Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

A routing loop prevention scenario

Posted on 2006-11-15
4
795 Views
Last Modified: 2012-06-27
Hi, we have got around this problem now, but I wanted to ask this question for future reference.

We have a cab in an ISP's co-lo and they have provided us with 2 ethernet cables from their core Internet network which we originally wanted to plug in to 2 Cisco Catalyst 3560 switches that we have in the cab.

The switches are clustered, and run an internal VLAN (default), and Vlans named "Internet 1" and "Internet 2". The default VLAN spanned the cluster whilst the two Internet Vlans were tied to one or other of the switches. This was to prevent a routing loop when plugging the feeds in to the switches.

Whilst the ISP agreed that this config would work, they basically told us that they wouldn't allow us to plug their core in to our switches because - potentially - we could reconfigure the port assignment and create a routing loop (which we wouldn't do but hey ho....i get their point).

So anyhow - what they suggested we do is basically issue the "no switchport" command on both of the ports used for the Internet subnet feeds (one on each of our switches) however I think I am right in saying that this would have basically rendered the port useless and we couldn't then switch the traffic to the other 3 ports on the same switch that were configured for the Internet 1 (or 2) Vlan.....I hope I'm not losing anyone.

So - basically - is there a way to make this work. I'm good with IP routing but no good with switching (yet) and so hence my question.

Oh - yeah - the underlying reason for needing this config was that we wanted to create a "no single point of failure" route in to a number of servers running off of the Switch Cluster (dual NICs that are teamed) and were using 2 2811 routers with HSRP and a 2 PIXs with failover to do this.

Thanks in advance.

DS
0
Comment
Question by:prodriveit
  • 2
  • 2
4 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 17951297
You're right. Turning a switchport into a routed interface does not accomplish your goal of having 3 interfaces on each internet connection. Only a vlan interface will do this.

Unless you keep all of your redundancy at layer3, running BGP/OSPF or some other dynamic routing protocol between the ISP, your switches and PIX's.
With full L3 capability of the 3560, what it the function of the 2811 routers/HSRP?

Heres the guide to failover/backup routing on PIX V7.x /ASA
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

You  might be able to follow the logic in this thread where we're discussing vitrually the same thing
http://www.experts-exchange.com/Security/Firewalls/Q_22059936.html


0
 
LVL 2

Author Comment

by:prodriveit
ID: 17954088
Hi - Thanks for the reply...

The 2811s are for VPNs to other sites, and we didn't really want them to go through the PIX as we wanted the PIX's doing one job and the 2811s doing another. The HSRP bit isn't really necessary to be honest as the VPNs are just using secondary peer config - bit of a red herring I suppose - sorry.

I'll take a look at the links - thanks very much for your help - don't know much about BGP but ok with OSPF.

The way we have worked round it is to just get the ISP to give us 2 more internet feeds and we are going to plug these in to the back of the PIXs and 2811s - but this may not always be an option.

Thanks again!

DS
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 18107907
Are you still working on this? Can you close out this question before the cleanup crew gets around to it?
Thanks!
0
 
LVL 2

Author Comment

by:prodriveit
ID: 18472527
Sorry - forgot to close this one out - thanks for your help lrmoore. We did the job with the 2 additional feeds but the advice was much appreciated as always.

DS
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Nimble Storage 3 104
winscp 000webhost.com 6 73
NAT not working on trunk 6 37
Dell PowerConnect 2824 w/ two DHCP 6 22
Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question