Solved

2611 Setup policy based routing to defer HTTP traffic to specific interface

Posted on 2006-11-20
4
910 Views
Last Modified: 2008-02-01
I'm attempting to route http / https traffic thru another link as my dual T1's are just not enough to handle it all.

Can someone give me a sample configuration on how to setup the access lists to do this?

I'm updating the software image to 12.3 for policy based routing at the moment.

Thanks in advance!

eth0/0 65.x.x.x   (Connected to Dual T1's)
eth0/1 66.x.x.x  (Connected to Backhaul Radio Link)


Shoota
0
Comment
Question by:Chris Staunton
  • 2
  • 2
4 Comments
 
LVL 50

Accepted Solution

by:
Don Johnston earned 500 total points
Comment Utility
interface FastEthernet0/0 !(inbound interface)
 ip policy route-map homer

access-list 102 permit tcp any any eq www

route-map homer permit 10
 match ip address 102
 set interface e0/0 !(or next hop address)
0
 
LVL 12

Author Comment

by:Chris Staunton
Comment Utility
Thanks Don!

!
interface Ethernet0/0
 description Connection to District
 ip address 65.xx.xx.xx 255.255.255.224
 ip policy route-map HTTP
 full-duplex
!
interface Serial0/0
 no ip address
 no ip mroute-cache
 shutdown
 no fair-queue
!
interface Ethernet0/1
 description Connected to Backhaul
 ip address 66.xx.xx.xx 255.255.255.252
 full-duplex
!
no ip http server
ip classless
ip route 0.0.0.0 0.0.0.0 65.xx.xx.xx
!
!
access-list 102 permit tcp any any eq www
route-map HTTP permit 10
 match ip address 102
 set interface Ethernet0/1


Here's what I've come up with so far.  Do I need an ip route (0.0.0.0 ?????) to the network connected to Eth0/0?  I still have to implement the ip nat trans for eth0/0 as well I suspect I can do inside on Eth0/1 and Outside on Eth0/0?

Thanks again for the help!


Shoota
0
 
LVL 50

Expert Comment

by:Don Johnston
Comment Utility
>Do I need an ip route (0.0.0.0 ?????) to the network connected to Eth0/0?

If you want the path out that interface to be used for non-policy based traffic, then yes.

>I still have to implement the ip nat trans for eth0/0 as well I suspect I can do inside on Eth0/1 and Outside on Eth0/0?

Yes. The only thing policy based routing does is bypass the routing table if it finds a match. Everything else behaves the way it normally does. (i.e. NAT)

-Don
0
 
LVL 12

Author Comment

by:Chris Staunton
Comment Utility
Thanks again,

Everything seems to be working correctly through the router, can see all the nat trans happening and traffic is flowing out that connection.


Shoota
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now