cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
475
Views
0
Helpful
0
Replies
Highlighted
Beginner

3 ASN, 2 ISP, 2 ASR1000X, path issues over internet

Hello all,

 

I've run into an issue with my enterprise network, we currently use AS7029 on our Primary ASR as well as AS 600/3112 on our Secondary ASR.  I can see our traffic go outbound but not all of that traffic returns back to my network, this has resulted in a lot of connection timeouts, or resets as browser errors for the clients.  When I shut down one ISP everything works and this works both ways between my different ISPs.  Another weird thing is that some of my external NAT'd IPs connect to the internet just fine with no issues, but others do not.  Our clients are having most of their issues reaching anything that is hosted by AWS or Akamai, and it is intermittent as only some clients run into this issue and others don't, in addition to this some of our exteneral NAT IPs run into the issue while others are immune.  I recently found out that both of my ISPs are peering partners with both services which I'm not sure if that could be an issue and how would I get around that?

 

 

AR1:

Single-homed

Connected via AS7029

Set as Primary, previously had AS prepend statement repeated 3 times, removed but has not fixed issues

BGP:

x.x.72.0/21

x.x.73.0

x.x.74.0

x.x.75.0

x.x.76.0

x.x.77.0

x.x.78.0

 

AR2:

Connected via AS600/3112

Dual-homed via router on a stick

BGP

x.x.72.0/21

x.x.72.0

x.x.73.0

x.x.74.0

x.x.75.0

x.x.76.0

x.x.77.0

x.x.78.0

x.x.79.0

 

Flow of traffic Outbound:

 

Client Site > WAN > 7k > F5 > iBoss > ASA > AR1 > AS7029 or (AR2 > AS600/3112)

 

What I noticed in a traceroute yesterday prior to testing one network on and off the traffic flowed like this:

AR1 > AR2 > AS600 > AS7029 > AWS > AS7029 > AWS > Timeout

 

What could be the cause of the above issue when a traceroute is performed?

 

I'm willing to provide some configuration however TAC has validated that there is nothing wrong on my end I just want to get a better understanding of why this could be happening.

 

Any suggestions are welcome, I've also considered taking half of my /21 and forwarding it through one router while pruning it on the other to make the flows of traffic more equal so it would be like this.

 

AR1

x.x.72.0

x.x.73.0

x.x.74.0

x.x.75.0

x.x.79.0

 

AR2

x.x.72.0

x.x.76.0

x.x.77.0

x.x.78.0

x.x.79.0

 

Everyone's tags (5)
CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards