cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1214
Views
20
Helpful
12
Replies

Routing a single device

jasongr33nway
Level 1
Level 1

Hello,

 

I need to test ipsec config at DR site. Our L3 device uses BGP. I need to take one device and force it's traffic to our DR and not use the BGP route. Can anyone help me with this config?

12 Replies 12

balaji.bandi
Hall of Fame
Hall of Fame

You need to show your toplogy and some configuration, with the information you have provided not going enough for us to think what is exiting setup and arrangements.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

We have devices that need data routed out of our firewall and over an IPsec tunnel to a vendor. I am in the process of configuring our DR to be able to route this traffic to our vendor if our main site goes down. Right now our L3 device has BGP routes that point to our firewall as a next hop for this traffic. I need to take one of the devices that typically uses the BGP routes to instead route out of our MPLS interface and to our DR site in order to test that the IPsec tunnel is configured properly.

 

Current Topology: Packet -----> L3 Device ----> Firewall ------> IPsec Tunnel

 

 

Testing Topology: Packet -----> L3 Device ----> MPLS ------> DR L3 Device------> DR Firewall ----->IPsec Tunnel

 

 

 

 

Jaderson Pessoa
VIP Alumni
VIP Alumni

Hello,

You can use

network backdoor

 

See http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a00800c95bb.shtml#bgpbackdoor

for an example.

Jaderson Pessoa
*** Rate All Helpful Responses ***

Hello

I would say BGP backdoor feature is a good feature and suggestion  however it would only be really applicable if there is an igp running between the alternative path which at this time the OP doesn’t state  and then if you have hundreds of routes or subnets to advertise it could be a really quite administrative- other possible options may in include PBR or conditional route advertisement.

 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Thanks everyone for all of your help.

 

I don't believe BGP Backdoor would help me, unless I am not understanding something in the BGP Case Study link.

 

I have multiple devices that need to send traffic over the IPsec tunnel on our local firewall which they are doing now and with no issues. I am trying to test the DR firewall config without changing the route path for all of our devices and possibly interrupting normal business operations. That's why I was hoping I could take one of those devices and route it's traffic towards DR while the rest of the devices continue to route traffic as they normally would out of our local firewall.

Hello


@jasongr33nway wrote:

Thanks everyone for all of your help.

 

I don't believe BGP Backdoor would help me, unless I am not understanding something in the BGP Case Study link.

 

I have multiple devices that need to send traffic over the IPsec tunnel on our local firewall which they are doing now and with no issues. I am trying to test the DR firewall config without changing the route path for all of our devices and possibly interrupting normal business operations. That's why I was hoping I could take one of those devices and route it's traffic towards DR while the rest of the devices continue to route traffic as they normally would out of our local firewall.


Sounds like PBR would be the answer, post a topology diagram so we can review it - and if applicable configuration your router

 

 

 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Hello,

Yes, now we have a clear vision about your doubt. You will need a PBR to control this traffic between these devices.

check link below to more information.
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/15-0SY/configuration/guide/15_0_sy_swcg/policy_based_routing_pbr.pdf

Jaderson Pessoa
*** Rate All Helpful Responses ***

@Jaderson Pessoa 


@Jaderson Pessoa wrote:
Yes, now we have a clear vision about your doubt.

Really?

@jasongr33nway  If you have posted the topology/configuration already - then apologies i may have missed it -

FYI -without knowing your current setup it would be hard to suggest the correct resolution PBR or otherwise


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Thanks for it. You has right :)

 

Because he input it:

Current Topology: Packet -----> L3 Device ----> Firewall ------> IPsec Tunnel

 

 

Testing Topology: Packet -----> L3 Device ----> MPLS ------> DR L3 Device------> DR Firewall ----->IPsec Tunnel

Jaderson Pessoa
*** Rate All Helpful Responses ***

jasongr33nway
Level 1
Level 1

Thanks for al of your help guys!

 

PBR worked just as I needed it to.

Thanks for the update confirming that PBR did work and was the solution for your requirement.

 

HTH

 

Rick

HTH

Rick

Great mark as solved and helpful all post that were help you
Jaderson Pessoa
*** Rate All Helpful Responses ***
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card