12-02-2005 08:22 AM - edited 03-03-2019 11:07 AM
I have two routers on a common subnet running HSRP connected to another pair of routers also running HSRP via a couple of WAN links, 1 10 Meg and 1 5 Meg. The 5 Meg link is a LAN extension, so EIGRP forms neighbour relationships OK, but the 10 Meg link crosses the telco network which uses BGP.We got them to redistribute our EIGRP into their BGP and redistribute out again at the other end, played with the EIGRP weighting and got the 10 M link as the preferred route. All seemed OK....until we tested the failover! The routers failover OK, traffic switches to the backup 5M link, but the clients lose their connection to the webservers which are behind a couple of CSS 11500's. Pinging from the client side routers works if we use the backup router, but fails from the main router. When the network is in the normal state(no failover) pinging from either router works! I've attached a sanitized copy of the configs for the routers. Does anyone have any ideas what to check next?
Thx
George
12-02-2005 12:20 PM
Appears NAT is your problem.
As the NAT table on the routers don't get replicated, the failover you are seeing is non-stateful, i.e all existing tcp/udp sessions will hang. Connections have to be restarted.
HTH,
Sundar
12-02-2005 12:36 PM
Hello George,
in addition to Sundar's post, there are basically two approaches to get around the HSRP/NAT failover issue, you might want to have a look at the documents below:
Stateful Failover of Network Address Translation (SNAT)
http://www.cisco.com/en/US/products/sw/iosswrel/ps1839/products_white_paper09186a00801124ad.shtml
NAT - Static Mapping Support with HSRP for High Availability
http://www.cisco.com/en/US/products/sw/iosswrel/ps1839/products_feature_guide09186a0080087c4c.html
Regards,
GP
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide