cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
725
Views
0
Helpful
10
Replies

Multiple Internet Access Points in Different Regional Offices

dmpeter666
Level 1
Level 1

I have 5 regional offices and an HQ office. Right now all traffic comes through HQ via bgp for internet access, I have an overload statement for natting since it is on a sub interface, and HQ access uses the VPLS address to our public address. I have an internet access point in 1 regional office that I cant get other regional offices to see or to route traffic out of, also I cant even get traffic from that office out of that sub interface, it comes through are HQ office.

I have tried the overload statement in that regional office but traffic will not go anywhere. I tried all traffic using a ip route statement but same result. It may be bgp, our isp has everything hardcode so we can not manipulate our bgp commands. We do advertise that subnet to come to HQ.

If anyone has any information or has run into the same problem please let me know.

I will provide configs.

Thanks.

1 Accepted Solution

Accepted Solutions

Hi

Thank you for the update, good to know it was fixed.

Have a great day

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

View solution in original post

10 Replies 10

Julio E. Moisa
VIP Alumni
VIP Alumni

Hi 

Please correct me but you want to manipulate the traffic of Internet to get it locally, BGP is advertising a default route, a local default route should be preferred over BGP (AD: 1 over eBGP 20 / iBGP 200) . Now if it is not working (for any reason) your could use route-maps / set ip next hop to manipulate the traffic. Could you please share your topology and configuration / show ip route on the branch?

Thank you 




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

I will modify the config tomorrow morning and then post it. If I modify it now they will lose internet connectivity.

Thanks for the response.

That sounds good, please keep me posted. If your are going to use the local internet access for that specific brand remember to verify the NAT as well. The rest of the branches will still using the HQ internet access. 

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Here is my config. Also the local subnet for that officeuses 172.16.x.x/25.

Thanks again.

Thank you, please let me take a look to the file and share may findings. 




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Hi

If this router is a branch and it has a local internet access, your config looks fine, you need to configure a default route:

ip route 0.0.0.0 0.0.0.0 <next hop IP 'ISP' router>

or 

ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0/1.2

Please see the attachment, it is my understanding. Just the Branch 3 will use the local internet access. 

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Yes. Thank you and I will try that in the morning again.

Thanks again.

Thank you, please keep me posted, I saw you have configured the ip nat inside on a sub interface, I dont know about your entire network but remember to configure the ip nat inside under the interfaces where the local private networks are known to get Internet access.

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Thanks again. I just had the inside nat in the wrong place. Instead of having it on VPN sub interface I needed it on the main interface.

Hi

Thank you for the update, good to know it was fixed.

Have a great day

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<