NAT Failover on Cisco router with BGP not working

Posted on 2009-06-29
Last Modified: 2012-05-07
Hi Everyone

I'm having a problem with NAT Failover
we have just gone to a BGP setup for multi homing from static routes on the gateway router
the NAT failover worked before when we just had static routes but doesnt work now.
Before the move from static routers i have several users designated with and access-list and router map to use the backup connection as there default router, these no longer work which is why I know something is wrong.

With the above mentioned routemap (called BACK_UP) in place from the .60 address i can tracert to the backup connections interface and gateway IP's but a traceroute to anything passed that gets stuck at the .1 ip addess of the router anything after that is * * *

I'm pretty sure i'm just missing something simple
I've attached a sanitized copy of the relevant config from the router and sanitized in the same way copy of the sh ip route

For ease of readed but at the same time to protect my self I changed the IP addresses so that
mmm.mmm.mmm.  address are the connection to the main ISP
bbb.bbb.bbb. address are the IP address assigned to us by our backup ISP are our own IP address range. is the default IP for traffic coming for our firewall

Show ip route
Gateway of last resort is mmm.mmm.mmm.85 to network

     bbb.bbb.bbb.0/27 is subnetted, 1 subnets
C       bbb.bbb.bbb.96 is directly connected, GigabitEthernet0/2
     mmm.mmm.0.0/30 is subnetted, 1 subnets
C       mmm.mmm.mmm.84 is directly connected, Serial1/0
B* [20/1] via mmm.mmm.mmm.85, 6w3d
C is directly connected, GigabitEthernet0/1

Router Config

interface GigabitEthernet0/1
 description External IP's
 ip address
 no ip unreachables
 no ip proxy-arp
 ip nat inside
 ip virtual-reassembly
 ip route-cache flow
 ip policy route-map BACK_UP
 duplex auto
 speed auto
 media-type rj45
 negotiation auto
 no mop enabled
interface GigabitEthernet0/2
 description Backup Connection
 ip address bbb.bbb.bbb.98
 ip verify unicast reverse-path
 no ip unreachables
 no ip proxy-arp
 ip nat outside
 ip virtual-reassembly
 ip route-cache flow
 duplex auto
 speed auto
 media-type rj45
 negotiation auto
 no mop enabled
interface Serial1/0
 description T3 multihome (Serial interface)
 ip address mmm.mmm.mmm.86
 ip verify unicast reverse-path
 no ip unreachables
 no ip proxy-arp
 ip flow ingress
 ip flow egress
 ip route-cache flow
 dsu bandwidth 9000
 framing c-bit
 cablelength 10
router bgp XXXXX
 no synchronization
 bgp router-id mmm.mmm.mmm.86
 bgp log-neighbor-changes
 network mmm.mmm.mmm.84 mask
 network mask
 neighbor mmm.mmm.mmm.85 remote-as YYYYY
 neighbor mmm.mmm.mmm.85 version 4
 neighbor mmm.mmm.mmm.85 default-originate
 neighbor mmm.mmm.mmm.85 route-map our_ips out
 neighbor mmm.mmm.mmm.85 maximum-prefix 500
 no auto-summary
ip default-gateway mmm.mmm.mmm.85
ip forward-protocol nd
ip route mmm.mmm.mmm.85 80
ip route bbb.bbb.bbb.97 120
ip nat inside source list NAT2BACKUP interface GigabitEthernet0/2 overload
ip nat inside source static bbb.bbb.bbb.100
ip nat inside source static bbb.bbb.bbb.101
ip nat inside source static bbb.bbb.bbb.102
ip access-list standard BGP_OUT
 remark Access list for bgp routemap to allow only our IP's to broadcast out
ip access-list standard NAT2BACKUP
 remark NAT_2_BACKUP
route-map our_ips permit 10
 match ip address BGP_OUT
ip access-list extended Backup_Users
 remark ip's in this acl map to route-map BACK_UP
 remark and are pushed out of the backup connection
 permit ip host any
route-map BACK_UP permit 100
 match ip address Backup_Users
 set ip default next-hop bbb.bbb.bbb.97
Question by:mhorrocks
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 28

Expert Comment

by:Jan Springer
ID: 24831326
You say that you are multi-homing but I only see one neighbor in the BGP config.

Even with a multi-homed environment, you can still choose a preferred path out with static routes if the outgoing bandwidth is dramatically less than the incoming bandwidth.

Author Comment

ID: 24895902
We are not currently multihomed, it's what we are working towards hence the single neighbor
that should be done in about a month or so

so what you are saying this secondary connection should be included in my BGP routing table either as
redistribute connected or redistribute static? I can then manipulate the the best route, would the fix my NAT problem ?
LVL 28

Expert Comment

by:Jan Springer
ID: 24896054
I see the DS3 as the external facing interface peering with its BGP neighbor but the NAT is not applied to traffic leaving that interface.

According to the configuration above, the nat outside statement is applied to the backup GigE connection.  Is this GigE connection to be your backup external connection?
Instantly Create Instructional Tutorials

Contextual Guidance at the moment of need helps your employees adopt to new software or processes instantly. Boost knowledge retention and employee engagement step-by-step with one easy solution.


Author Comment

ID: 24897732
Yes that's correct
there are 3 connections in to the router

One from the Firewall (g0/1)
One for the DS3 (s1/0)
and one for a Business cable provider (g0/2)

there is no need to NAT traffic going over the DS3 (primary) but we do need to NAT traffic if i goes over the cable connection.
LVL 28

Accepted Solution

Jan Springer earned 500 total points
ID: 24910080
what do you see with "sh ip nat trans" when failing over to the cable connection?

Author Comment

ID: 25008723
Manage to figure out my problem
partly route-map, partly bgp routing
while Jesper didnt fully solve the issue her comments did help
so im going to award _jesper the points

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Layer 3 switch recommendation 15 61
Cisco RV320 Gateway to Gateway connected but not passing traffic 6 31
AD Design Best Practices 6 39
Exchange 2016 - not receiving mail 17 51
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Internet Business Fax to Email Made Easy - With  eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question