zakwan
March 2, 2020, 10:21am
1
Hi,
Please help me on the requirement below.
The situation are :
The connection between Router X to Vyos1(203.X.X.1) is using vpn ipsec site to site peer.
Vyos 1 and Vyos2 have an Internet connection via eth0
There is direct connection from Vyos1 to Vyos2 both using eth1
Some of the connection (besides 10.10.10.0/24) using internet via Vyos1.
However, i would like to try if 10.10.10.0/24 can using internet via Vyos2.
Please advise if this is possible.
Hi, zakwan
Maybe you met the same issue as me. Please follow my instruction to fixed this issue.
Hello @echowings , I reproduced this schema in our laboratory, and I think I have workaround.
[06]
On GW2 needs to add static route to l2tp client
set protocols static route 192.168.255.0/24 next-hop 10.0.0.2
And in VyOS-l2tp node add ip rule (not VyOS CLI command)
sudo ip rule add from 192.168.255.0/24 table 100
#and
set protocols static table 100 route 0.0.0.0/0 next-hop 10.0.0.1
ps:// Thanks @Viacheslav for idea
zakwan
March 3, 2020, 2:18am
3
Hi echowings,
Its working. Thank you so much
Please say something to improve priority of the request feature.
@zakwan
https://phabricator.vyos.net/T2012
zakwan
March 4, 2020, 2:45am
5
Hi echowings,
I found a proper PBR using vyos commands instead of Linux.
Below is the Vyos commands i used to replace Linux commands :
Need to set PBR on the policy commands
VyosRouter1#sh policy route TO-Vyos2
rule 1000 {
set {
table 100
}
source {
address 10.10.10.0/24
}
Set the static table 100 to Vyos2
VyosRouter1# sh protocols static table 100
route 0.0.0.0/0 {
next-hop 10.40.X.X {
}
Set static route Vyos2 to Vyos1
VyosRouter1# sh protocols static
route 10.10.10.0/24 {
next-hop 10.40.X.X {
}
}
This is great. PBR is suitable for your case. But I need the Globle PBR function to let all network from vpn route 0.0.0.0/0 to another gateway.