11-09-2017 04:29 PM - edited 03-05-2019 09:27 AM
Solved! Go to Solution.
11-10-2017 04:54 AM
Hi
All you traffic is already passing through a svi or physical L3 interface where your default route is, i mean svi facing your isp1. You can apply it to that svi to reroute the traffic on isp2 lan interface
11-09-2017 06:47 PM
11-10-2017 05:05 AM
Hi Francesco, thanks for your reply.
This is the configuration done:
Core Site A:
ip route 10.10.88.0/21 10.10.0.3 name ISP2 (Send all traffic to SiteB thru ISP2)
ip access-list LAN_to_SiteB (Match with traffic from LAN to SiteB)
10 permit ip 10.0.0.0/8 10.10.88.0/21
ip access-list INET_to_SiteB (Match with traffic from INTERNET to SiteB)
10 permit ip any 10.141.88.0/21
route-map SiteB_DUAL_MPLS permit 20 (Set next hop to ISP1 to traffic matching INET_to_SiteB)
match ip address INET_to_SiteB
set ip next-hop 10.10.0.2
route-map CBA_DUAL_MPLS permit 30
match ip address LAN_to_SiteB
interface Vlan1000 (SVI with Internet ingress traffic)
ip policy route-map SiteB_DUAL_MPLS
interface Vlan20 (SVI with Internet ingress traffic)
ip policy route-map SiteB_DUAL_MPLS
Core Site B:
ip route 0.0.0.0/0 10.10.88.2 name ISP1
ip route 10.0.0.0/8 10.10.88.3 name ISP2
11-11-2017 04:04 PM
11-10-2017 01:15 AM
Hello,
in addition to Francesco's post, PBR has some peculiar limitations on the Nexus 5600 (as outlined in the link below).
Either way, the below is what I have come up with:
feature pbr
ip access-list LAN_TO__LAN
permit ip 10.0.0.0 0.255.255.255 10.10.88.0 0.0.7.255
ip policy route-map LAN_THRU_ISP2
match ip address LAN_TO__LAN
set ip next-hop 10.0.0.3
11-10-2017 04:39 AM - edited 11-10-2017 04:39 AM
I forgot to mention that in Site A we have several SVIs with 10.10.0.0/16 subnetted, and if I'm not wrong, the route-map should be linked to the ingress L3 interface, right?
So, I should issue this commands on every Interface VLAN in "Core Site A":
interface Vlan1000
ip policy route-map LAN_THRU_ISP2
interface Vlan20
ip policy route-map LAN_THRU_ISP2
Is there any other way to do this?, Because I already have SVI with other PBR assigned.
11-10-2017 04:54 AM
Hi
All you traffic is already passing through a svi or physical L3 interface where your default route is, i mean svi facing your isp1. You can apply it to that svi to reroute the traffic on isp2 lan interface
11-10-2017 04:54 AM
Hello,
before doing anything else, does it work for the SVIs you have applied it to ?
interface Vlan1000
ip policy route-map LAN_THRU_ISP2
interface Vlan20
ip policy route-map LAN_THRU_ISP2
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: