11-08-2017 09:39 AM - edited 03-05-2019 09:26 AM
We have a netblock of IPs that are configured for BGP between 2 ISPs for failover and redundancy. We had an issue with our primary site ISP and brought it back online. Everything seemed fine and existing IPs and NATs are working properly for the primary site. However I tried to set up a new NAT at that site with another public IP that should be tied to this ISP and I can't get any reply packets back from the internet. Our theory is that the IP is tied to the secondary ISP for some reason during a BGP failover and never came back.
Unfortunately the person who configured BGP is long gone and I am not network expert. I know enough to be dangerous :)
Can someone help me figure out how to reset the BGP so that the IPs are associated with the primary ISP instead of the secondary? How can I restore this? It was my understanding this configuration was supposed to be pretty automatically but something has clearly gone awry.
11-08-2017 12:22 PM
11-08-2017 12:44 PM
Hello,
I would get on the phone with your ISP to make sure you still have access to the entire range. You own 510 public addresses...how many of those have you actually been actively using ?
204.152.150.207 happens to be the broadcast address for the 204.152.150.0/28 network.
11-08-2017 12:47 PM
Broadcast address for the 204.152.150.192/28 subnet ?
Jon
11-08-2017 12:50 PM
Sorry, I meant the 204.152.150.200/28 subnet...
Either way, checking with the ISP can't hurt.
11-08-2017 12:56 PM
ARIN registration looks good, but that doesn't mean the ISP could not have made a mistake:
Source: whois.arin.netIP
Address: 204.152.150.207
Name: KKAMERICA
Handle: NET-204-152-150-0-1
Registration Date: 2/22/11
Range: 204.152.150.0-204.152.151.255
Org: K+K America CorporationOrg
Handle: KAC-21Address: 770 S 70th Street
City: MilwaukeeState/Province: WIPostal Code: 53214Country: UNITED STATES
11-08-2017 12:57 PM
See my last post, I have just done traceroutes to working and non working IPs and they all end up at the 2911 router so i think the ISP is routing everything correctly.
Jon
11-08-2017 01:02 PM
11-08-2017 12:55 PM
11-08-2017 01:37 PM
Hello,
what if you configure your static NAT entry with the actual interfaces instead of any/any:
object network VM-STOCKIQ
nat (inside,outside) static VM-STOCKIQ-PUBLIC net-to-net
11-08-2017 01:48 PM
11-08-2017 01:56 PM
Thanks for letting us know.
What I don't understand is why it did not show when I asked for a static route output from the router, still good to hear it is working now.
Jon
11-09-2017 04:25 AM
11-09-2017 04:31 AM
So the switch was L3 after all.
Okay, that makes sense now, thanks for clearing that up.
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide