VLAN Default Route

I'm need some help to solve a problem for a customer. Their primary Internet connection (from HQ) goes down a lot so they ordered Internet from the local cable company. HQ does not allow the alternate connection so it will be hidden. Here's how I thought I would solve the problem. Will this work?

Create two VLANs for the two ISPs and route between them using the L3 switch (3750). DHCP will have two scopes and will allocate IP addresses on the appropriate network. Each VLAN will need it's own default route to the respective gateway.

How do I set up a different default route for each VLAN?

Reply to
Bob Simon
Loading thread data ...

PBR should meet this requirement (policy based routing). Just google that w/ 'cisco' and there is plenty of good documentation out there.

Reply to
Trendkill

If you are in the US or Canada, then because you know that the company policy does not permit this connection, there is the danger that you could wind up charged with "exceeding authorized access" under the US Computer Fraud and Abuse Statutes, or the Canada Computer Security Act (as appropriate), both of which carry jail terms for this kind of conduct. Your only defence would be if you had a signed statement of the work to be done from your customer in which the signer claimed to have the authority to order the connection (and if you knew otherwise then you compound the charges into Conspiracy To..., which can often have much worse penalties than the original charges -- e.g., in the USA, Conspiracy to commit a Misdemenor is a Felony.)

Your contract could require that your customer reinburse you in the event of any fines or whatever, but it is not possible to create a contract in which your customer would somehow reinburse you for the time you spend in jail upon conviction. Heck, that would probably be considered a "proceeds of crime" clause.

I wouldn't do it, not without a signed paper that the installation is within the company security policy.

Reply to
Walter Roberson

Thanks for the tip to use PBR. I need to read up on this over the weekend.

As an alternative, can the 3750 be configured with two default routes having different metrics. If it didn't get a RIP advertisement from the prefered router within the timeout period, wouldn't this route be replaced by the other one? And when the preferred route became available again, wouldn't it be reinstalled in the route table?

Reply to
Bob Simon

Thank you. I will take appropriate precautions.

Reply to
Bob Simon

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.