Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Cisco 1700 Dual internet connections config question

Posted on 2006-11-13
Medium Priority
Last Modified: 2013-02-05
This is the scenario:

I have a
1700 cisco with 2 Ethernet cards installed plus the internal fast ethernet port
1 card - internet provider a
1 card - internet provider b
internal card - network

I have two internet provider both of who provide ethernet connections to me.

I want to setup the 1700 to use one connection unless it is down and then use the other connection
I need to set up some port forwarding and also set up some ACLs

I know a bit about cisco but im not quite sure about how to config this

example commands would be really helpfully
I already have the ip address and mask set on the router

no routes or ACL have been Set
I have updated to the 12.3 ios with the ip and fw feature set

Any additional information can be provided

Thank you

Question by:omegamueller
LVL 32

Assisted Solution

rsivanandan earned 600 total points
ID: 17935340
To do the failover when one internet connection is down -> Add a static route to provider A and add another static route to provider B with higher administrative distance, so that it gets picked only when the first route is down.

ip route <InternetProviderA-ISP Router IP>
ip route <InternetProviderB-ISP Router IP> 200

So what are the services that you want to port forward to ? A General idea is;


LVL 12

Expert Comment

ID: 17935967
Doing failover without BGP is usually only successful if you don't have services available externally or the only service you care about is inbound email via prioritized MX records.  Your internal PCs will be able to access the Internet by using ISPB's address block, but that's usually the limit of what can be done (besides MX records).

Doing static route failover with two Ethernet connections will be spotty at best.  Each carrier has most likely put a switch or media converter on your premises; the links will not go down (and therefore the static routes will not fail over) unless the switch/media converter loses power.

Assisted Solution

bugsaif earned 300 total points
ID: 17936409
What you need is Policy Based Routing with Tracking...

Configuration example can be found here: http://www.cisco.com/en/US/tech/tk364/technologies_configuration_example09186a0080211f5c.shtml

if you need more help just post back.

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 12

Expert Comment

ID: 17937406
Good catch; I wasn't aware of that feature.  Be aware that it requires at least the Enterprise Base image, which is likely not on this user's router.

But once again, realize that even with this functionality, in the event of a failure at ISP-A, your internal users will be able to view the Internet, your secondary MX will be reachable, but no external services will be available on the public addresses they were configured for.
LVL 79

Expert Comment

ID: 17937796
The hard part is going to be NAT.
Do you have an internal firewal that does your NAT for you now? Can it handle multiple IP ranges , one from each provider? I doubt it. Probably only from one provider, so you'd have to do double-nat on the 1700. Inbound www or email traffic is a problem. Email is OK with multiple MX records as PJ mentioned above, but if you have a web site it won't be available if your primary ISP link is down.
You're going to be asking a lot from that little 1700 router's CPU. Since it is end-of-lifed, and you are obviously concerned with downtime/Internet resiliency, I'd seriously look into something more robust.

Author Comment

ID: 17938488
Thank you for all the help

All i need it for is internte and email.
I do remote in to the site but i can configure both ip to do that and just pick the one that i need

how do i setup double nat.

I think im going to go with the two routes vs. a policy based route
LVL 79

Accepted Solution

lrmoore earned 600 total points
ID: 17946217
The problem with dual routes is that the interface has to go down for the route to change. This is unlikely with an Ethernet interface.

How you set up the nat depends on how you're doing it now, but in a nutshell:

interface Fast 0
 ip address a.b.c.d  <== address block belongs to ISP A
 ip nat inside

interface Eth 0
 description ISP A
 ip address c.d.e.f

interface Eth 1
 description ISP B
 ip address g.h.i.j
 ip nat outside

ip nat inside source list 1 interface Eth1 overload
access-list 1 permit a.b.c.0 <== assuming that your firewall already nats to ISPA addresses
ip nat inside source static tcp a.b.c.x 25 g.h.i.j 25  <== map email to your firewall/existing MX

Add another MX record and now email will come in even if ISPA link is down.
Outbound traffic will be natted at the firewall, then it hits the router. It is either passed on out ISPA, or if the link is dead, it will go out to ISPB, but will be natted again to ISPB ip address

Hope this makes sense to you...


Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question