Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Policy Based Routing on HP Procurve 5406

Posted on 2014-04-24
2
Medium Priority
?
1,620 Views
Last Modified: 2014-04-28
I have a business case to split certain vLANs between 2 different ISPs.  I have attached a very simple diagram of the network layout.  I am attempting to configure PBR on the 5406 to push traffic from vLAN 7 to ISP 2 and traffic from vLAN 1 to ISP 1.  I have attached the running config of the 5406.  Once I apply the policy to vLAN 7, only ping and DHCP traffic appear to flow.  From vLAN 7, I can ping other devices on vLAN 1 and from vLAN 1 I can ping devices on vLAN 7.  The DHCP server sits on vLAN 1 and is still able to hand out addresses to clients on vLAN 7.  I need the vLANs to communicate with eachother as well as separating their Internet traffic.

default gateway on vLAN 1 (10.1.0.0 /16): 10.1.1.252
default gateway on vLAN 7 (10.249.0.0 /16) : 10.249.0.1
default gateway on switch: 10.1.1.252

I am trying to determine what I am missing in the setup of the 5406 to make this scenario work.
Network-Diagram.JPG
5406.txt
0
Comment
Question by:smithdw1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 17

Accepted Solution

by:
jburgaard earned 2000 total points
ID: 40021558
I have never worked with PBR in practice, but based on the fact that both
'next-hop' and
'default-next-hop'
statements exist , I guess there could be a difference.

As far as I can tell you must go via vlan1 to come from an IP in vlan7 to 10.1.0.10, but if 'next hop' is not the directly connected 10.1.8.15, you may miss a step-stone.
So my 2cents:
Either give 10.1.0.10 an IP in 10.249.0.0 and connect to vlan7 (also supply route to vlan1 via 10.249.0.1)
 or try
replace 'action next-hop 10.1.0.10'  with
action default-next-hop 10.1.0.10

HTH
0
 
LVL 1

Author Comment

by:smithdw1
ID: 40027061
Hello jburgaard,

Thanks for commenting.  I broke down and opened a case with HP and confirmed that the pbr is set correctly.  We verified that the switch was matching packets as expected.  They feel they have narrowed the issue down to the Cisco ASA that is handling the connection to ISP 2 - indicating that it may be blocking some traffic to vlan1.  I will have to take a closer look at the ASA to see if that is the case.  I do like your suggestion of adding a vlan interface to the ASA for each of the subnets, which would then allow me to do away with pbr on the switches.
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This program is used to assist in finding and resolving common problems with wireless connections.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question