I am able to fail a remote MPLS location (running iBGP) and have its IP Traffic traverse an IPSEC Tunnel
across the Internet and into an ASA. At the core router, I point that backup traffic to that ASA.
While the failover time is not instantaneous, it does resume in less than 30 seconds.
Network Details;
Remote Site1: 10.1.60.1/24 and Remote Site2: 10.1.70.1/24
Core Router: 10.1.2.1/24 with Failover ASA: 10.1.2.5/25
Here is what the Core Route configuration looks like;
!
router bgp 111
network 10.1.60.0 mask 255.255.255.0 route-map NoStatic backdoor
network 10.1.70.0 mask 255.255.255.0 route-map NoStatic2 backdoor
!
ip route 10.1.60.0 255.255.255.0 10.1.2.5 220 tag 220
ip route 10.1.70.0 255.255.255.0 10.1.2.5 225 tag 225
!
route-map NoStatic permit 10
match tag 220
set metric 220
!
route-map NoStatic2 permit 20
match tag 225
set metric 225
Comments
(There are currently no comments for this post.)