Forum Discussion

Syed_380258's avatar
Syed_380258
Icon for Nimbostratus rankNimbostratus
Dec 31, 2018

2 ISP's connected on F5 directly .

i have terminated two ISP links directly on F5 i 4800 which having DDOS license but right now no ddos configure . I have created 2 partitions and Route Domains for each . My question is that how i can use traffic on both ISP's at a time . IPSEC is running on both ISP's so when the outbound packet need to go ISP 1 they always go to ISP 1 and Same for ISP 2 but how i can achieve this . Please Answer this .

 

5 Replies

  • Shain_Singh_846's avatar
    Shain_Singh_846
    Historic F5 Account

    Hi Syed,

     

    Are you going to be using BGP to advertise a range of networks you own to both ISPs? Or will you just have a default route that you accept from both ISPs?

     

    At the moment, you question is more around networking design.

     

    Using Auto-Last-Hop (which is on by default), means return traffic on F5 devices will return the way it came in terms of your IPSEC traffic

     

    • Syed_380258's avatar
      Syed_380258
      Icon for Nimbostratus rankNimbostratus

      Thanks for the reply. Its arround networking.no bgp use . 2 default routes use which provided by ISPs . Right now after creation of partition and route domains seperate for each one segment is working properly but other segment inbound traffic not coming .

       

    • Shain_Singh_846's avatar
      Shain_Singh_846
      Historic F5 Account

      Have you got a snippet of config you can scrub and show?

       

      If I understand you correctly, inbound is only working for one ISP/Route-Domain and not the other one. Are there specific networks that both ISPs send traffic to you on? e.g. your public subnet range?

       

    • Syed_380258's avatar
      Syed_380258
      Icon for Nimbostratus rankNimbostratus

      Thanks for the comment . Issue has been resolved . After resolving routing . I appreciate your comments . Thanks alot .