Jump to content

Recommended Posts

Posted

Всем приветы

имеется в наличии каталист, настроен дефолтный гейтвей на роутер .253, в распоряжении 3 блока адресов. Появилась необходимость разделить трафик по блокам, т.е.

по дефолту сливаем на .253 узел (1 блок адресов) и 2 остальных блока сливаем на .252 маршрутизатор. Попробовал для этого настроить PBR - эффекта ноль. Кто сталкивался, куда смотреть?

IOS вот такой

 

 

Cisco IOS Software, C3750 Software (C3750-ADVIPSERVICESK9-M), Version 12.2(46)SE, RELEASE SOFTWARE (fc2)

 

 

C уважением ...

Posted

sdm profile поставили? В дефолтном pbr запрещен.

 

3750-48#sh sdm prefer

The current template is "desktop routing" template.

The selected template optimizes the resources in

the switch to support this level of features for

8 routed interfaces and 1024 VLANs.

 

number of unicast mac addresses: 3K

number of IPv4 IGMP groups + multicast routes: 1K

number of IPv4 unicast routes: 11K

number of directly-connected IPv4 hosts: 3K

number of indirect IPv4 routes: 8K

number of IPv4 policy based routing aces: 0.5K

number of IPv4/MAC qos aces: 0.5K

number of IPv4/MAC security aces: 1K

 

вроде то что надо

Posted

routing-pbr упоминается лишь в мамонтоподобных иосах. с 12.2(20) его не стало, остался тольк routing. с учетом того что routing-pbr по ткамам эквивалентен routing, заисключением того что в нем тупо можно было включать pbr, его выпилили. routing темплейт теперь отдувается за обоих.

Posted (edited)

Тогда конфиг в студию.

 

Building configuration...

 

Current configuration : 10456 bytes

!

!

version 12.2

no service pad

service timestamps debug datetime msec localtime

service timestamps log datetime localtime

service password-encryption

!

hostname 3750-48

!

boot-start-marker

boot-end-marker

!

logging buffered 128000

no logging console

!

no aaa new-model

clock timezone MSK 4

switch 1 provision ws-c3750g-48ts

system mtu routing 1500

ip subnet-zero

ip routing

!

!

!

!

port-channel load-balance src-dst-ip

!

!

!

spanning-tree mode pvst

spanning-tree extend system-id

no spanning-tree vlan 1-3

!

vlan internal allocation policy ascending

!

no ip rcmd domain-lookup

ip rcmd rsh-enable

!

!

interface Null0

no ip unreachables

!

interface Loopback0

no ip address

!

interface Port-channel1

description NAS29-int-channel

switchport mode access

!

interface Port-channel2

description NAS27-int-channel

switchport mode access

!

interface Port-channel3

description NAS28-int-channel

switchport mode access

!

interface Port-channel4

description NAS28-ext-channel

switchport access vlan 2

switchport mode access

!

interface Port-channel5

description NAS27-ext-channel

switchport access vlan 2

switchport mode access

!

interface Port-channel6

description NAS29-ext-channel

switchport access vlan 2

switchport mode access

!

interface Port-channel7

description User-network-channel

switchport mode access

!

interface GigabitEthernet1/0/1

description USER-network-aggr1

switchport mode access

channel-group 7 mode active

!

interface GigabitEthernet1/0/2

description USER-network-aggr2

switchport mode access

channel-group 7 mode active

!

interface GigabitEthernet1/0/3

switchport mode access

!

interface GigabitEthernet1/0/4

description Office network

switchport mode access

!

interface GigabitEthernet1/0/5

description NAS27-aggr1-int

switchport mode access

channel-group 2 mode active

!

interface GigabitEthernet1/0/6

description NAS27-aggr2-int

switchport mode access

channel-group 2 mode active

!

interface GigabitEthernet1/0/7

description NAS28-aggr1-int

switchport mode access

channel-group 3 mode active

!

interface GigabitEthernet1/0/8

description NAS28-aggr2-int

switchport mode access

channel-group 3 mode active

!

interface GigabitEthernet1/0/9

description serv14 int

switchport mode access

!

interface GigabitEthernet1/0/10

description serv11 int

switchport mode access

!

interface GigabitEthernet1/0/11

description www int

switchport mode access

!

interface GigabitEthernet1/0/12

description backup int

switchport mode access

!

interface GigabitEthernet1/0/13

description 7114 int

switchport mode access

!

interface GigabitEthernet1/0/14

description serv4 int

switchport mode access

!

interface GigabitEthernet1/0/15

switchport mode access

!

interface GigabitEthernet1/0/16

description serv5 int

switchport mode access

!

interface GigabitEthernet1/0/17

description NAS29-aggr1-int

switchport mode access

channel-group 1 mode active

!

interface GigabitEthernet1/0/18

description NAS29-aggr2-int

switchport mode access

channel-group 1 mode active

!

interface GigabitEthernet1/0/19

description NAS27 int temp

switchport mode access

!

interface GigabitEthernet1/0/20

description NAS29 int temp

switchport mode access

!

interface GigabitEthernet1/0/21

switchport mode access

!

interface GigabitEthernet1/0/22

description sberbank int

switchport mode access

!

interface GigabitEthernet1/0/23

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/24

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/25

description NAS28-aggr1-ext

switchport access vlan 2

switchport mode access

channel-group 4 mode active

!

interface GigabitEthernet1/0/26

description NAS28-aggr2-ext

switchport access vlan 2

switchport mode access

channel-group 4 mode active

!

interface GigabitEthernet1/0/27

description NAS27-aggr1-ext

switchport access vlan 2

switchport mode access

channel-group 5 mode active

!

interface GigabitEthernet1/0/28

description NAS27-aggr2-ext

switchport access vlan 2

switchport mode access

channel-group 5 mode active

!

interface GigabitEthernet1/0/29

description NAS29-aggr1-ext

switchport access vlan 2

switchport mode access

channel-group 6 mode active

!

interface GigabitEthernet1/0/30

description NAS29-aggr2-ext

switchport access vlan 2

switchport mode access

channel-group 6 mode active

!

interface GigabitEthernet1/0/31

description Cisco 7201 ext

switchport access vlan 2

switchport mode access

flowcontrol receive desired

!

interface GigabitEthernet1/0/32

description serv14 ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/33

description serv11 ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/34

description serv5 ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/35

description www ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/36

description serv4 ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/37

description backup ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/38

description ethernet 3750 ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/39

description Yurev

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/40

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/41

description serv10 ext

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/42

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/43

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/44

switchport access vlan 2

switchport mode access

!

interface GigabitEthernet1/0/45

description BGP-1

switchport access vlan 3

switchport mode access

!

interface GigabitEthernet1/0/46

description BGP-2

switchport access vlan 3

switchport mode access

!

interface GigabitEthernet1/0/47

description speedtest

switchport access vlan 3

switchport mode access

!

interface GigabitEthernet1/0/48

switchport access vlan 3

switchport mode access

!

interface GigabitEthernet1/0/49

!

interface GigabitEthernet1/0/50

!

interface GigabitEthernet1/0/51

!

interface GigabitEthernet1/0/52

!

interface Vlan1

description SVI-internal

no ip address

!

interface Vlan2

description SVI-external

ip address A.B.C.1 255.255.255.224

!

interface Vlan3

description SVI-uplink

ip address A.B.C.254 255.255.255.248

ip route-cache policy

ip policy route-map PBR

!

router rip

network A.0.0.0

!

ip classless

ip route 0.0.0.0 0.0.0.0 A.B.C.253

ip route H.K.L.0 255.255.252.0 Null0 254

ip route A.B.C.0 255.255.240.0 Null0 254

ip route M.N.S.0 255.255.248.0 Null0 254

ip route 192.168.0.0 255.255.255.0 172.16.0.10 permanent

ip http server

ip http authentication local

ip http secure-server

!

!

ip access-list extended Internet-in

deny ip 0.0.0.0 0.255.255.255 any log

deny ip host 255.255.255.255 any log

deny ip 127.0.0.0 0.255.255.255 any log

deny ip 224.0.0.0 15.255.255.255 any log

deny ip 240.0.0.0 7.255.255.255 any log

deny ip 192.168.0.0 0.0.255.255 any log

deny ip 172.16.0.0 0.15.255.255 any log

deny ip 10.0.0.0 0.255.255.255 any log

deny ip 192.0.2.0 0.0.0.255 any log

deny ip 169.254.0.0 0.0.255.255 any log

deny ip 172.18.0.0 0.0.255.255 any log

deny ip 172.28.0.0 0.0.255.255 any log

deny ip 172.23.0.0 0.0.255.255 any log

permit ip any host 194.186.72.142

permit ip host 194.186.72.142 any

permit ip any 194.186.192.0 0.0.0.255

deny ip any any log

!

logging trap debugging

logging facility local5

!

access-list 1 permit M.N.S.0 0.0.7.255

access-list 1 permit H.K.L.0 0.0.3.255

no cdp run

!

route-map PBR permit 10

match ip address 1

set ip next-hop A.B.C.252

!

snmp-server enable traps envmon fan shutdown supply temperature status

snmp-server manager

!

control-plane

!

!

line con 0

login local

line vty 0 4

login local

line vty 5 15

login local

!

ntp clock-period 36029257

ntp server 83.229.210.18

ntp server 193.41.86.117

ntp server 79.120.83.33

ntp server 212.192.253.168

ntp server 192.168.0.122

end

 

 

3750-48#sh route-map PBR

route-map PBR, permit, sequence 10

Match clauses:

ip address (access-lists): 1

Set clauses:

ip next-hop A.B.C.252

Nexthop tracking current: A.B.C.252

A.B.C.252, fib_nh:3E9DFA4,oce:484B850,status:1

 

Policy routing matches: 0 packets, 0 bytes

Edited by ichthyandr
Posted

А где у вас абоненты? На Vlan2?

А Vlan3 это линк наружу?

тогда route-map PBR надо на другой интерфейс прикручивать. PBR на input работает обычно.

Posted (edited)

А где у вас абоненты? На Vlan2?

А Vlan3 это линк наружу?

тогда route-map PBR надо на другой интерфейс прикручивать. PBR на input работает обычно.

абоненты на NAS-ах, внутренние интерфейсы насов в Vlan1, внешние в Vlan2 (Vlan2 держит RIP домен), Vlan3 - uplink к BGP бордерам

мне нужно трафик от разных блоков раскидать на разные бордеры, по умолчанию все льется на .253, а два других нужно слить на .252

"PBR на input работает обычно" - т.е. полиси роут-мап должен быть на Vlan2?

 

С уважением

Edited by ichthyandr
Posted

Да, в вашем случае - на влан 2. Т.е. трафик пришедший от абонента через НАС кидается на соотв. некстхоп. на основе сурс-адреса абонента.

Но как при этом пойдёт входящий - тайна великая есть...

Posted

Да, в вашем случае - на влан 2. Т.е. трафик пришедший от абонента через НАС кидается на соотв. некстхоп. на основе сурс-адреса абонента.

Но как при этом пойдёт входящий - тайна великая есть...

Спасибо помогло :) Входящий трафик разделил препендами на BGP бордерах, т.к. подключен к двум ISP

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...