[c-nsp] Simple NAT based IOS failover between providers

Rodney Dunn rodunn at cisco.com
Tue Sep 27 10:30:00 EDT 2005


On Tue, Sep 27, 2005 at 12:02:26PM +0200, Gert Doering wrote:
> Hi,
> 
> On Mon, Sep 26, 2005 at 12:32:57PM -0400, Rodney Dunn wrote:
> > The gotcha I think with this is that any existing flow that
> > is being NAT'ed will fail until it times out because
> > a new translation on the new interface will have to be created.
> 
> Yes - but that's unavoidable anyway, given the fact that "ISP B"
> won't know to route "ISP A"'s IP addresses back over the link

Yep. Funny is it worked in the lab and then I realized it was
because my simulation was with two links to the same "ISP" router. :)

> 
> For web surfing (-alike) traffic, consisting of lots of short TCP
> session, this shouldn't be a major problem.

Agree.

> 
> For things like "working over Citrix / remote desktop" this could
> be fairly annoying...

Agree.

I'm working on the timeout problem with the probe. It looks broke
to me as it doesn't honor the consecutive retries I configured and
takes the route down immediately. Just a gotha with the configuration
I gave for now.

> 
> gert
> -- 
> USENET is *not* the non-clickable part of WWW!
>                                                            //www.muc.de/~gert/
> Gert Doering - Munich, Germany                             gert at greenie.muc.de
> fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de


More information about the cisco-nsp mailing list