Policy based routing

Hello, I've this kind of configuration to do: I have a router with a configuration quite simple: two interfaces and a quick routing table.

I need that some hosts are routed to a default gateway, others on another (double internet connection).

I thought of using a route map, but the problem is as follows: hosts that are administered by the route map using the right gateway, but ignores all other routes.

How can I fix?

Basically I want some use IP as a default gateway IP different, but both continue to use other routes ...
interface GigabitEthernet0/0
 ip address 192.168.4.100 255.255.254.0
 ip nat outside
 ip policy route-map switchugw
 duplex auto
 speed auto
!
interface GigabitEthernet0/1
 ip address 192.168.7.100 255.255.255.0
 ip access-group 101 in
 ip nat inside
 duplex full
 speed 100
!
ip route 0.0.0.0 0.0.0.0 192.168.4.240
ip route 10.10.100.0 255.255.255.0 192.168.4.240
ip route 10.10.200.0 255.255.255.0 192.168.4.240
ip route 192.168.0.0 255.255.255.0 192.168.4.240
ip route 192.168.2.0 255.255.254.0 192.168.4.240
ip route 192.168.6.0 255.255.255.0 192.168.4.205
ip route 192.168.8.0 255.255.255.0 192.168.4.205
ip route 192.168.9.0 255.255.255.0 192.168.4.205
ip route 192.168.10.0 255.255.255.0 192.168.4.240
ip route 192.168.40.0 255.255.255.0 192.168.4.201
ip route 192.168.100.0 255.255.255.0 192.168.4.240
ip route 192.168.110.0 255.255.255.0 192.168.4.240
ip route 192.168.200.0 255.255.255.0 192.168.4.240
!
ip access-list extended topix201
 permit ip host 192.168.4.33 any
 permit ip host 192.168.4.102 any
 deny   ip any any
!
route-map switchugw permit 10
 match ip address topix201
 set ip next-hop 192.168.4.201
!

Open in new window

LVL 3
Faber82Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Marijan77Commented:
You may set 'deny' rules to exclude local routing, so this is how access-list topix201 need to be:

ip access-list extended topix201
 deny ip host 192.168.4.33 10.10.0.0 0.0.255.255
 deny ip host 192.168.4.102 10.10.0.0 0.0.255.255
 deny ip host 192.168.4.33 192.168.0.0 0.0.255.255
 deny ip host 192.168.4.102 192.168.0.0 0.0.255.255
 permit ip host 192.168.4.33 any
 permit ip host 192.168.4.102 any
 deny   ip any any

Simply exclude all subnet that you don't want to parsed through route-map.
ip access-list extended topix201
 deny ip host 192.168.4.33 10.10.0.0 0.0.255.255
 deny ip host 192.168.4.102 10.10.0.0 0.0.255.255
 deny ip host 192.168.4.33 192.168.0.0 0.0.255.255
 deny ip host 192.168.4.102 192.168.0.0 0.0.255.255
 permit ip host 192.168.4.33 any
 permit ip host 192.168.4.102 any
 deny   ip any any

Open in new window

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Faber82Author Commented:
Ok I will try wit this. Do you know if I can use also:
deny ip any 10.10.0.0 0.0.255.255

because in future I need to add more IP in that acl and I prefer don't duplicate each string.

Thanks
0
Faber82Author Commented:
Yes works also with any ;)

thankyou very much for the help!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.