I have 2 X cisco routers running BGP multihomed to our ISP, these two routers connect back in to our firewall (checkpoint) that is in a HA balanced pair. and for simplicities sake lets image I have 2 subnets that I advertise to the ISP A and B.
The ISP has set up two community strings that correspond to the priority they set the route to, so I am currently advertising both subnets out of the primary link with the better community and out the backup link with the poorer community, so all traffic comes in via one link.
What I would like to do is advertise subnet A out of link 1 and subnet B out of link 2, which is straight forward enough, but what I am not sure of is how best to do is the out bound policing.
I know I can statically do this on the fire wall if I wanted to, but this does not give me the dynamic fail-over I am looking for, and it means configuring the incoming routing policy on the routers and the outgoing on the firewall. Is there any way for an upstream router to request a downstream router takes the source IP address in to consideration when routing?
I want to say " for source addresses in subnet A use path to link 1 as DFGW, if source address in subnet B use path to link 2". So I know how to do this with static configuration, but what about with dynamic routing protocols.
Routing protocols populate the IP routing table and then the router can only forward based on destination IP address.
The only way to do it really is to use PBR on your routers together with tracking to failover if the link goes down.
Because you have two routers you would need to make one the default gateway for the firewall and then do the PBR there. Which means unless you have a separate link between the routers then traffic for subnet B is going to go to the primary router and then have to be sent back out of the same interface to get to the other router.
This is assuming the inside interfaces are connected to a switch ie. they don't connect directly to the firewalls.
Tracking could be tricky if you are receiving routes from the provider and exchanging them between your BGP routers because there would always be a way to get to the tracked IP so PBR might not realise the link has failed.
What I am considering doing is adding the Firewall in to the BGP domain, so it is aware of the exteranl link status to the ISP from both external routers. Although I could do the same by having the external routers advertise the default gateways (default information originate) with a tag/different metrics.
this way the fire wall will see two OSPF advertisements, one from each external router, this is exactly what happens now. with the primary sending a route with higher priority.
Question then.. Can I use the presence of a dynamic route in the policy of a router map?
"if source = A then use next hop of OSPF/BGP route of tag Y"
I will go look :) as if so this is an answer to the issue.
The following documents are reviewed on the Ask The Experts Session titled: Use Case Overview and Planning: Cisco DNA Center Project Planning.
Here you can find editable versions of the
Solution Requirements Document UCOP_CiscoDNACenterProjectPlann...
If so, we’d like to speak with you to understand you and your team’s process on how you monitor and troubleshoot network traffic.
We ask that you complete our brief survey: https://ciscoux.az1.qualtrics.com/jfe/form/SV_d4LYJ5oWqWj9CCy Based on your ...
Listen: https://smarturl.it/CCRS8E38 Follow us: twitter.com/CiscoChampionAdding learning capabilities to the internet will increase the overall network SLO and application experience. Real data driven experiments have shown that such an approach...
Listen: https://smarturl.it/CCRS8E37Follow us: twitter.com/ciscochampionSometimes, situations require temporary fixes. Sometimes, the network becomes an afterthought in overall office design and planning. In either situation, it may require netw...
In this special edition of the Insider Series, we hear from Cisco partners who have taken steps to be more eco-friendly and sustainable. We hear what inspires ASHRAE, Southwire, Igor, and NTT to create a workplace that is centered around people and how th...