ISP failover and PAT connections

Unanswered Question
Apr 2nd, 2009

Ok, so I have an 2811 router that has IOS Firewall in it. Router is doing PAT for inside hosts, and is connected to two ISPs.

Solution desired is that one of the ISPs get used as a "backup". So SLA policies go in, and voilla. It fails over and starts using the backup isp, until that backup isp comes back up (via a pingable address in their network).

The only trouble in paradise is this:

Existing PAT translations do not get cleared, and so devices that are talking constantly (such as SIP devices) always have existing translations, and thus do not appear to fail over until they somehow create a new xlate (for example, rebooting a sip device).

Is there a way, in conjunction with ip sla policies, to force a clearing of all ip nat trans * ? Or, failing that, something else I should be using to get that functionality out of this failover scenario?

Thanks in advance for your help.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Edison Ortiz Thu, 04/09/2009 - 15:07

Yes, you are triggering my memory. I did a lab, which you were a thread participant, on this subject.

The problem with 'oer' is that is only available on selected trains.

I can't exactly recall if 'oer' on itself takes care of it. I believe on that lab, I had to use aggressive time-out as well.

__

Edison.

Actions

This Discussion