Wednesday, August 4, 2021

Policy-based routing question/setup

Hi All,

I'll keep this short (I hope). We're brining in a 2nd ISP into our environment for path diversity with a new IP range. I wanted to get some info on how I can implement policy-based routing to have these links work in tandem, but I am unsure where to start as we got a handful of subnets and site-to-site VPNs with some vendors using our current ISP.

The setup seems simple, we have Cisco firepower's at our edge doing routing so I was hoping to just plug up the new ISP into this firepower and create my ACLs and do the route-maps, but, my question is where do I start? Do I just do a few subnets at a time? create a "test" subnet and use that first to make sure traffic flows correctly?

I am in a bit of a pickle due to the fact we're a 24/7 operation so scheduling this without testing could be problematic if something goes wrong.

I know i haven't given the bigger picture of our environment but just wanted to get an idea on how to plan and come up with the design.

Thank you!



No comments:

Post a Comment