Dual-Home Internet Connectivity Design Help

Unanswered Question
Oct 14th, 2009
User Badges:

Hi All,

Need your help on Dual- homed internet connectivity design.

Please refer the attached diagram & following design requirements


• We have our own APNIC range public ip address let's say /24 range A and B

• Router 1 connects to SP provider 1 & Router 2 connects to Service provider 2

• With Both SP we decided to run BGP session and advertise both APNIC range with both SP

• We do NAT or PAT our internal IP's at dedicated firewall with APNIC ip's

• We do segregation of Internet browsing & Project traffic at firewall ( APNIC Range A for Projects & APNIC B for internet browsing)

• VPN concentrator to be connected on DMZ interface of Firewall & outside interface of concentrator towards internet router.

• VPN connector will be used for some projects traffic.


Need to meet following requirements

• Project specific traffic needs to go via primarily Service Provider-1 & when primary fails should go via Service Provider-2

• Auto Failover is strongly recommended Project specific traffic.

• Internet browsing traffic should only go via Service Provider-2 only. We are ok if SP-2 fails & browsing stops.

Yes…this requirement would need policy based routing may be at router or at switch before the router.

Need your help to get the best design which meets the requirements.

Thanks in Advance



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
paolo bevilacqua Wed, 10/14/2009 - 02:48
User Badges:
  • Super Gold, 25000 points or more
  • Hall of Fame,

    Founding Member

Since your design has some complexity, would eb a good idea for you to take use of a certifies and reputable cisco engineer of proven experience.

The advice you can get on forums can never be complete enough to accomplish a business, an the implementation and testing pahse can be very long an painful if you do not have the necessary experience.

yogesh.suryawanshi Wed, 10/14/2009 - 03:05
User Badges:


I just need to have thoughts or logic which can meet this design requirment.

Hope someone will help with logic /idea



Anonymous (not verified) Wed, 10/14/2009 - 03:53
User Badges:


This Discussion