?
Solved

Cisco ACL and PBR

Posted on 2008-10-19
1
Medium Priority
?
848 Views
Last Modified: 2012-08-13
I am currently planning the installation of a Hotel Network.  The attached diagram shows a very simplified version of the network.  I am planning on setting up 4 VLANs and will enable IP routing on the Cisco Layer 3 switch.  Each VLAN will use the DHCP server on VLAN 20 for IP addresses.  

Could you give me an idea of what types of ACLs and PBRs I would need to set up to enable the following:
1) VLANs 10, 20, 30 uses ISP 1 and are able to fully communicate/route with each other.
2) VLAN 40 uses ISP 2 and should be fully segregated from the rest of the network.  

Thank you.

Network-2.jpg
0
Comment
Question by:sharwani
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 15

Accepted Solution

by:
wingatesl earned 2000 total points
ID: 22752318
On your later 3 switch:

ip access-list extended ToISP1
   deny ip 172.16.0.0 0.0.255.255 172.16.0.0 0.0.255.255
   permit ip 172.16.1.0 0.0.0.255 any
   permit ip 172.16.2.0 0.0.0.255 any
   permit ip 172.16.3.0 0.0.0.255 any
ip access-list extended ToISP2
   deny ip 172.16.0.0 0.0.255.255 172.16.0.0 0.0.255.255
   permit ip 172.16.4.0 0.0.0.255 any  

route-map Director permit 10
   match ip address ToISP1
   set ip next-hop 172.16.1.2
route-map Director permit 20
   match ip address ToISP2
   set ip next-hop 172.16.1.3

int vlan 10
  ip policy route-map Director
int vlan 20
  ip policy route-map Director
int vlan 30
  ip policy route-map Director
int vlan 40
  ip policy route-map Director

Of course this is an example, if you post yur core switch config we can tailor it perfectly.
You will need to put an access list on vlan 40 to prevent intervlan communication.


0

Featured Post

Percona Live Europe 2017 | Sep 25 - 27, 2017

The Percona Live Open Source Database Conference Europe 2017 is the premier event for the diverse and active European open source database community, as well as businesses that develop and use open source database software.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question