Solved

Policy Based Routing on HP Procurve 5406

Posted on 2014-04-24
2
1,540 Views
Last Modified: 2014-04-28
I have a business case to split certain vLANs between 2 different ISPs.  I have attached a very simple diagram of the network layout.  I am attempting to configure PBR on the 5406 to push traffic from vLAN 7 to ISP 2 and traffic from vLAN 1 to ISP 1.  I have attached the running config of the 5406.  Once I apply the policy to vLAN 7, only ping and DHCP traffic appear to flow.  From vLAN 7, I can ping other devices on vLAN 1 and from vLAN 1 I can ping devices on vLAN 7.  The DHCP server sits on vLAN 1 and is still able to hand out addresses to clients on vLAN 7.  I need the vLANs to communicate with eachother as well as separating their Internet traffic.

default gateway on vLAN 1 (10.1.0.0 /16): 10.1.1.252
default gateway on vLAN 7 (10.249.0.0 /16) : 10.249.0.1
default gateway on switch: 10.1.1.252

I am trying to determine what I am missing in the setup of the 5406 to make this scenario work.
Network-Diagram.JPG
5406.txt
0
Comment
Question by:smithdw1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 17

Accepted Solution

by:
jburgaard earned 500 total points
ID: 40021558
I have never worked with PBR in practice, but based on the fact that both
'next-hop' and
'default-next-hop'
statements exist , I guess there could be a difference.

As far as I can tell you must go via vlan1 to come from an IP in vlan7 to 10.1.0.10, but if 'next hop' is not the directly connected 10.1.8.15, you may miss a step-stone.
So my 2cents:
Either give 10.1.0.10 an IP in 10.249.0.0 and connect to vlan7 (also supply route to vlan1 via 10.249.0.1)
 or try
replace 'action next-hop 10.1.0.10'  with
action default-next-hop 10.1.0.10

HTH
0
 
LVL 1

Author Comment

by:smithdw1
ID: 40027061
Hello jburgaard,

Thanks for commenting.  I broke down and opened a case with HP and confirmed that the pbr is set correctly.  We verified that the switch was matching packets as expected.  They feel they have narrowed the issue down to the Cisco ASA that is handling the connection to ISP 2 - indicating that it may be blocking some traffic to vlan1.  I will have to take a closer look at the ASA to see if that is the case.  I do like your suggestion of adding a vlan interface to the ASA for each of the subnets, which would then allow me to do away with pbr on the switches.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CCNP Exam question 6 38
DESKTOP MONITORING 41 83
What is weight in VIP (Vserver) in Netscalar? 2 32
Active directory DNS integrated question? 7 45
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question