Got it

Default route of vpn-instance

Created: May 20, 2020 07:00:47Latest reply: Sep 5, 2021 06:51:58 982 8 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi,

Please, I need your assistance of onconfiguring the vpn-instance.

I'm trying to isolate the management interface into a independent vpn instance for out-of-band management. But the configuration below doesn't achieve the goal. Though ping and access from the local subnet works, failed access the router from adifferent subnet. Also I've already added the default route to thevpn-instance but no success either.

#

ip vpn-instance mgmt-vpn

 ipv4-family

  route-distinguisher 100:1

  vpn-target 100:1 export-extcommunity

  vpn-target 100:1 import-extcommunity

#

ip route-static 0.0.0.0 0.0.0.0 vpn-instance mgmt-vpn x.x.x.x

#

interface GigabitEthernet0/0/1

 ip binding vpn-instance mgmt-vpn

 ip address x.x.x.y 255.255.255.0

 undo shutdown

#

Regards.


Featured Answers

Recommended answer

chenhui
Admin Created May 20, 2020 07:03:56

Hi,
The default route you configured is error.
The default route you posted will direct all the traffic to the mgmt-vpn, and, I think, which is not what you want, even the service might be impacted.
To bind the static route to the vpn-instance, please refer to the command below:
ip route-stat vpn-instance mgmt-vpn 0.0.0.0 0.0.0.0 x.x.x.x
View more
  • x
  • convention:

user_4237671
user_4237671 Created Sep 5, 2021 02:35:29 (0) (0)
 
All Answers
Hi,
The default route you configured is error.
The default route you posted will direct all the traffic to the mgmt-vpn, and, I think, which is not what you want, even the service might be impacted.
To bind the static route to the vpn-instance, please refer to the command below:
ip route-stat vpn-instance mgmt-vpn 0.0.0.0 0.0.0.0 x.x.x.x
View more
  • x
  • convention:

user_4237671
user_4237671 Created Sep 5, 2021 02:35:29 (0) (0)
 
hi,

Please change your static route config,now you redirect all traffic to mnmt-vpn as you don't wish
View more
  • x
  • convention:

Posted by chenhui at 2020-05-20 07:03 Hi,The default route you configured is error.The default route you posted will direct all the traffi ...
It's really thanks.
BTW, I found that the route could be configure as "ip route-static vpn-instance mgmt-vpn 0.0.0.0 0.0.0.0 vpn-instance xxx". Does this static route guide the traffic in vpn-instance mgmt-vpn to vpn-instance xxx?
View more
  • x
  • convention:

chenhui
chenhui Created May 22, 2020 00:31:32 (0) (0)
Yes, you are right.  
Posted by Sapte at 2020-05-20 07:28 hi,Please change your static route config,now you redirect all traffic to mnmt-vpn as you don't wish
It's really thanks.
BTW, I found that the route could be configure as "ip route-static vpn-instance mgmt-vpn 0.0.0.0 0.0.0.0 vpn-instance xxx". Does this static route guide the traffic in vpn-instance mgmt-vpn to vpn-instance xxx?
View more
  • x
  • convention:

Sapte
Sapte Created May 21, 2020 11:34:53 (0) (0)
Hi @user_3534491

Yes,also you can find the details in the below for you quesition

ip route-static vpn-instance vpn-source-name destination-address { mask | mask-length } { nexthop-address [ public ] | interface-type interface-number [ nexthop-address ] | vpn-instance vpn-destination-name nexthop-address }

From the soure vpn : mgmt-vpn
for thedestination 0.0.0.0.0
To tje destination vpn : xxx  
great
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.