cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1362
Views
0
Helpful
2
Replies

ISG, bypass downstream traffic for IPv4 packets

arnydandi
Level 1
Level 1

Topology:

The Cisco ASR with ISG is sitting between the ISP's routeed IP subcribers (on the LAN side) and Internet edge router. 

ip subscriber routed
  initiator unclassified ip-address

 

Current state:

When an IP subscriber sends an outbound packet, ISG opens an IP session and allows bidirectional traffic to/from the IP subscriber. 

 

Problem: Downstream access from Internet to an IP subscriber that does not have an open session is not allowed. Example: an IP camera as an IP subscriber that should be reachable from the internet. This IP camera never initiates a session because it never sends the initial packet upstream. Thus it won't be accessible from Internet ever. 

 

Cisco has a bypass downstream traffic command for IPv6 traffic (passthru downstream ipv6) but nothing for IPv4. Any workaround for IPv4 traffic? So I want downstream IPv4 to be allowed regardless of the client session. 

Thanks,

Arny

 

 

2 Replies 2

bobbydazzler
Level 1
Level 1
Hello Arny,
have you found a way to achieve this?
Best regards

nope... not yet...


@bobbydazzler wrote:
Hello Arny,
have you found a way to achieve this?
Best regards