Solved

Failover with Cisco 1721

Posted on 2006-10-26
8
468 Views
Last Modified: 2008-03-10
Hello
I have a 1721 router.
It has 1 internal fastethernet and 1 T-1 card that connects to my ISP over a private T-1 connection.
Everything works ok.
I'm attempting to get another fastethernet or ethernet card to connect to a DSL provider.

How can I get the router to failover (and possibly load balance?) over the 2 links? so that if link A fails, link B would activate and vice versa?

Here's the config:

Current configuration : 858 bytes
!
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname eggster34
!
enable secret 5 xxx
!
ip subnet-zero
!
!

!
!
!
!
!
interface FastEthernet0
 description LAN interface
 ip address x.x.x.x  255.255.255.240 (public ip)
 speed auto
!
interface Serial0
 description WAN connection
 ip address 172.31.0.10 255.255.255.252
!
ip classless
ip route 0.0.0.0 0.0.0.0 172.31.0.9 <-- my ISPs router.
no ip http server
!

!
line con 0
 password 7 xxx
 login
line aux 0
line vty 0 4
 password 7 xxx
 login
!        
no scheduler allocate
!
end
0
Comment
Question by:eggster34
  • 2
  • 2
  • 2
8 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 17815458
One obstacle to this configuration is NAT.  Since the 1721 is not doing NAT, the device connected to the 1721 would need to be able to NAT inside traffic to the other ISP block of addresses in the event of failover.  This could be accomplished if you were to do NAT on the 1721.
0
 

Author Comment

by:eggster34
ID: 17815491
Hmm.. The device is a PIX 506E. it does NAT between 192.168.1.0 and the current public IP space.
Wouldn't routing on the 1721 take care of that problem ? Instead of routing between my current public space and 172.16.0.10 ,  it'd just route between my current public space and the new connection?
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 250 total points
ID: 17815561
Yes, for outbound traffic, but the rest of the world will know to get to your current public space via the ISP that has issued your public block of addresses so if the T1 is down, it will not be sent to you via the DSL provider.  This is where BGP comes into play but I doubt a DSL provider will run BGP with you.

If you were to NAT on the 1721, you could create two pools of addresses to NAT behind (one pool for the current public block and another pool for the block of addresses from the second ISP).  Depending on which interface traffic will be routed out will determine which address to NAT behind.  This method would provide load balancing and redundancy.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 250 total points
ID: 17818271
You'll have to double-nat to the 2nd ISP connection. On the PIX only for traffic in/out the T1 and on both the pix and the router for traffic out the new connection.
You can't just route your ISPA ip addresses through the ISPB connection. Since you are considering Ethernet, I will assume that this will be a cable/dsl connection.
Because of that, load balancing is tough to do. You can use route maps to selectively choose some traffic to go out either connection. Inbound is a little trickier with having 2 dns records with 2 different public IP's. DNS isn't smart enough to know if on link is down or not. Inbound email can easily be handled with mulitple MX records and priority.
Failover is easy. Consider using SLA's to select routes since you can't use dynamic routing:
 http://www.cisco.com/en/US/products/sw/iosswrel/ps5413/products_feature_guide09186a00801d862d.html

 
0
 

Author Comment

by:eggster34
ID: 17837161
Actually I'm not hosting any services that need to be accessed publicly on my internal network.
My concern is internet access only. all of my servers are hosted somewhere else.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 17837228
Then double-nat works just fine..
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Configuring EIGRP with neighbor command 25 60
Not able to route between subnets 8 117
Open a port on Cisco Router 1941 23 40
BGP Code 12 49
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question