2 ISP - Failover - Router Cisco 1801
Inviato: ven 18 feb , 2011 10:29 pm
Ragazzi dopo 5 nottate in bianco getto la spugna e chiedo il vostro prezioso aiuto.
Finalmente mi è arrivato un Cisco 1801 e dopo aver scaricato di tutto e di più da internet e specialmente dal vostro forum ho cominciato a smanettare non avendo esperienza nella configurazione di routers.
Ho preso spunto dal seguente topic viewtopic.php?f=6&t=14167 (WAN - Load Balancer e Failover) avendo una configurazione simile...almeno credo:
ISP Tiscali (IP Statico - PPPoA - non conosco il next-hop)
ISP BT Italia (IP Statico attraverso un loro router con NAT 1:1 l'IP del mio router è 10.0.1.1 il gateway 10.0.1.2 255.255.255.252)
Vorrei abilitare la navigazione libera su ISP Tiscali e quella condizionata (VPN, RDP, ecc.) su BT Italia.
Ho impostato la configurazione allegata e:
1) con le due track up risponde al ping una sola interfaccia (la prima che va up)
2) con una track down l'altro ISP che era down passa up
A me servirebbero tutte e due le connessioni attive con traffico regolato dalle acl.
Help me!!
*********************************************************************************************
no ip source-route
!
ip cef
no ip bootp server
ip domain name mydomain.lan
ip name-server 213.205.32.70
ip name-server 212.17.192.216
login block-for 300 attempts 3 within 30
login on-failure log
no ipv6 cef
!
multilink bundle-name authenticated
!
license udi pid CISCO1801/K9 sn FHK144374NN
username admin privilege 15 secret 5 $1$AIfC$lDTq2uzL/sY2YB88DiGU51
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
track 1 interface Dialer0 ip routing
delay down 5 up 30
!
track 2 ip sla 2 reachability
delay down 1 up 1
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
no atm ilmi-keepalive
!
pvc 8/35
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface BRI0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
encapsulation hdlc
shutdown
!
interface FastEthernet0
description ***Link to ISP BTITALIA***
ip address 10.0.1.1 255.255.255.252
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
!
interface FastEthernet5
!
interface FastEthernet6
!
interface FastEthernet7
!
interface FastEthernet8
!
interface Vlan1
description ***Inside LAN***
ip address 192.168.210.10 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1452
ip policy route-map PBR
!
interface Dialer0
description ***Link to ISP TISCALI***
ip address negotiated
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
ppp chap hostname [email protected]
ppp chap password xxxxxxxxxxxx
ppp pap sent-username [email protected] password xxxxxxxx
no cdp enable
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 1000
!
ip nat inside source route-map ISP_BTITALIA interface FastEthernet0 overload
ip nat inside source route-map ISP_TISCALI interface Dialer0 overload
ip route 0.0.0.0 0.0.0.0 Dialer0 track 1
ip route 0.0.0.0 0.0.0.0 10.0.1.2 track 2
!
ip access-list extended PBR_NAT_ISP_BTITALIA
permit ip 192.168.210.0 0.0.0.255 any
ip access-list extended PBR_NAT_ISP_TISCALI
permit ip 192.168.210.0 0.0.0.255 any
!
ip sla 2
icmp-echo 10.0.1.2
timeout 500
threshold 2
frequency 3
ip sla schedule 2 life forever start-time now
logging trap debugging
access-list 100 remark ***NAT 0***
access-list 100 permit ip 192.168.210.0 0.0.0.255 any
no cdp run
route-map ISP_BTITALIA permit 10
match ip address 100
match interface FastEthernet0
!
route-map PBR permit 10
match ip address PBR_NAT_ISP_BTITALIA
set ip next-hop verify-availability 10.0.1.1 2 track 2
!
route-map PBR permit 20
match ip address PBR_NAT_ISP_TISCALI
set ip next-hop verify-availability AAA.BBB.CCC.DDD 1 track 1
(NON CONOSCO IP NEXT-HOP PERTANTO HO INSERITO IL MIO IP STATICO TISCALI – LA COSA MI VIENE SEGNALATA ANCHE DA IOS)
!
route-map ISP_TISCALI permit 10
match ip address 100
match interface Dialer0
*********************************************************************************************
Finalmente mi è arrivato un Cisco 1801 e dopo aver scaricato di tutto e di più da internet e specialmente dal vostro forum ho cominciato a smanettare non avendo esperienza nella configurazione di routers.
Ho preso spunto dal seguente topic viewtopic.php?f=6&t=14167 (WAN - Load Balancer e Failover) avendo una configurazione simile...almeno credo:
ISP Tiscali (IP Statico - PPPoA - non conosco il next-hop)
ISP BT Italia (IP Statico attraverso un loro router con NAT 1:1 l'IP del mio router è 10.0.1.1 il gateway 10.0.1.2 255.255.255.252)
Vorrei abilitare la navigazione libera su ISP Tiscali e quella condizionata (VPN, RDP, ecc.) su BT Italia.
Ho impostato la configurazione allegata e:
1) con le due track up risponde al ping una sola interfaccia (la prima che va up)
2) con una track down l'altro ISP che era down passa up
A me servirebbero tutte e due le connessioni attive con traffico regolato dalle acl.
Help me!!
*********************************************************************************************
no ip source-route
!
ip cef
no ip bootp server
ip domain name mydomain.lan
ip name-server 213.205.32.70
ip name-server 212.17.192.216
login block-for 300 attempts 3 within 30
login on-failure log
no ipv6 cef
!
multilink bundle-name authenticated
!
license udi pid CISCO1801/K9 sn FHK144374NN
username admin privilege 15 secret 5 $1$AIfC$lDTq2uzL/sY2YB88DiGU51
!
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
!
track 1 interface Dialer0 ip routing
delay down 5 up 30
!
track 2 ip sla 2 reachability
delay down 1 up 1
!
interface ATM0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
no atm ilmi-keepalive
!
pvc 8/35
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
!
interface BRI0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
encapsulation hdlc
shutdown
!
interface FastEthernet0
description ***Link to ISP BTITALIA***
ip address 10.0.1.1 255.255.255.252
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
!
interface FastEthernet5
!
interface FastEthernet6
!
interface FastEthernet7
!
interface FastEthernet8
!
interface Vlan1
description ***Inside LAN***
ip address 192.168.210.10 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1452
ip policy route-map PBR
!
interface Dialer0
description ***Link to ISP TISCALI***
ip address negotiated
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer pool 1
ppp chap hostname [email protected]
ppp chap password xxxxxxxxxxxx
ppp pap sent-username [email protected] password xxxxxxxx
no cdp enable
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 1000
!
ip nat inside source route-map ISP_BTITALIA interface FastEthernet0 overload
ip nat inside source route-map ISP_TISCALI interface Dialer0 overload
ip route 0.0.0.0 0.0.0.0 Dialer0 track 1
ip route 0.0.0.0 0.0.0.0 10.0.1.2 track 2
!
ip access-list extended PBR_NAT_ISP_BTITALIA
permit ip 192.168.210.0 0.0.0.255 any
ip access-list extended PBR_NAT_ISP_TISCALI
permit ip 192.168.210.0 0.0.0.255 any
!
ip sla 2
icmp-echo 10.0.1.2
timeout 500
threshold 2
frequency 3
ip sla schedule 2 life forever start-time now
logging trap debugging
access-list 100 remark ***NAT 0***
access-list 100 permit ip 192.168.210.0 0.0.0.255 any
no cdp run
route-map ISP_BTITALIA permit 10
match ip address 100
match interface FastEthernet0
!
route-map PBR permit 10
match ip address PBR_NAT_ISP_BTITALIA
set ip next-hop verify-availability 10.0.1.1 2 track 2
!
route-map PBR permit 20
match ip address PBR_NAT_ISP_TISCALI
set ip next-hop verify-availability AAA.BBB.CCC.DDD 1 track 1
(NON CONOSCO IP NEXT-HOP PERTANTO HO INSERITO IL MIO IP STATICO TISCALI – LA COSA MI VIENE SEGNALATA ANCHE DA IOS)
!
route-map ISP_TISCALI permit 10
match ip address 100
match interface Dialer0
*********************************************************************************************