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;event manager applet CLEARNAT1&lt;BR /&gt;event syslog pattern “LINEPROTO-5-UPDOWN: Line protocol on Interface Gi0/2, changed state to down”&lt;BR /&gt;action 1.0 cli command “enable”&lt;BR /&gt;action 2.0 cli command “clear ip nat translation *”&lt;BR /&gt;event manager applet CLEARNAT2&lt;BR /&gt;event syslog pattern “LINEPROTO-5-UPDOWN: Line protocol on Interface Gi0/1, changed state to down”&lt;BR /&gt;action 1.0 cli command “enable”&lt;BR /&gt;action 2.0 cli command “clear ip nat translation *”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other Option with IP SLA Tracking :&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ip sla 20&lt;BR /&gt;icmp-echo 8.8.8.8 source-interface Gi0/1&lt;BR /&gt;timeout 1000&lt;BR /&gt;frequency 10&lt;BR /&gt;ip sla schedule 20 life forever start-time now&lt;BR /&gt;track 1 rtr 20 reachability&lt;/P&gt;
&lt;P&gt;- your static routes:&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 x.x.x.x track 1&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 y.y.y.y 2&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 07:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3859895#M28297</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-05-21T07:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Conectar 2 ISP a router</title>
      <link>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3860323#M28298</link>
      <description>Hola gracias por tu apoyo, disculpa mi ignorancia sobre el tema, al hacer éstos movimientos me quedo sin internet en todas mis VLAN y el router empieza a colapsar.&lt;BR /&gt;Ésta configuración que me indicas es para cuando un ISP falle, entre el otro o es para trabajar en conjunto? ya que lo que deseo hacer es dejar que todas mis VLAN sigan trabajando con el ISP1 y solo las VLAN que yo elija salgan ainternte por el ISP2.&lt;BR /&gt;&lt;BR /&gt;Ésta configuración es con la que trabajo actualmente y hace que todas mis VLAN salgan hacia internet por el ISP1 Gi0/1:&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;------------------------------------------&lt;BR /&gt;ip address 192.168.11.13 255.255.255.240&lt;BR /&gt;ip nat outside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;description ISP-200MB&lt;BR /&gt;ip address 192.168.12.13 255.255.255.240&lt;BR /&gt;ip nat outside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;!&lt;BR /&gt;ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.11.14&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.12.14 100&lt;BR /&gt;ip route 192.168.50.0 255.255.255.0 10.20.20.253&lt;BR /&gt;!&lt;BR /&gt;access-list 1 deny 192.168.180.0 0.0.3.255&lt;BR /&gt;access-list 1 permit any&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;---------------------------------&lt;BR /&gt;INTERFAZ DE PRUEBA PARA EL ISP2&lt;BR /&gt;interface GigabitEthernet0/0.127&lt;BR /&gt;description ISP2&lt;BR /&gt;encapsulation dot1Q 127&lt;BR /&gt;ip address 172.16.27.6 255.255.255.248&lt;BR /&gt;ip nat inside&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;ip policy route-map ISP2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 21 May 2019 16:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectar-2-isp-a-router/m-p/3860323#M28298</guid>
      <dc:creator>CRUZPEREZ518</dc:creator>
      <dc:date>2019-05-21T16:20:36Z</dc:date>
    </item>
  </channel>
</rss>

