cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2189
Views
4
Helpful
17
Replies

WAN routing for a subnet that appears in two places in the network

branfarm1
Level 4
Level 4

Hi everybody,

I was brought in last minute on a migration project where I discovered the first phase of the project is to move a subset of servers to a new location. The new location will eventually receive all of the servers currently in this subnet, 10.80.3.X/24, but for a short time there will be servers in two locations with the same subnet address.  Fortunately, the servers that are moving are only accessed by a handful of other machines.  I was wondering if PBR will solve my problem here, and if so, if my hardware can support it.  I have two 6509's w/Sup720 with PFC3A.

My first idea is to create an access-list for servers that will be accessing the devices that are moving, then use a route-map to set the next hop for these devices to be the firewall (WAN connectivity is still being built out, so I'm using an IPsec tunnel between two ASA's for now).

Will this work?

Thanks in advance,

Brandon

17 Replies 17

branfarm1 wrote:

I hear ya -- I spend 99% of my time changing firewall configs  -- not writing acl's for switches.

I can't remember -- do switches/router always use wildcard masks, or only sometimes?

For acls they always use wildcard masks.

One other thing. Don't be surprised if you don't see hits against the acls in your route-maps because PBR is done in hardware on the 6500 and acls are not incremented when processed in hardware.

Jon

Thanks for that -- I need to write myself a reminder about wildcard vs standard masks.

Thanks for all your help -- you're a lifesaver.

Happy holidays!

Brandon

branfarm1 wrote:

Thanks for that -- I need to write myself a reminder about wildcard vs standard masks.

Thanks for all your help -- you're a lifesaver.

Happy holidays!

Brandon

Brandon

No problem, glad to have helped.

Happy holidays to you as well.

Jon