?
Solved

PBR

Posted on 2009-04-22
6
Medium Priority
?
588 Views
Last Modified: 2013-11-30
Experts,

I have a client who's email server is blocking mail coming from our public IPs, or seems to be--we have no other SMTP issues with anyone, and the server accepts mail from our other gateway (its NATed and the public address is not on any blacklist).

This must be resolved immediately, at least with a working temporary solution.

To do this, the only way i see is to accomplish this is route that clients traffic to the other gateway. However, we do not have enough bandwidth on that ISP to suffice for all the traffic of the client. So, it can only be the SMTP traffic, and only the SMTP to that particular problem server.

Currently out core switch is the gateway for all the VLANs, and static routes traffic to an ASA where it is NATed. VOIP traffic is parted at the core switch to a different router for NAT and routing on the other ISP link.

I'd like to separate all clients smtp the traffic at the core, and send it to the other router.

I guess this should look something like this:

access-list 180 permit tcp any host x.x.x.x eq smtp

route-map SMTP permit 10
     match ip 180
     set ip default next-hop <ip of router, not asa>

apply on interface:

int vl 12
     ip policy route-map smtp

Correct?

Can I do PBR and static routing simultaneously? Should the above config work? I have this currently, but it is not. Please advise.
0
Comment
Question by:demetri08
  • 4
  • 2
6 Comments
 
LVL 28

Accepted Solution

by:
asavener earned 750 total points
ID: 24214991
Correct?
-Remove the "default" keyword from the policy map.

Can I do PBR and static routing simultaneously?
-yes

Should the above config work?
-The above config should send SMTP traffic destined for x.x.x.x to the router.  What happens after that depends on the router, and whether it is configured properly to provide Internet access for private addresses.
0
 
LVL 28

Expert Comment

by:asavener
ID: 24215001
Suggestion:

Modify the access list to send all traffic with a destination of x.x.x.x to the router; then you can run traceroute, and various other tests.
0
 

Author Comment

by:demetri08
ID: 24215100
thanks. i'll change the acl...

i have tested it, and the traffic does go to the other router (though i have to enable some sort of dynamic routing to get the rout maps to work, correct?).

anyway, the traffic is nated properly, but the smtp is not working still--with different symptoms. first, telnet smtp-server 25 does not get any srt of response now. second, wireshark shows pretty much only tcp retrans from the server back to the cleints.
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
LVL 28

Expert Comment

by:asavener
ID: 24215743
"though i have to enable some sort of dynamic routing to get the rout maps to work, correct?"
-No.  Once the policy is applied to the interface, the route map will take effect.  Note, however, that it will only apply to traffic entering that interface; it will not affect traffic entering other interfaces, or exiting the interface.
0
 

Author Comment

by:demetri08
ID: 24215814
thanks again.

i'm thinking perhaps i'm going down a path i don't need to be. lets say we don't stcik to my original plan...how should i get all the clients smtp traffic (to just that one server) out through a different gateway. or, are there any other solutions i'm not thinking of?

Thanks!
0
 
LVL 28

Expert Comment

by:asavener
ID: 24215899
PBR is the right tool to use for that.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question