ichthyandr Posted April 5, 2011 Posted April 5, 2011 Всем приветы имеется в наличии каталист, настроен дефолтный гейтвей на роутер .253, в распоряжении 3 блока адресов. Появилась необходимость разделить трафик по блокам, т.е. по дефолту сливаем на .253 узел (1 блок адресов) и 2 остальных блока сливаем на .252 маршрутизатор. Попробовал для этого настроить PBR - эффекта ноль. Кто сталкивался, куда смотреть? IOS вот такой Cisco IOS Software, C3750 Software (C3750-ADVIPSERVICESK9-M), Version 12.2(46)SE, RELEASE SOFTWARE (fc2) C уважением ... Вставить ник Quote
Дегтярев Илья Posted April 5, 2011 Posted April 5, 2011 sdm profile поставили? В дефолтном pbr запрещен. Вставить ник Quote
ichthyandr Posted April 5, 2011 Author Posted April 5, 2011 sdm profile поставили? В дефолтном pbr запрещен. 3750-48#sh sdm prefer The current template is "desktop routing" template. The selected template optimizes the resources in the switch to support this level of features for 8 routed interfaces and 1024 VLANs. number of unicast mac addresses: 3K number of IPv4 IGMP groups + multicast routes: 1K number of IPv4 unicast routes: 11K number of directly-connected IPv4 hosts: 3K number of indirect IPv4 routes: 8K number of IPv4 policy based routing aces: 0.5K number of IPv4/MAC qos aces: 0.5K number of IPv4/MAC security aces: 1K вроде то что надо Вставить ник Quote
ichthyandr Posted April 5, 2011 Author Posted April 5, 2011 up sdm prefer routing-pbr. чтото такого профиля не наблюдается Вставить ник Quote
darkagent Posted April 5, 2011 Posted April 5, 2011 routing-pbr упоминается лишь в мамонтоподобных иосах. с 12.2(20) его не стало, остался тольк routing. с учетом того что routing-pbr по ткамам эквивалентен routing, заисключением того что в нем тупо можно было включать pbr, его выпилили. routing темплейт теперь отдувается за обоих. Вставить ник Quote
ichthyandr Posted April 6, 2011 Author Posted April 6, 2011 (edited) Тогда конфиг в студию. Building configuration... Current configuration : 10456 bytes ! ! version 12.2 no service pad service timestamps debug datetime msec localtime service timestamps log datetime localtime service password-encryption ! hostname 3750-48 ! boot-start-marker boot-end-marker ! logging buffered 128000 no logging console ! no aaa new-model clock timezone MSK 4 switch 1 provision ws-c3750g-48ts system mtu routing 1500 ip subnet-zero ip routing ! ! ! ! port-channel load-balance src-dst-ip ! ! ! spanning-tree mode pvst spanning-tree extend system-id no spanning-tree vlan 1-3 ! vlan internal allocation policy ascending ! no ip rcmd domain-lookup ip rcmd rsh-enable ! ! interface Null0 no ip unreachables ! interface Loopback0 no ip address ! interface Port-channel1 description NAS29-int-channel switchport mode access ! interface Port-channel2 description NAS27-int-channel switchport mode access ! interface Port-channel3 description NAS28-int-channel switchport mode access ! interface Port-channel4 description NAS28-ext-channel switchport access vlan 2 switchport mode access ! interface Port-channel5 description NAS27-ext-channel switchport access vlan 2 switchport mode access ! interface Port-channel6 description NAS29-ext-channel switchport access vlan 2 switchport mode access ! interface Port-channel7 description User-network-channel switchport mode access ! interface GigabitEthernet1/0/1 description USER-network-aggr1 switchport mode access channel-group 7 mode active ! interface GigabitEthernet1/0/2 description USER-network-aggr2 switchport mode access channel-group 7 mode active ! interface GigabitEthernet1/0/3 switchport mode access ! interface GigabitEthernet1/0/4 description Office network switchport mode access ! interface GigabitEthernet1/0/5 description NAS27-aggr1-int switchport mode access channel-group 2 mode active ! interface GigabitEthernet1/0/6 description NAS27-aggr2-int switchport mode access channel-group 2 mode active ! interface GigabitEthernet1/0/7 description NAS28-aggr1-int switchport mode access channel-group 3 mode active ! interface GigabitEthernet1/0/8 description NAS28-aggr2-int switchport mode access channel-group 3 mode active ! interface GigabitEthernet1/0/9 description serv14 int switchport mode access ! interface GigabitEthernet1/0/10 description serv11 int switchport mode access ! interface GigabitEthernet1/0/11 description www int switchport mode access ! interface GigabitEthernet1/0/12 description backup int switchport mode access ! interface GigabitEthernet1/0/13 description 7114 int switchport mode access ! interface GigabitEthernet1/0/14 description serv4 int switchport mode access ! interface GigabitEthernet1/0/15 switchport mode access ! interface GigabitEthernet1/0/16 description serv5 int switchport mode access ! interface GigabitEthernet1/0/17 description NAS29-aggr1-int switchport mode access channel-group 1 mode active ! interface GigabitEthernet1/0/18 description NAS29-aggr2-int switchport mode access channel-group 1 mode active ! interface GigabitEthernet1/0/19 description NAS27 int temp switchport mode access ! interface GigabitEthernet1/0/20 description NAS29 int temp switchport mode access ! interface GigabitEthernet1/0/21 switchport mode access ! interface GigabitEthernet1/0/22 description sberbank int switchport mode access ! interface GigabitEthernet1/0/23 switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/24 switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/25 description NAS28-aggr1-ext switchport access vlan 2 switchport mode access channel-group 4 mode active ! interface GigabitEthernet1/0/26 description NAS28-aggr2-ext switchport access vlan 2 switchport mode access channel-group 4 mode active ! interface GigabitEthernet1/0/27 description NAS27-aggr1-ext switchport access vlan 2 switchport mode access channel-group 5 mode active ! interface GigabitEthernet1/0/28 description NAS27-aggr2-ext switchport access vlan 2 switchport mode access channel-group 5 mode active ! interface GigabitEthernet1/0/29 description NAS29-aggr1-ext switchport access vlan 2 switchport mode access channel-group 6 mode active ! interface GigabitEthernet1/0/30 description NAS29-aggr2-ext switchport access vlan 2 switchport mode access channel-group 6 mode active ! interface GigabitEthernet1/0/31 description Cisco 7201 ext switchport access vlan 2 switchport mode access flowcontrol receive desired ! interface GigabitEthernet1/0/32 description serv14 ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/33 description serv11 ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/34 description serv5 ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/35 description www ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/36 description serv4 ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/37 description backup ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/38 description ethernet 3750 ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/39 description Yurev switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/40 switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/41 description serv10 ext switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/42 switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/43 switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/44 switchport access vlan 2 switchport mode access ! interface GigabitEthernet1/0/45 description BGP-1 switchport access vlan 3 switchport mode access ! interface GigabitEthernet1/0/46 description BGP-2 switchport access vlan 3 switchport mode access ! interface GigabitEthernet1/0/47 description speedtest switchport access vlan 3 switchport mode access ! interface GigabitEthernet1/0/48 switchport access vlan 3 switchport mode access ! interface GigabitEthernet1/0/49 ! interface GigabitEthernet1/0/50 ! interface GigabitEthernet1/0/51 ! interface GigabitEthernet1/0/52 ! interface Vlan1 description SVI-internal no ip address ! interface Vlan2 description SVI-external ip address A.B.C.1 255.255.255.224 ! interface Vlan3 description SVI-uplink ip address A.B.C.254 255.255.255.248 ip route-cache policy ip policy route-map PBR ! router rip network A.0.0.0 ! ip classless ip route 0.0.0.0 0.0.0.0 A.B.C.253 ip route H.K.L.0 255.255.252.0 Null0 254 ip route A.B.C.0 255.255.240.0 Null0 254 ip route M.N.S.0 255.255.248.0 Null0 254 ip route 192.168.0.0 255.255.255.0 172.16.0.10 permanent ip http server ip http authentication local ip http secure-server ! ! ip access-list extended Internet-in deny ip 0.0.0.0 0.255.255.255 any log deny ip host 255.255.255.255 any log deny ip 127.0.0.0 0.255.255.255 any log deny ip 224.0.0.0 15.255.255.255 any log deny ip 240.0.0.0 7.255.255.255 any log deny ip 192.168.0.0 0.0.255.255 any log deny ip 172.16.0.0 0.15.255.255 any log deny ip 10.0.0.0 0.255.255.255 any log deny ip 192.0.2.0 0.0.0.255 any log deny ip 169.254.0.0 0.0.255.255 any log deny ip 172.18.0.0 0.0.255.255 any log deny ip 172.28.0.0 0.0.255.255 any log deny ip 172.23.0.0 0.0.255.255 any log permit ip any host 194.186.72.142 permit ip host 194.186.72.142 any permit ip any 194.186.192.0 0.0.0.255 deny ip any any log ! logging trap debugging logging facility local5 ! access-list 1 permit M.N.S.0 0.0.7.255 access-list 1 permit H.K.L.0 0.0.3.255 no cdp run ! route-map PBR permit 10 match ip address 1 set ip next-hop A.B.C.252 ! snmp-server enable traps envmon fan shutdown supply temperature status snmp-server manager ! control-plane ! ! line con 0 login local line vty 0 4 login local line vty 5 15 login local ! ntp clock-period 36029257 ntp server 83.229.210.18 ntp server 193.41.86.117 ntp server 79.120.83.33 ntp server 212.192.253.168 ntp server 192.168.0.122 end 3750-48#sh route-map PBR route-map PBR, permit, sequence 10 Match clauses: ip address (access-lists): 1 Set clauses: ip next-hop A.B.C.252 Nexthop tracking current: A.B.C.252 A.B.C.252, fib_nh:3E9DFA4,oce:484B850,status:1 Policy routing matches: 0 packets, 0 bytes Edited April 6, 2011 by ichthyandr Вставить ник Quote
Stak Posted April 6, 2011 Posted April 6, 2011 А где у вас абоненты? На Vlan2? А Vlan3 это линк наружу? тогда route-map PBR надо на другой интерфейс прикручивать. PBR на input работает обычно. Вставить ник Quote
ichthyandr Posted April 6, 2011 Author Posted April 6, 2011 (edited) А где у вас абоненты? На Vlan2? А Vlan3 это линк наружу? тогда route-map PBR надо на другой интерфейс прикручивать. PBR на input работает обычно. абоненты на NAS-ах, внутренние интерфейсы насов в Vlan1, внешние в Vlan2 (Vlan2 держит RIP домен), Vlan3 - uplink к BGP бордерам мне нужно трафик от разных блоков раскидать на разные бордеры, по умолчанию все льется на .253, а два других нужно слить на .252 "PBR на input работает обычно" - т.е. полиси роут-мап должен быть на Vlan2? С уважением Edited April 6, 2011 by ichthyandr Вставить ник Quote
Stak Posted April 6, 2011 Posted April 6, 2011 Да, в вашем случае - на влан 2. Т.е. трафик пришедший от абонента через НАС кидается на соотв. некстхоп. на основе сурс-адреса абонента. Но как при этом пойдёт входящий - тайна великая есть... Вставить ник Quote
ichthyandr Posted April 7, 2011 Author Posted April 7, 2011 Да, в вашем случае - на влан 2. Т.е. трафик пришедший от абонента через НАС кидается на соотв. некстхоп. на основе сурс-адреса абонента. Но как при этом пойдёт входящий - тайна великая есть... Спасибо помогло :) Входящий трафик разделил препендами на BGP бордерах, т.к. подключен к двум ISP Вставить ник Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.