cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
702
Views
0
Helpful
9
Replies

ISP Redundancy on Cisco 9200

brooksfam23701
Level 1
Level 1

Currently we have failover ISP but SIC will not establish over the 2nd ISP without manual intervention.

 

Both ISP terminate from their corresponding interfaces with different IP addresses directly to the firewall with ISP Redundancy enabled. When ISP A goes down we still have local internet over ISP B but we cannot get SIC to failover to ISP B without manually changing routes and reestablishing SIC.

 

My thought is to leverage an existing 9200 we have so I looked into doing some type of VRRP but can only seem to configure it on the VLAN interface level and not the interfaces themselves. I feel like I am missing something. If there is anyone out there with some configuration examples or suggestions I would Love IT.

 

Thank you

Todd B.

9 Replies 9

marce1000
VIP
VIP

 

 - I don't think the 9200 can do VRRP , you are probably better of with PBR (policy based routing) on the Firewall (if available).

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Thank you so much for the quick response.

 

I had found some reading on it last week and in fact did find that it was configurable by enabling fhrp version vrrp v3 but again not sure I am going the right way. I had also read on the PBR and I have a meeting with our Firewall Vendor tech support tomorrow.

 

This is what I have in my switch so far and I thought I could put an IP on another VLAN and complete the VRRP config from there???

 

fhrp version vrrp v3

interface Vlan199
ip address xxx.xxx.xxx.251 255.255.255.0
vrrp 1 address-family ipv4
exit-vrrp

balaji.bandi
Hall of Fame
Hall of Fame

Hope we are looking  ISPA and ISPB connected switch (that is Cat9200)?

 

Cat 9200 have limited command set what you looking to do.

 

why not run FHRP your favourite between Routers (that is ISPA and ISPB)

 

what is exiting Load balance ? machnism, Active/ Active or Active standby ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I would have loved that solution with an ASR but turns out it will take over 9 months to get one probably. That was my first suggestion until I got quotes back and all said no less than 6 to 9 month lead time. The problem with the ISP routers is they are completely managed by the separate ISP and they do not like to play nice together so we would need to bring both circuits into an ASR and do a Virtual IP. Again this was my first solution of choice smh.

Sorry the CAT 9200 is our managed switch where we can terminate both ISP but then go to the firewall.

 

Currently both ISP go directly to the Firewall and the firewall supports ISP redundancy out of the box but does not support SIC failover on those ISP links to the other Firewalls in the WAN. So if the ISP that has SIC going over it fails we still have internet locally but all the outlying sites have nothing.

how is your failover working now ?  what Checkpoint version is this ? R80 ?

 

how about return traffic failover ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

That's just it the failover is not working today. It is Checkpoint R80 and when the main ISP fails we have internet here in our office only but no SIC or internet at the other sites because they get internet though us via the SIC link.

but no SIC or internet at the other sites because they get internet though us via the SIC link.

Can you explain what is SIC Link ? (you mean Manange CP FW using Management ?) 0r i miunderstood this ?

 

Couple quesiton that can be fixed if understand your setup :

 

1. Right side FW (INET for all sites)  means that FW using to connect to internet, that is Main site.

2. ISP A and ISP B is the MPLS Links or Internet Links ?

3. Remote FW and FW  have VPN ?

4. CLOUD ? what you mean Cloud ( is this hosted any AWS ? or any other ?)

 

Can you make some traffic flow and descriptions so we (as community can offer some solution to fix)

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Can you explain what is SIC Link ? (you mean Manange CP FW using Management ?) 0r i miunderstood this ?   SIC is Secure Internal Communication link which makes all traffic flow between firewalls and we have no local internet running at the remote sites. They pull their internet from our site ISP A at the time.

 

Couple quesiton that can be fixed if understand your setup :

 

1. Right side FW (INET for all sites) means that FW using to connect to internet, that is Main site. Yes that is the main site but ISP A has to be up for the remote sites to establish SIC and connect to the internet.

2. ISP A and ISP B is the MPLS Links or Internet Links ? ISP A and B are straight Ethernet IP links directly to the internet.

3. Remote FW and FW have VPN ?

4. CLOUD ? what you mean Cloud ( is this hosted any AWS ? or any other ?) Cloud is meaning the internet itself. Each remote site has an Ethernet IP internet circuit but the firewall requires the SIC connection to our main firewall for them to pull internet and internal traffic from us.

Can you make some traffic flow and descriptions so we (as community can offer some solution to fix)

Review Cisco Networking for a $25 gift card