Solved

Policy Based Routing on HP Procurve 5406

Posted on 2014-04-24
2
1,480 Views
Last Modified: 2014-04-28
I have a business case to split certain vLANs between 2 different ISPs.  I have attached a very simple diagram of the network layout.  I am attempting to configure PBR on the 5406 to push traffic from vLAN 7 to ISP 2 and traffic from vLAN 1 to ISP 1.  I have attached the running config of the 5406.  Once I apply the policy to vLAN 7, only ping and DHCP traffic appear to flow.  From vLAN 7, I can ping other devices on vLAN 1 and from vLAN 1 I can ping devices on vLAN 7.  The DHCP server sits on vLAN 1 and is still able to hand out addresses to clients on vLAN 7.  I need the vLANs to communicate with eachother as well as separating their Internet traffic.

default gateway on vLAN 1 (10.1.0.0 /16): 10.1.1.252
default gateway on vLAN 7 (10.249.0.0 /16) : 10.249.0.1
default gateway on switch: 10.1.1.252

I am trying to determine what I am missing in the setup of the 5406 to make this scenario work.
Network-Diagram.JPG
5406.txt
0
Comment
Question by:smithdw1
2 Comments
 
LVL 17

Accepted Solution

by:
jburgaard earned 500 total points
ID: 40021558
I have never worked with PBR in practice, but based on the fact that both
'next-hop' and
'default-next-hop'
statements exist , I guess there could be a difference.

As far as I can tell you must go via vlan1 to come from an IP in vlan7 to 10.1.0.10, but if 'next hop' is not the directly connected 10.1.8.15, you may miss a step-stone.
So my 2cents:
Either give 10.1.0.10 an IP in 10.249.0.0 and connect to vlan7 (also supply route to vlan1 via 10.249.0.1)
 or try
replace 'action next-hop 10.1.0.10'  with
action default-next-hop 10.1.0.10

HTH
0
 
LVL 1

Author Comment

by:smithdw1
ID: 40027061
Hello jburgaard,

Thanks for commenting.  I broke down and opened a case with HP and confirmed that the pbr is set correctly.  We verified that the switch was matching packets as expected.  They feel they have narrowed the issue down to the Cisco ASA that is handling the connection to ISP 2 - indicating that it may be blocking some traffic to vlan1.  I will have to take a closer look at the ASA to see if that is the case.  I do like your suggestion of adding a vlan interface to the ASA for each of the subnets, which would then allow me to do away with pbr on the switches.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now