11-19-2019 12:38 PM
Hello Cisco Community! I have a 3750 acting as WAN switch connected to CrownCastle and MetTel
I was able to get the routing up for the CrownCastle side as that circuit was available/installed first..so the default route that's configured routes to Crown currently.... now that MetTel has been installed, I'd like to carve out a few ports on the 3750 for MetTel and route it's respective public LAN IP's out to MetTel.
vlan 222 - MetTel LAN
vlan 444 - MetTel WAN
Is it possible to configure a routemap for just the 2nd ISP to be used? What am I missing? I configured an ACL, a route map, and applied the route-map to the vlan interface. I must be missing something silly! Please help! Thank you!
Configuration is below!:
interface FastEthernet0
no ip address
no ip route-cache
shutdown
!
interface GigabitEthernet1/0/1
switchport access vlan 333
spanning-tree portfast
!
interface GigabitEthernet1/0/2
switchport access vlan 333
spanning-tree portfast
!
interface GigabitEthernet1/0/3
switchport access vlan 333
spanning-tree portfast
!
interface GigabitEthernet1/0/4
switchport access vlan 333
spanning-tree portfast
!
interface GigabitEthernet1/0/5
switchport access vlan 333
spanning-tree portfast
!
interface GigabitEthernet1/0/6
switchport access vlan 333
spanning-tree portfast
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
switchport access vlan 50
!
interface GigabitEthernet1/0/11
switchport access vlan 50
!
interface GigabitEthernet1/0/12
switchport access vlan 50
!
interface GigabitEthernet1/0/13
switchport access vlan 222
!
interface GigabitEthernet1/0/14
switchport access vlan 444
!
interface GigabitEthernet1/0/15
switchport access vlan 444
!
interface GigabitEthernet1/0/16
switchport access vlan 444
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
switchport access vlan 222
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
!
interface GigabitEthernet1/0/24
description ToCrownModem
switchport access vlan 777
!
interface GigabitEthernet1/1/1
switchport access vlan 444
speed nonegotiate
!
interface GigabitEthernet1/1/2
switchport access vlan 444
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
switchport access vlan 444
switchport mode access
speed nonegotiate
!
interface TenGigabitEthernet1/1/2
!
interface Vlan1
no ip address
shutdown
!
interface Vlan50
description AryakaTransitVLAN
no ip address
!
interface Vlan222
description MetTelLAN
ip address x.x.x.123 255.255.255.248
!
interface Vlan333
description CrownCastleLAN
ip address x.x.x.33 255.255.255.240
!
interface Vlan444
description MetTelWAN
ip address x.x.x.30 255.255.255.252
!
interface Vlan777
description CrownCastleWAN
ip address x.x.x.146 255.255.255.252
!
!
ip route 0.0.0.0 0.0.0.0 x.x.x.145
!
access-list 110 permit ip 1.1.1.0 0.0.0.255 any
!
route-map To-MetTelWAN permit 10
match ip address 110
set ip next-hop 1.1.1.29
11-19-2019 12:43 PM - edited 11-19-2019 12:44 PM
HaemoWANswitch#show route-map To-MetTelWAN
route-map To-MetTelWAN, permit, sequence 10
Match clauses:
ip address (access-lists): 110
Set clauses:
ip next-hop x.x.x.29
Policy routing matches: 0 packets, 0 bytes
HaemoWANswitch#
11-19-2019 12:58 PM
Hi,
You shouldn't need any route-map.
Configure a default route toward CrownCastle which you already have (ip route 0.0.0.0 0.0.0.0 x.x.x.145)
Now, configure a second default route toward MetTel (ip route 0.0.0.0 0.0.0.0 x.x.x.29)
This will load balance traffic between the 2 ISPs for you. If you want CrownCastle to be the primary and MetTel to be the backup provider you can configure MetTel with a higher AD (100).
ip route 0.0.0.0 0.0.0.0 x.x.x.145
ip route 0.0.0.0 0.0.0.0 x.x.x.29 100
HTH
11-19-2019 01:03 PM
Thank you for the reply Reza!! I do not want to load balance over the two ISP. I would like to route CrownLAN traffic over the CrownWAN link...
and MetTelLAN traffic over the MetTelWAN link.
I should use a route-map for this scenario, right?
thanks again! I really appreciate the help!
11-19-2019 01:18 PM
Ok, than in that case you need route-maps.
HTH
11-19-2019 01:21 PM
11-19-2019 01:34 PM
I don't see anything on interface vlan 222.
can you confirm?
HTH
11-19-2019 01:40 PM
11-19-2019 01:47 PM
Ok, is this just a regular 3750 or 3750G, 3750x, etc..?
Can you post "sh ver"?
Just wanting to make sure your image support route-maps.
11-19-2019 01:48 PM
11-19-2019 04:05 PM
Got the show SDM Prefer output--- desktop default template?!?!
HaemoWANswitch#show sdm prefer
The current template is "desktop default" template.
The selected template optimizes the resources in
the switch to support this level of features for
8 routed interfaces and 1024 VLANs.
number of unicast mac addresses: 6K
number of IPv4 IGMP groups + multicast routes: 1K
number of IPv4 unicast routes: 8K
number of directly-connected IPv4 hosts: 6K
number of indirect IPv4 routes: 2K
number of IPv6 multicast groups: 64
number of IPv6 unicast routes: 106
number of directly-connected IPv6 addresses: 74
number of indirect IPv6 unicast routes: 32
number of IPv4 policy based routing aces: 0
number of IPv4/MAC qos aces: 0.5K
number of IPv4/MAC security aces: 0.875k
number of IPv6 policy based routing aces: 0
number of IPv6 qos aces: 0
number of IPv6 security aces: 60
HaemoWANswitch#
11-19-2019 01:33 PM
Hello,
in your access-list 110, you are permitting 1.1.1.0/24, so that is the traffic you want to go to MeT Tel WAN. On which interface is that traffic entering your layer 3 switch ? There is no interface on the switch with an IP address that corresponds to 1.1.1.0/24.
Either way, that is the interface where you would have to apply the route map using the command 'ip policy route-map To-MetTelWAN'. On which interface did you configure this ( as I don't see it in the config you have posted) ?
11-19-2019 01:42 PM
11-19-2019 03:10 PM
try it
!
route-map To-MetTelWAN permit 10
match ip address 110
set ip default next-hop 1.1.1.29
11-19-2019 03:51 PM - edited 11-19-2019 03:54 PM
Hello
First of all you need to apply the route-map to the l3 interface
interface Vlan222
ip policy route-map To-MetTelWAN
Also does the network in the ACL to be policy routed sit behind vlan 222 because it needs to be?
Lastly for PBR to work on a 3750, You may need o change the SDM template.
show sdm prefer
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide