Solved

2611 Setup policy based routing to defer HTTP traffic to specific interface

Posted on 2006-11-20
4
915 Views
Last Modified: 2008-02-01
I'm attempting to route http / https traffic thru another link as my dual T1's are just not enough to handle it all.

Can someone give me a sample configuration on how to setup the access lists to do this?

I'm updating the software image to 12.3 for policy based routing at the moment.

Thanks in advance!

eth0/0 65.x.x.x   (Connected to Dual T1's)
eth0/1 66.x.x.x  (Connected to Backhaul Radio Link)


Shoota
0
Comment
Question by:Chris Staunton
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 50

Accepted Solution

by:
Don Johnston earned 500 total points
ID: 17980905
interface FastEthernet0/0 !(inbound interface)
 ip policy route-map homer

access-list 102 permit tcp any any eq www

route-map homer permit 10
 match ip address 102
 set interface e0/0 !(or next hop address)
0
 
LVL 12

Author Comment

by:Chris Staunton
ID: 17981266
Thanks Don!

!
interface Ethernet0/0
 description Connection to District
 ip address 65.xx.xx.xx 255.255.255.224
 ip policy route-map HTTP
 full-duplex
!
interface Serial0/0
 no ip address
 no ip mroute-cache
 shutdown
 no fair-queue
!
interface Ethernet0/1
 description Connected to Backhaul
 ip address 66.xx.xx.xx 255.255.255.252
 full-duplex
!
no ip http server
ip classless
ip route 0.0.0.0 0.0.0.0 65.xx.xx.xx
!
!
access-list 102 permit tcp any any eq www
route-map HTTP permit 10
 match ip address 102
 set interface Ethernet0/1


Here's what I've come up with so far.  Do I need an ip route (0.0.0.0 ?????) to the network connected to Eth0/0?  I still have to implement the ip nat trans for eth0/0 as well I suspect I can do inside on Eth0/1 and Outside on Eth0/0?

Thanks again for the help!


Shoota
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 17981787
>Do I need an ip route (0.0.0.0 ?????) to the network connected to Eth0/0?

If you want the path out that interface to be used for non-policy based traffic, then yes.

>I still have to implement the ip nat trans for eth0/0 as well I suspect I can do inside on Eth0/1 and Outside on Eth0/0?

Yes. The only thing policy based routing does is bypass the routing table if it finds a match. Everything else behaves the way it normally does. (i.e. NAT)

-Don
0
 
LVL 12

Author Comment

by:Chris Staunton
ID: 17981897
Thanks again,

Everything seems to be working correctly through the router, can see all the nat trans happening and traffic is flowing out that connection.


Shoota
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How VPC help preventing STP Loops 4 151
Where is running-config located at in ASR9K? 3 28
VPN Server config in Modem 5 68
Show IP BGP Information 10 48
In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question