Got it

How to route between VPN Instance and Global Routing Table

Latest reply: Sep 16, 2021 09:43:54 293 5 3 0 0

I have a router in my lab that I am trying to configure to solve an important issue in production.


The router has two interfaces that are relevant to this discussion, one on a VPN instance and the other on the global routing table.  I want to be able to ping from the global routing side to the VPN side.  I have been able to import the routes in both directions using static routes.  However, I cannot ping from one side to the other.  Please look at the relevant config and routing tables below.  What am I doing wrong?  


*** Configuration ***


ip vpn-instance cust-a

 description Customer-A

 ipv4-family

  route-distinguisher 0:201


interface GigabitEthernet0/0/0.201

 dot1q termination vid 201

 ip binding vpn-instance cust-a

 ip address 172.16.1.2 255.255.255.0


interface GigabitEthernet0/0/2

 ip address 57.1.1.9 255.255.255.240


ip route-static 172.16.1.0 255.255.255.0 GigabitEthernet0/0/0.201

ip route-static vpn-instance cust-a 57.1.1.0 255.255.255.240 GigabitEthernet0/0/2



*** Route Tables ***


[AR2220E-1]disp ip routing-table

Route Flags: R - relay, D - download to fib

------------------------------------------------------------------------------

Routing Tables: Public

         Destinations : 25       Routes : 25       


Destination/Mask    Proto   Pre  Cost      Flags NextHop         Interface


       57.1.1.0/28    Direct  0    0           D   57.1.1.9        GigabitEthernet0/0/2

       57.1.1.9/32   Direct  0    0           D   127.0.0.1       GigabitEthernet0/0/2

      57.1.1.15/32  Direct  0    0           D   127.0.0.1       GigabitEthernet0/0/2

      127.0.0.0/8   Direct  0    0           D   127.0.0.1       InLoopBack0

      127.0.0.1/32  Direct  0    0           D   127.0.0.1       InLoopBack0

127.255.255.255/32  Direct  0    0           D   127.0.0.1       InLoopBack0

     172.16.1.0/24  Static  60   0           D   172.16.1.2      GigabitEthernet0/0/0.201

255.255.255.255/32  Direct  0    0           D   127.0.0.1       InLoopBack0



[AR2220E-1]disp ip routing-table vpn-instance cust-a

Route Flags: R - relay, D - download to fib

------------------------------------------------------------------------------

Routing Tables: cust-a

         Destinations : 12       Routes : 12       


Destination/Mask    Proto   Pre  Cost      Flags NextHop         Interface


       57.1.1.0/28  Static  60   0           D   57.1.1.9        GigabitEthernet0/0/2

     172.16.1.0/24  Direct  0    0           D   172.16.1.2      GigabitEthernet0/0/0.201

     172.16.1.1/32  Direct  0    0           D   127.0.0.1       GigabitEthernet0/0/0.201

     172.16.1.2/32  Direct  0    0           D   127.0.0.1       GigabitEthernet0/0/0.201

   172.16.1.255/32  Direct  0    0           D   127.0.0.1       GigabitEthernet0/0/0.201

255.255.255.255/32  Direct  0    0           D   127.0.0.1       InLoopBack0


Here is my ping/trace results from my test PC on the global routing side:

C:\>ping 172.16.1.2

Pinging 172.16.1.2 with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 172.16.1.2:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\>ping 172.16.1.3

Pinging 172.16.1.3 with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 172.16.1.3:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\>tracert 172.16.1.2

Tracing route to 172.16.1.2 over a maximum of 30 hops

1 <1 ms <1 ms <1 ms 57.1.1.9
2 * * * Request timed out.
3 ^C
C:\>
C:\>tracert 172.16.1.3

Tracing route to 172.16.1.3 over a maximum of 30 hops

1 <1 ms <1 ms <1 ms 57.1.1.9
2 * * * Request timed out.
3 ^C
C:\>

(Note: 172.16.1.2 is VPN interface address. 172.16.1.3 is a next-hop router, which has a route back to 57.1.1.0/28 via 172.16.1.2.)
View more
  • x
  • convention:

WELL DONE FRIEND
View more
  • x
  • convention:

andersoncf1
MVE Author Created Jul 29, 2021 22:32:39

Very useful. Thanks for sharing
View more
  • x
  • convention:

Thanks for sharing! Keep up the good work!
View more
  • x
  • convention:

AL_93
Moderator Created Sep 16, 2021 09:43:54

Well done! Very useful post
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.