Multihomed BGP and HSRP (again)

Posted on 2005-04-20
Last Modified: 2013-11-30
This questions has seemed to be asked and answered but not exactly to my understanding...(my fault I am sure)
I currently have 1 x 3 meg connection to the internet. We are using BGP because that was the way it was when I took over management. We own a class c network which is announced via bpg to our ISP.
We are getting a new 3.0 meg connection from a different ISP on a different local loop for redundancy. Each ISP will be terminated on its own 7206xvr. Here is how it will look...

     ISP-A      ISP-B
        |            |         (3 meg each)  (Using MFR and MPPP to combine 2 T1's)
 RTRA---iGP---RTRB   (Routers are both 7206XVR with 256 of mem)
      Redundant Pix
     Core Switch (Nortel Passport - soon to be 6509)
        |              |           |  
 Dist Switch     SRV        SRV

My concerns are redundancy, automatic failover, load balancing.
I am confused between HSRP and GLBP.

Sorry about asking this question yet again but this seems to be a popular subject and I want to make sure that there is a clear answer.
I have also seen where I can stagger the announcements to do some outbound load balancing as well as some BGP tweaks to control manipulate inbound traffic.
Any thoughts on this would be appreicated.
Question by:mmahaney
    LVL 32

    Accepted Solution

    HSRP is for redundancy, two routers join a group, each has a physical IP, they are both configured to respond
    to a virtual IP, however, only one is active at a time. So the router with the higher metric will be the router who responds
    for all ARPs on that segment. The other router will be in standby mode, it will become active only if it cannot talk to the other router. HSRP is for redundancy for outbound traffic only. You could use MHSRP to create multiple groups and balance outgoing
    traffic on one router for vlan A and the other router for vlan B.

    GLBP takes MHSRP to another level defining multiple VIPs for a single segment. In other words, you can use both routers
    simualtaneously, providing redundancy at the same time for the same subnet.

    Check it out:

    LVL 8

    Expert Comment

    Short for Hot Standby Routing Protocol, a proprietary protocol from Cisco. HSRP is a routing protocol that provides backup to a router in the event of failure. Using HSRP, several routers are connected to the same segment of an Ethernet, FDDI or token-ring network and work together to present the appearance of a single virtual router on the LAN. The routers share the same IP and MAC addresses, therefore in the event of failure of one router, the hosts on the LAN are able to continue forwarding packets to a consistent IP and MAC address. The process of transferring the routing responsibilities from one device to another is transparent to the user.


    Author Comment

    I do understand all the fundamental concepts I just want to know what would be the best practice way to set up a multihome BGP environment with redundancy at the edge. I was hoping to get thoughts on what was though to be the best way to get this architected....
    LVL 2

    Expert Comment

    Coudl you give us more details:

    C class is a part of the first ISP-s networks, right? Do you get another C-class form the other one?
    You are using NAR, right, and you are translating to the first c-class, how will you move to the other one. If you want to be reached you have to announce your C-class on through noth providers, a very tough thing, I mean, they are very reluctant to do so...

    HSRP is clear, you can set it up in two lines, just follow docs on CISCO site, and PIX will happily oblige, but what happends next?

    If you have "your" C-class, what I doubt, then you have to ask your ISPs to announce it to their upstream ISPs....
    LVL 32

    Expert Comment

    Follow the classic core-dist-access design . Nail down your layer 2 and layer 3 to route/switch traffic along a predictable path to the edge device. I do not agree with the placement of the firewalls, what kind of site is this?

    I agree with Vladan, we need more details


    Author Comment

    by:mmahaney basically boils down to having the ability and need to have 2 different ISP's on 2 differnet local loops, on 2 differnet ingress routers. We own a class C space and will be announcing that space 2 both ISP's. This will enable us to have redundacy at the edge. I was thinking of doing GLBP on the 2 7206XVR's to load balance outbound internet traffic while either letting inbound traffic just pick best path or tweaking some BGP parmaters to try to get a better balance....depending on what the balance turns out to be.

    Our core network will remain the same with dist switches connnected to a core switch which then fowards everything to the firewalls.

    Vladan, can you explain why you do not agree with the placement of the firewalls. I have inherited this network and have researched some ways to re-architect it so I am intrested in your thoughts....

    LVL 2

    Expert Comment

    Thanks for the additional info, mmahaney,

    harbor235 explained both HSRP and GLBP, and the basic difference is that HSRP is fail-over redundancy, and GLBP is HA with load-sharing, but I can not justify the use in this particular case. With 3Mbps through each provider, it is hardly a bottleneck in your access to 7206 from PIXes, so I would use only HSRP, turn on IGP between border routers, as you said, and let the BGP decide which router is the best one to use to exit.

    Basically, exactly the same as you have proposed.

    On the other hand, I am not against your design, and would like to hear from harbor235. We have the same (more or less) architecture. We contain 60% of all traffic inside, the rest goes to the DMZ and to the Internet...

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    #Citrix #Citrix Netscaler #HTTP Compression #Load Balance
    Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now