Networking-Blog

My WordPress Blog

Cisco 887G ADSL + 3G Backup

VPN IP SLA – In order to keep vpn up and active.

IP SLA MONITOR STATIC FLOATING ROUTE SOURCE LAN :

ip sla 1
icmp-echo 10.20.0.1 source-interface vlan 1
threshold 2
timeout 1000
frequency 5
!
!
ip sla schedule 1 life forever start-time now
!
!
ip sla 10
icmp-echo 80.74.16.173 source-interface Dialer0
threshold 2
timeout 1000
frequency 5
!
ip sla schedule 10 life forever start-time now
ip sla responder
!
track 10 interface ATM0 line-protocol
delay down 15 up 15
!
!
ip route 0.0.0.0 0.0.0.0 Dialer0 name PRIMARY track 10
ip route 0.0.0.0 0.0.0.0 Cellular0 name 3G_BACKUP
!

Rest of the Configuration :

ADSL :

service internal
!
interface ATM0
no ip address
atm vc-per-vp 64
atm bandwidth dynamic
atm ilmi-keepalive 30 retry 5
pvc 0/38
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl sync interval 3
dsl sync mode itu
dsl operating-mode itu-dmt
dsl power-cutback 1
dsl noise-margin 3
dsl max-tone-bits 10
dsl bitswap both
!
interface Dialer0
ip address negotiated
ip verify unicast reverse-path
ip access-group INTERNET in
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap callin
ppp chap hostname test@securewan.co.uk
ppp chap password 0 password
ppp ipcp dns request
crypto map mapping
!

3G Interface

chat-script mobile “” “ATDT*98*1#” TIMEOUT 60 CONNECT

interface Cellular0
ip address negotiated
ip nat outside
encapsulation ppp
dialer in-band
dialer idle-timeout 0
dialer string mobile
dialer-group 1
ppp chap hostname web
ppp chap password 7 10590C1B
ppp ipcp dns request
crypto map mapping
!
!
interface Vlan1
description Corporate VLAN
ip address 10.20.4.100 255.255.255.0
ip access-group LAN in
ip tcp adjust-mss 1400
!

DNS Name-Server :

ip name-server 80.74.16.30
ip name-server 80.74.16.31
ip name-server 8.8.8.8
ip dns server
!
ip nat inside source route-map NAT_WW interface Dialer0 overload
ip nat inside source route-map NAT_3G interface Cellular0 overload
!
ip access-list extended NAT_ACL_WW
deny ip 10.20.4.0 0.0.0.255 10.20.0.0 0.0.255.255
permit ip 10.20.4.0 0.0.0.255 any
deny ip any any
!
ip access-list extended NAT_ACL_3G
deny ip 10.20.4.0 0.0.0.255 10.20.0.0 0.0.255.255
permit ip 10.20.4.0 0.0.0.255 any
deny ip any any
!
route-map NAT_WW permit 10
match ip address NAT_ACL_WW
!
route-map NAT_3G permit 20
match ip address NAT_ACL_3G

 

VPN :ADSL_3G

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2

!
crypto isakmp key cvsrtmvpn96 address 85.234.65.57crypto isakmp identity hostname
crypto isakmp keepalive 15 10

!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
!
crypto map mapping_3g 1 ipsec-isakmp
set peer 85.234.65.57
set security-association lifetime seconds 86400
set security-association idle-time 86400
set transform-set secure
match address VPN
!
ip access-list extended VPN
permit ip 10.20.4.0 0.0.0.255 any
!

ACCESS-LIST RULE :
ip access-list extended INTERNET
remark WAVEWORKS
permit ip 80.74.16.8 0.0.0.7 any
permit ip host 80.74.17.9 any
remark IPSEC_VPN
permit esp host 85.234.65.57 any
permit udp host 85.234.65.57 any eq isakmp
permit icmp host 85.234.65.57 any
remark ICMP
permit icmp any any administratively-prohibited
permit icmp any any echo-reply
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any traceroute
permit icmp any any unreachable
remark NTP
permit udp host 80.74.16.30 any eq ntp
permit udp host 80.74.16.31 any eq ntp
remark DNS
permit udp any eq domain any
remark DENY_ALL
deny ip any any log
!
ip access-list extended LAN
remark DENY_BROADCASTS
deny ip any host 10.20.4.0
deny ip any host 10.20.4.255
deny ip host 0.0.0.0 any
remark PERMIT_ALL
permit ip 10.20.4.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log
!
ip access-list standard TELNET_SSH
permit 80.74.17.9
permit 80.74.16.8 0.0.0.7
permit 10.20.4.0 0.0.0.255
!
line vty 0 4
access-class TELNET_SSH in
!
dialer-list 1 protocol ip permit
!
line 3
exec-timeout 0 0
script dialer mobile

 

LINUX VMG VPN PROFILE :

conn cvs161_3g
left=85.234.65.57
leftsubnet=0.0.0.0/0
right=0.0.0.0
rightid=@cvs161.waves.uk.net
rightsubnet=10.20.253.40/29
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=24h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=30

ipsec.secrets :

%any 85.234.65.57 : PSK “cvsrtmvpn96”

All Traffic will be forced to be sent down the tunnel including
INTERNET BREAK-OUT terminating at the Linux VM :

Linux VPN Profile

leftsubnet=0.0.0.0/0
right=0.0.0.0

Cisco Router VPN ACL set to :

ip access-list extended VPN
permit ip 10.20.4.0 0.0.0.255 any

This will cause all traffic to be pushed down the tunnel, even internet bound traffic.

 

Changes made to Linux terminating firewall

This will locally break-out sourced traffic to the internet :
iptables -t nat -I POSTROUTING 83 -o eth1 -s 10.20.4.0/24 -j MASQUERADE
!
route add –host 85.234.66.161 gw 85.234.65.57
!

This will provide HQ connectivity and block intersite connectivity as well
as allow
internet access :

iptables -I FORWARD 46 -s 10.20.78.0/26 -d 10.20.0.0/24 -j ACCEPT
iptables -I FORWARD 47 -s 10.20.0.0/24 -d 10.20.78.0/26 -j ACCEPT
iptables -I FORWARD 48 -s 10.20.78.0/26 -d 10.20.0.0/16 -j DROP
iptables -I FORWARD 49 -s 10.20.0.0/16 -d 10.20.78.0/26 -j DROP
iptables -I FORWARD 50 -s 10.20.78.0/26 -j ACCEPT
iptables -I FORWARD 51 -d 10.20.78.0/26 -j ACCEPT

 

This is to allow HQ site to be able to establish connectivity over to remote site via
ipsec vpn tunnel

iptables -t nat -N 3g_access

sudo iptables -t nat -I POSTROUTING 85 -s 10.20.0.0/24 -j 3g_access
!
sudo iptables -t nat -I 3g_access 5 -d 10.20.78.0/26 -p icmp –icmp-type echo-request -j ACCEPT
sudo iptables -t nat -I 3g_access 6 -d 10.20.78.0/26 -j ACCEPT

Cisco IP SLA

Senerio 1 : Sla Monitor with Route Map

ip sla monitor responder
ip sla monitor 1
type http operation get url http://www.cisco.com source-ipaddr 172.16.250.254
ip sla monitor schedule 1 life forever start-time now

!
!

track 1 rtr 1 reachability
delay down 180 up 180
!
ip local
policy route-map 1
!
route-map 1 permit 10
match ip address 150
set ip next-hop 192.168.50.250
!
ip route 0.0.0.0 0.0.0.0
192.168.50.250 track 1
ip route 0.0.0.0 0.0.0.0 172.16.18.10 10
!
access-list
150 permit ip host 172.16.250.254 any

!
!

Senerio 2 : IP SLA Monitor Static Floating Route :

ip sla 1
icmp-echo 10.1.1.1
timeout 1000
frequency 3
threshold 2

!

ip sla schedule 1 life forever start-time now
!
track 10 rtr 1 reachability

!
! Tagging the static route with the tracking object 10 and adjusting the AD of the
! floating static route to a higher value

!
ip route 0.0.0.0 0.0.0.0 172.16.1.1 track 10

!
ip route 0.0.0.0 0.0.0.0 172.16.1.5 254

!
!

Senerio 3 : IP SLA Monitor Ipsec Vpn :

In order to keep  Ipsec vpn active and always up with
crypto isakmp sa association.

Configured and Tested out on Cisco 850.

!

ip sla 1
icmp-echo 172.16.0.11 source-interface vlan 1
timeout 1000
frequency 3
threshold 2
!
ip sla schedule 1 life forever start-time now
!
!

ip sla 2
icmp-echo 172.18.192.10 source-interface vlan 1
timeout 1000
frequency 3
threshold 2
!
ip sla schedule 2 life forever start-time now
!
!
Senerio 4 : IP SLA DEFAULT ROUTE REDUNTANT…

ip sla monitor responder
ip sla monitor 10
http get
http://www.cisco.com source-ip 192.168.0.254
frequency 60
timeout 30
ip sla schedule 10 life forever start-time now

!
!
ip local policy route-map 1
!

route-map 1 permit 10
match ip address 99

set ip next-hop verify-availability 85.234.95.240 1 track 10
!
!

The first static route is only valid if the sla is successful. The second static route has an AD of 254
and will only make it into the routing table if no other matching route (default route – 85.234.95.240).

!
ip route 0.0.0.0 0.0.0.0 85.234.95.240 track 10
ip route 0.0.0.0 0.0.0.0 192.168.0.222 254
!
access-list 99 permit ip host 192.168.0.254 any

set ip next-hop verify-availability
Normally set ip next-hop will forward packets when the route-map is matched regardless
if the next hop is alive or not. Adding the verify-availability keyword, the router will check
the next hop availability via CDP before forwarding the packets, and when next-hop is dead,
the packets will be routed through the normal routing table
.


Show ip sla statistics

Cisco: Dynamic Failover with IP SLA

This post describes how to set up IP SLA to allow a static route to failover if pings to a specified internet host should fail. This is really useful if you have two ISPs (and thus, two default routes) where the router cannot detect a link failure. This is really common if you have a cable/DSL modem or some type of wireless connectivity. Here’s the basic config:

ip sla 1 < The number 1 here is arbitrary, used only to identify this sla. It is otherwise knows as the operation number>

icmp-echo 4.2.2.2 < 4.2.2.2 is a DNS server that responds to pings out on the internet>

timeout 500 < This is how long to wait for a response from the ping>

frequency 3 < This is the repeat rate for the SLA>

ip sla schedule 1 start-time now life forever < This command says “start SLA 1 now and keep it running forever>

track 1 rtr 1 reachability < This comand creates the track object “1″ and monitors the SLA 1>

now for the routing, we need to change the default route and associate it with the tracker

no ip route 0.0.0.0 0.0.0.0 1.1.1.1

and then put it back with the tracking

ip route 0.0.0.0 0.0.0.0 1.1.1.1 track 1

Then we need to add our secondary route

ip route 0.0.0.0 0.0.0.0 1.1.1.2 10

Now when the ping to 4.2.2.2 fails the primary route is removed and the secondary route with the higher metric becomes the default. The route will be reinstated when the connectivity is restored.

With the 12.4 and higher releases the commands have changed slightly but the “?” is your friend.