I would like to influence inbound traffic into a site based on the source AS, is this possible?
I have two circuits communicating with two different business units
Outbound is fine, using local preference
I want all inbound and outbound traffic to use the circuits as follows
Circuit A = BU 1
Circuit B = BU 2
Obviously the site is advertising the same routes from both circuits. So I can't use MED for the local routes as traffic will come in one way only
what I want to do is match on source AS number, so
If AS 2 (BU 2) wants to access the site, then they will use circuit B
I was thinking I could do the following on the Circuit A, whereby if source is AS 2 (BU 2) then prepend the route, but I have not got this right as I need to actually prepend the local AS!!! So that the BU 2 traffic preferes circuit B
ip as-path access-list 1 permit _2$
route-map BU 2 permit 10 match as-path 1 set as-path prepend 2 2
neighbor x.x.x.x route-map BU 2 out
I am not sure if this is even possible? Any help much appreciated.
Note that all connections to the cloud are eBGP
Within the local site, the router to router connections are iBGP
>> I have two circuits communicating with two different business units
Do you mean you have direct eBGP sessions on local AS between (localAS, AS1) on circuitA and (localAS, AS2) on circuitB?
If this is the case, you don't need to do anything to achieve the desired result as from the point of view of AS2 the direct eBGP session on circuitB is a better path then going through AS1 and circuitA
(shortest AS path is preferred)
Your attempts are conceptually wrong as AS2 choices are not influenced by what you do on the other eBGP session. You could achieve that all return traffic comes back via circuitB even if originated in AS1. But you don't want this.
if AS1 and AS2 have no direct eBGP session with local AS of local site the result is not guaranteed and you cannot influence it in any way it is a choice of administrators of AS2 at that point what path to prefer to go back to you.
This is actually a pretty cool feature, i didn't even know it existed until I was looking for a solution to advertise a subnet (prefix in BGP talk), only if a certain condition existed. This is exactly what conditional advertisements does
j ai une question j ai achete un routeur cisco 887VA-k9 , je le configuré avec la configuration ci- dessous
si je le lier avec mon pc portable sur l un de ses ports directement ça marche toute est bien ( la connexion internet + m...
Attached policy provides CLI access to the Cisco 4G router over text messaging. Two files are in the attached .tar file:
2. PDF with instructions on how to load and use the .tcl file.