
ããã«ã¡ã¯ HunterXXIã«è§ŠçºãããŠããã®èšäºãèšäºã Two Providers at the Same Timeã ãŸãã¯ãCiscoäžã®VRFãåãããã¥ã¢ã«ISP ãã«æžããŸãã ã ç§ã¯èå³ãæã¡ãåé¡ãç 究ããå®è·µããŸããã ã·ã¹ã³ã«ãã¥ã¢ã«ISPãå®è£ ããçµéšãã2ã€ã®ISPãåæã«å®éã«äœ¿çšããããã«ã¯ããŒããã©ã³ã·ã³ã°ã§å ±æããããšæããŸãã
ãã¢ã¹ããŒã ïŒ

説æïŒ
ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ãEHWIC-4ESGã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ãããCisco 1921 IOSããŒãžã§ã³15.5ïŒ3ïŒM3ã§å®è¡ãããŸãã
- ããŒãGigabitEthernet0 / 0ããã³GigabitEthernet0 / 1ã¯ãISPã®æ¥ç¶ã«äœ¿çšãããŸãã
- GigabitEthernet0 / 0/0ããã³GigabitEthernet0 / 0/1ããŒãã¯TRUNKã§æ§æãããã¹ã€ããã«æ¥ç¶ãããŸãã
- ããŒã«ã«ãããã¯ãŒã¯ã䜿çšããã«ã¯ãVLANã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšãããŸãã
- ãã®ã¹ããŒã ã¯ãVLAN 100ã192.168.101.0 / 24 VLAN 101ãããã³192.168.102.0/24 VLAN 102ã®3ã€ã®ããŒã«ã«IPãããã¯ãŒã¯192.168.100.0/24ãæäŸããŸãã
- ãã®äŸã§ã¯ãVLAN 100ãšVLAN 101ã¯çžäºã«æ¥ç¶ãããŸããã101ã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ãããVLAN 102ã¯ã€ã³ã¿ãŒãããã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã
ãããã£ãŠãVRFéã®ã€ã³ããŒã/ãšã¯ã¹ããŒãã®å¯èœæ§ã瀺ãããšãèããããŸãã
æ®ãã®ç©çããŒãã¯é¢ä¿ããŸããããèªåã®å€æã§ãããã䜿çšããããšã劚ãããã®ã¯äœããããŸããã
Gi0 / 0/0ããã³Gi0 / 0/1ã®èšå®
interface GigabitEthernet0/0/0 description TRUNK=>sw-access-1 switchport mode trunk no ip address end interface GigabitEthernet0/0/1 description TRUNK=>sw-access-2 switchport mode trunk no ip address end
VRFèšå®
ã·ã¹ã³ãšã¯ã¹ãã¬ã¹ãã©ã¯ãŒãã£ã³ã°ãã¯ãããžãŒïŒCEFïŒ-VRFãæ©èœãããã«ã¯æå¹ã«ããå¿ èŠããããŸãã
ISPçšã®VRFãæ§æãã
ip vrf isp1 description ISP1 rd 65000:1 route-target export 65000:1 route-target import 65000:100 route-target import 65000:102 ip vrf isp2 description ISP2 rd 65000:2 route-target export 65000:2 route-target import 65000:100 route-target import 65000:102
VLAN 101ã«å²ãåœãŠãããæ§æã«ã¯65000ïŒ101ã€ã³ããŒãããªãããšã«æ³šæããŠãã ããããããã£ãŠãisp1ããã³isp2ä»®æ³ã«ãŒã¿ãŒã«ã¯ããããã¯ãŒã¯192.168.101.0/24ãžã®ã«ãŒãããããŸããã
VLANã®VRFãæ§æãã
ip vrf 100 description VLAN_Desktop rd 65000:100 route-target export 65000:100 route-target import 65000:1 route-target import 65000:2 route-target import 65000:101 ip vrf 101 description VLAN_Voice rd 65000:101 route-target export 65000:101 route-target import 65000:100 ip vrf 102 description VLAN_Wireless rd 65000:102 route-target export 65000:102 route-target import 65000:1 route-target import 65000:2
VRF 101ã«åã³æ³šæããŠãã ãããVRF101ã¯ISPãšã«ãŒãã亀æãããVRF 100ãšäº€æããŸãã
ç§èªèº«ã®çµéšãããISPã®VRFãšããååã¯isp1ããã³isp2ãšããŠäœ¿çšãããšäŸ¿å©ã§ãããšç¢ºä¿¡ããŸãããVLANã®VRFãšããååã¯VLANçªå·ã«å¯Ÿå¿ããå¿ èŠããããŸããVRFãèå¥ãããã®ã¯ãã¹ãŠèª¬æã§ãã ããã¯ãããšãã°ããããã€ããŒã®1ã€ãå€æŽãããšãåæ§æå šäœãã€ã³ã¿ãŒãã§ã€ã¹ãšèª¬æã®IPã¢ãã¬ã¹ã®å€æŽã«æžããšããäºå®ã«ãããã®ã§ãã
ã€ã³ã¿ãŒãã§ã€ã¹æ§æ
IPã¢ãã¬ã¹ãå²ãåœãŠãåã«ãã€ã³ã¿ãŒãã§ã€ã¹ã§ip vrf forwardingã³ãã³ãã䜿çšããå¿ èŠããããŸãã ããã§ãªãå ŽåãIPã¢ãã¬ã¹ã¯åé€ãããåå²ãåœãŠãå¿ èŠã«ãªããŸãã
ã¯ã³
interface GigabitEthernet0/0 description ISP1 ip vrf forwarding isp1 ip address 198.51.100.1 255.255.255.252 ip nat outside interface GigabitEthernet0/1 description ISP2 ip vrf forwarding isp2 ip address 203.0.113.1 255.255.255.252 ip nat outside
LAN
interface Vlan100 description VLAN_Desktop ip vrf forwarding 100 ip address 192.168.100.254 255.255.255.0 ip nat inside interface Vlan101 description VLAN_Voice ip vrf forwarding 101 ip address 192.168.101.254 255.255.255.0 ip nat inside interface Vlan102 description VLAN_Wireless ip vrf forwarding 102 ip address 192.168.102.254 255.255.255.0 ip nat inside
é©åãªVLANãäœæããããšãå¿ããªãã§ãã ããã
vlan 100 name Desktop exit vlan 101 name Voice exit vlan 102 name Wireless exit show vlan-switch VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active 100 Desktop active 101 Voice active 102 Wireless active
Vlan1ã¯äœ¿çšãããŸãããã€ã³ã¿ãŒãã§ã€ã¹ãç¡å¹ã«ããããšã¯çã«ããªã£ãŠããŸãã
interface Vlan1 shutdown
BGPèšå®
router bgp 65000 bgp log-neighbor-changes address-family ipv4 vrf 100 redistribute connected maximum-paths 2 exit-address-family address-family ipv4 vrf 101 redistribute connected exit-address-family address-family ipv4 vrf 102 redistribute connected maximum-paths 2 exit-address-family address-family ipv4 vrf isp1 redistribute connected redistribute static route-map BGP_Filter default-information originate exit-address-family address-family ipv4 vrf isp2 redistribute connected redistribute static route-map BGP_Filter default-information originate exit-address-family
åBGPã¢ãã¬ã¹ãã¡ããªã¯VRFçšã«åå¥ã«æ§æãããæ¥ç¶ãããã«ãŒããåé åžããŸãïŒæ¥ç¶ãåé åžããŸãïŒã ããã©ã«ãã§ã¯ãVRF isp1ãéãã«ãŒããšisp2ãéãã«ãŒãã®2ã€ã®ã«ãŒãããããŸãã maximum-paths 2ãªãã·ã§ã³ã䜿çšãããšãäž¡æ¹ã®ããã©ã«ãã«ãŒããVRF 100ããã³102ã«ã€ã³ããŒãã§ããŸãã
次ã®ããã«ãªããŸãã
show ip route vrf 100 B* 0.0.0.0/0 [20/0] via 203.0.112.2 (isp2), 0d01h [20/0] via 198.51.100.2 (isp1), 0d01h
Ciscoã«ãŒã¿ãŒã¯ãåãã³ã¹ãã§åãæ¹åã®ã«ãŒãã®ãã©ãã£ãã¯ãèªåçã«åæ£ããŸãã
VRFãisp1ããã³isp2ã§ã¯ãæ¥ç¶ãããåé åžã«å ããŠãéçããã³ããã©ã«ãæ å ±çºä¿¡ãåé åžã§ããããã«ããå¿ èŠããããŸããããã«ãããããã©ã«ãã²ãŒããŠã§ã€ãä»ã®VRFã«è»¢éã§ããŸãã éçåé åžã¯ãã«ãŒããããBGP_Filterãä»ããŠè¡ãããããšã«æ°ä»ããããããŸããã ããã¯ã8.8.8.8ããã³80.80.80.80ãžã®ã«ãŒããVRFã«ãŒãã£ã³ã°ããŒãã«100ããã³102ã«åé¡ãããªãããã«ãããŒã«ã«ãããã¯ãŒã¯ã§å®çŸ©ãããVRFã«ãŒãã£ã³ã°ããŒãã«ã®å€èŠ³äžã®çç±ã ãã§çºçããŸãã
ã«ãŒãã£ã³ã°èšå®
ã«ãŒãã£ã³ã°ãèšå®ããŸãããã èšå®ãè€éã«ããVRFã䜿çšããæ©èœã®1ã€ã¯ãç¹å®ã®VRFã§ãã¹ãŠãå®çŸ©ããå¿ èŠãããããšã§ãã
ip route vrf isp1 0.0.0.0 0.0.0.0 198.51.100.2 tag 100 track 100 ip route vrf isp2 0.0.0.0 0.0.0.0 203.0.112.2 tag 100 track 200
- ã¿ã°-ããŒã«ã«VRFãžã®éä¿¡ã®ããã«ãããã®ã«ãŒãã®ã¿ããã£ã«ã¿ãªã³ã°ããã®ã«åœ¹ç«ã¡ãŸã
- track-ã«ãŒãã®ããã©ãŒãã³ã¹ãæ åœãããªããžã§ã¯ãã瀺ããŸã
route-map BGP_Filter permit 10 description Fix BGP static redistribution match tag 100
ãã®ã«ãŒããããã䜿çšããŠVRF for ISPã«é©çšãããšãã¿ã°ãæã€ã«ãŒãã®ã¿ãåé åžãããæ®ãã¯ISP VRFå ã«ã®ã¿æ®ããŸãã
ip route vrf isp1 8.8.8.8 255.255.255.255 198.51.100.2 ip route vrf isp1 80.80.80.80 255.255.255.255 198.51.100.2 ip route vrf isp2 8.8.8.8 255.255.255.255 203.0.112.2 ip route vrf isp2 80.80.80.80 255.255.255.255 203.0.112.2
ãã¹ã8.8.8.8ãš80.80.80.80ãžã®åå¥ã®ã«ãŒããå¿ èŠã§ããããããã©ãã¯ãæ©èœããããã©ã«ãã²ãŒããŠã§ã€ãåæãããšãã«ããããã®ã¢ãã¬ã¹ã®å¯çšæ§ã確èªããæ©äŒããããŸãã ã¿ã°ãå²ãåœãŠãªããããã«ãŒããããã«åé¡ããããåé åžãããŸãã
NATã»ããã¢ãã
NATãæ©èœããããã«ã¯ãå éšãå€éšã€ã³ã¿ãŒãã§ã€ã¹ãæå®ããå¿ èŠããããŸãã å€éšãšåæ§ã«ãip nat outsideã³ãã³ãã䜿çšããŠãISPãæ¥ç¶ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ãå®çŸ©ããŸãã LANã«é¢é£ããä»ã®ãã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãip nat insideã³ãã³ãã«ãã£ãŠå éšãšããŠç€ºãããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹isp1ããã³isp2ãå®çŸ©ãããŠãã2ã€ã®ã«ãŒãããããäœæããå¿ èŠããããŸã
route-map isp1 permit 10 match interface GigabitEthernet0/0 route-map isp2 permit 10 match interface GigabitEthernet0/1
NATã«ãŒã«ã¯ãåISPãä»ããŠåVRFã«æå®ããå¿ èŠããããŸãã ãã®ç¶æ ã§ã¯ãVlan 101ã«ã¯ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹æš©ããªããããã«ãŒã«ãæå®ããå¿ èŠã¯ãããŸãããã«ãŒã«ãæå®ããŠããã«ãŒãã£ã³ã°ããªãããæ©èœããŸããã
ip nat inside source route-map isp1 interface GigabitEthernet0/0 vrf 100 overload ip nat inside source route-map isp2 interface GigabitEthernet0/1 vrf 100 overload ip nat inside source route-map isp1 interface GigabitEthernet0/0 vrf 102 overload ip nat inside source route-map isp2 interface GigabitEthernet0/1 vrf 102 overload
å°ãã®NATçè«
ã·ã¹ã³ã«ã¯å€ãã®çš®é¡ã®NATããããŸãã ã·ã¹ã³ã®çšèªã§ã¯ã䜿çšãããã®ã¯ãªãŒããŒããŒããŸãã¯PATã䜿çšãããã€ãããã¯NATãšåŒã°ããŸãã
NATãæ©èœããã«ã¯äœãå¿ èŠã§ããïŒ
åçŽãªNATæ§æã§ã¯ãããŒã«ã«ãããã¯ãŒã¯ãå®çŸ©ããå€æèŠåãé©çšããã¢ã¯ã»ã¹ãªã¹ããäœæããã ãã§ååã§ãã
ãããã£ãŠãç§ãã¡ã¯ããã®äžã«ãããŒããã£ã¹ããå«ãããã€ãŸãå¿ èŠãªãã¹ãŠã®èŠä»¶ãæºãããŠããããšã瀺ããŸãã
ããã¯åçŽãªæ§æèšå®ã§ãããè¿œå ã®è©³çŽ°ããªããŠãæçœã§ç解ãããããã®ã§ãã
æ§æã«é©çšããã«ãŒã«ã¯ããã»ã©æ確ã§ã¯ãããŸããã æãåºããŠãã ãããã«ãŒããããisp1ã¯GigabitEthernet0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ãå®çŸ©ããŸãã ã³ãã³ããèšãæãããšãåæ§ã®ãã®
ã©ã®GigabitEthernet0 / 0ã®ãœãŒã¹ãã©ãã£ãã¯ãå€æããå¿ èŠãããããšãããããŸããã
ãããç解ããã«ã¯ãã«ãŒã¿ãŒå ã§ãã±ãããæž¡ãã¡ã«ããºã ã«çªå ¥ããå¿ èŠããããŸãã
NATãæ©èœããã«ã¯äœãå¿ èŠã§ããïŒ
- å éšããã³å€éšã€ã³ã¿ãŒãã§ã€ã¹ãå®çŸ©ãã
- æŸéãããããšã瀺ã
- äœãæŸéããããã瀺ããŠãã ãã
- ãããŒããã£ã¹ããæå¹ã«ãã
åçŽãªNATæ§æã§ã¯ãããŒã«ã«ãããã¯ãŒã¯ãå®çŸ©ããå€æèŠåãé©çšããã¢ã¯ã»ã¹ãªã¹ããäœæããã ãã§ååã§ãã
ip access-list extended NAT permit ip 192.168.0.0 0.0.0.255 any ip nat inside source list NAT interface GigabitEthernet0/0 overload
ãããã£ãŠãç§ãã¡ã¯ããã®äžã«ãããŒããã£ã¹ããå«ãããã€ãŸãå¿ èŠãªãã¹ãŠã®èŠä»¶ãæºãããŠããããšã瀺ããŸãã
ããã¯åçŽãªæ§æèšå®ã§ãããè¿œå ã®è©³çŽ°ããªããŠãæçœã§ç解ãããããã®ã§ãã
æ§æã«é©çšããã«ãŒã«ã¯ããã»ã©æ確ã§ã¯ãããŸããã æãåºããŠãã ãããã«ãŒããããisp1ã¯GigabitEthernet0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ãå®çŸ©ããŸãã ã³ãã³ããèšãæãããšãåæ§ã®ãã®
ip nat inside source GigabitEthernet0/0 interface GigabitEthernet0/0 overload in vrf 100
ã©ã®GigabitEthernet0 / 0ã®ãœãŒã¹ãã©ãã£ãã¯ãå€æããå¿ èŠãããããšãããããŸããã
ãããç解ããã«ã¯ãã«ãŒã¿ãŒå ã§ãã±ãããæž¡ãã¡ã«ããºã ã«çªå ¥ããå¿ èŠããããŸãã
- å éšãšããŠããŒã¯ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ã«å°çãããã©ãã£ãã¯ã¯ãããŒããã£ã¹ããããŸããã ãããããããŒããã£ã¹ããšããŠã©ãã«ä»ããããŸãã
- ãã®ãã©ãã£ãã¯ãåŠçãã次ã®ã¹ãããã¯ãã«ãŒãã£ã³ã°ããŒãã«ãŸãã¯PBRã«åŸã£ãŠã«ãŒãã£ã³ã°ããããšã§ãã
- è¡šã«åŸã£ãŠããã©ãã£ãã¯ãå€éšãšããŠããŒã¯ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ã«å°éãããšããããŒããã£ã¹ããããŸãã
- ãã©ãã£ãã¯ãå€éšä»¥å€ã®ãããŒããã£ã¹ãã€ã³ã¿ãŒãã§ã€ã¹ã«èœã¡ãå Žåã¯çºçããŸããã
誀ã£ãŠãã«ãŒããããLANãããã€ã³ã¿ãŒãã§ã€ã¹Vlan100ãå®è¡ã§ãããšèãããããããŸããã ããããœãŒã¹ã«ãŒããããLANãªã©ã®ip natãšããŠäœ¿çšããŸããCiscoã® IlyaPodkopaev NATã«æè¬ããŸãã ããŒã1
ãã®èããåé¿ããã«ã¯ããã©ãã£ãã¯ããã§ã«å€éšã€ã³ã¿ãŒãã§ã€ã¹ã«ããããã®ãã©ãã£ãã¯ããã¯ãäœãçããªããããã€ã³ã¿ãŒãã§ã€ã¹ã«ãããšãã«ããã®å€æã«ãŒã«ãããªã¬ãŒãããããšãç解ããå¿ èŠããããŸãã
SLAã»ããã¢ãã
ip sla auto discovery ip sla 10 icmp-echo 198.51.100.2 vrf isp1 frequency 5 ip sla schedule 10 life forever start-time now ip sla 11 icmp-echo 8.8.8.8 vrf isp1 frequency 5 ip sla schedule 11 life forever start-time now ip sla 12 icmp-echo 80.80.80.80 vrf isp1 frequency 5 ip sla schedule 12 life forever start-time now ip sla 20 icmp-echo 203.0.112.2 vrf isp2 frequency 5 ip sla schedule 20 life forever start-time now ip sla 21 icmp-echo 8.8.8.8 vrf isp2 frequency 5 ip sla schedule 21 life forever start-time now ip sla 22 icmp-echo 80.80.80.80 vrf isp2 frequency 5 ip sla schedule 22 life forever start-time now
æ§æã«ã¯ç¹å¥ãªãã®ã¯ãããŸãããICMPããŒã8.8.8.8 80.80.80.80ããã³åISP VRFããã®ãããã€ããŒã«ãŒã¿ãŒãä»ããã¢ã¯ã»ã¹å¯èœæ§ããã§ãã¯ãããŸãã
ãã©ãã¯ã®ã»ããã¢ãã
track 100 list boolean and object 101 object 110 track 101 ip sla 10 reachability delay down 20 up 180 track 102 ip sla 11 reachability delay down 20 up 180 track 103 ip sla 12 reachability delay down 20 up 180 track 110 list boolean or object 102 object 103 track 200 list boolean and object 201 object 210 track 201 ip sla 20 reachability delay down 20 up 180 track 202 ip sla 21 reachability delay down 20 up 180 track 203 ip sla 22 reachability delay down 20 up 180 track 210 list boolean or object 202 object 203 track 1000 stub-object
ä»äºã®è«çïŒ
ã«ãŒãã£ã³ã°ããŒãã«ã«ã¯ããã©ãã¯100ã«é¢é£ä»ããããroute ip route vrf isp1 0.0.0.0 0.0.0.0 198.51.100.2 tag 100 track 100ããããŸãã
- ãã©ãã¯100ãUPç¶æ ã®å ŽåãããŒãã«ã«ã«ãŒãããããŸãã
- ãªããžã§ã¯ã100ã¯ããŒã«å€ã§ããã€ãŸãããã¹ãŠã®ãªããžã§ã¯ããUPç¶æ ã«ããå ŽåãUPãšèŠãªãããŸãã
- ãªããžã§ã¯ãã®ããããã100 DOWNã®å Žåãã¡ãã»ãŒãžãªããžã§ã¯ã100ã¯DOWNã«ãªããŸãã
- ãªããžã§ã¯ã101ãš110ãå«ãŸããŠããŸãã
- ãªããžã§ã¯ã101ã¯SLA 10ã«å¯Ÿå¿ãããããã€ããŒã®ã²ãŒããŠã§ã€ããã§ãã¯ããŸãã
- ãªããžã§ã¯ã110ã¯ã102ãŸãã¯103ãããŒã«å€ãšããŠçµåããŸããã€ãŸããUPãªããžã§ã¯ãã®å°ãªããšã1ã€ãUPã«ãªããšããªããžã§ã¯ãã¯UPã«ãªããŸãã
- ãªããžã§ã¯ã102ããã³103ã¯ããããã8.8.8.8ããã³80.80.80.80ããã§ãã¯ããŸãããããã¯ã誀æ€ç¥ãæé€ããããã«2ã€å¿ èŠã§ãã
ãããã£ãŠããããã€ããŒã®ããã©ã«ãã²ãŒããŠã§ã€ãå€éšã¢ãã¬ã¹ã®å°ãªããšã1ã€ãæºããå Žåãæ¥ç¶ã¯æ©èœããŠãããšèŠãªãããŸãã
ãã©ãã¯1000
track 1000 stub-object default-state down
ãã®ãªããžã§ã¯ãã®ããã©ã«ãã¯DOWNã§ãã
ãã®èšå®ã§ã¯ãISPã®1ã€ã匷å¶çã«åæããæ¥ç¶ããªãããã«ããã®ãªããžã§ã¯ããå¿ èŠã§ãã ãããè¡ãã«ã¯ããã©ãã¯1000ããªããžã§ã¯ã100ãŸãã¯200ã«è¿œå ããå¿ èŠããããŸããããŒã«å€ã«åºã¥ãããªããžã§ã¯ãã®1ã€ãDOWNã®å Žåããªããžã§ã¯ãå šäœãDOWNãšèŠãªãããŸãã
EEMã»ããã¢ãã
EEM-Embedded Event Managerã䜿çšãããšãç¹å®ã®ã€ãã³ãã«åŸã£ãŠã¢ã¯ã·ã§ã³ãèªååã§ããŸãã
ãã®å ŽåãISPã®1ã€ãåäœãåæ¢ãããšãã«ãŒãã£ã³ã°ããŒãã«ããé€å€ãããŸãã ãã ããNATå€æã«ãŒã«ã¯æ®ããŸãã ãã®ãããã¿ã€ã ã¢ãŠãã«ãã£ãŠNATå€æãã¯ãªã¢ããããŸã§ããã§ã«ç¢ºç«ãããŠãããŠãŒã¶ãŒæ¥ç¶ã¯ãã³ã°ããŸãã
ãã®ããã»ã¹ãé«éåããã«ã¯ãclear ip nat translation *ã³ãã³ãã䜿çšããŠNATããŒãã«ãã¯ãªã¢ããå¿ èŠããããŸããããã¯èªåçã«è¡ãã®ãæé©ã§ãã
event manager applet CLEANNAT-100 event track 100 state down action 10 cli command "enable" action 20 cli command "clean ip nat translation *" event manager applet CLEANNAT-200 event track 200 state down action 10 cli command "enable" action 20 cli command "clean ip nat translation *"
ãªããžã§ã¯ã100ãŸãã¯200ãDOWNç¶æ ã«ãªããšãã¢ã¯ã·ã§ã³ã³ãã³ããé çªã«å®è¡ãããŸãã
ãã³ããšã³ã
VRFã䜿çšããããã€ãã®æ©èœã«æ³šç®ããããšæããŸãã
ããšãã°ãNTPèšå®ïŒ
ntp server vrf isp1 132.163.4.103
VRFã䜿çšããããããããã¯ãŒã¯æäœã¯ãã¹ãŠä»®æ³ã«ãŒã¿ãŒã«å²ãåœãŠãå¿ èŠããããŸããããã¯ããã®æ§æãæ§æããŠshow ip routeãå®è¡ãããšãã«ãŒãã£ã³ã°ããŒãã«ã«ãšã³ããªã衚瀺ãããªãããã§ãã
ping vrf isp1 8.8.8.8
泚æããŠãã ããã
ãã®æ§æã®å©ç¹ã«ã¯ããã®æè»æ§ãå«ãŸããŸãã 1ã€ã®ISPãä»ããŠ1ã€ã®VLANãã2çªç®ã®ISPãä»ããŠå¥ã®VLANãç°¡åã«åŒãåºãããšãã§ããŸãã
çæãããã¯ãISPã®1ã€ãè±èœããå Žåã«ãå°æ¬ãããŠãã倧è¡ã®è³ªåã§ãããclear ip nat translations *ã³ãã³ãã¯ãåäœäžã®ISPãå«ããã¹ãŠã®æ¥ç¶ãåæããŸãã å®è·µã瀺ããŠããããã«ããããã€ããŒãè±èœããå ŽåããŠãŒã¶ãŒã¯ãã®ãåŽãã«æ°ä»ããªãããéèŠã§ã¯ãããŸããã
å€æããŒãã«ãéšåçã«ã¯ãªã¢ããæ¹æ³ã誰ããç¥ã£ãŠããã°ãæè¬ããŸãã
PS>
ãã©ã€ããŒããµãããããžã®NATå€æãç¡å¹ã«ããããšãå¿ããªãã§ãã ããã
ip access-list extended NO_NAT deny ip any 192.168.0.0 0.0.255.255 deny ip any 172.16.0.0 0.15.255.255 deny ip any 10.0.0.0 0.255.255.255 permit ip any any
route-map isp1 permit 10 match ip address NO_NAT match interface GigabitEthernet0/0