Path Control: PBR & IP SLA

CCNP ENARSI 300-410 EVE-NG / GNS3

مقصدObjectiveObjective

اس لیب میں آپ Policy-Based Routing (PBR) سے ٹریفک کو routing table کے بجائے پالیسی پر چلانا، اور IP SLA سے لنک کی نگرانی اور automatic failover سیکھیں گے۔Is lab mein aap Policy-Based Routing (PBR) se traffic ko routing table ke bajaye policy par chalana, aur IP SLA se link ki nigrani aur automatic failover seekhenge.In this lab you will learn to steer traffic by policy instead of the routing table with Policy-Based Routing (PBR), and monitor links with IP SLA for automatic failover.

آسان مثالSimple AnalogySimple Analogy

عام routing ایسے ہے جیسے سب گاڑیاں ایک ہی سائن بورڈ دیکھ کر چلیں۔ PBR ایسا ہے جیسے ٹریفک پولیس مخصوص گاڑیوں (مثلاً ایمبولینس) کو الگ راستے پر بھیج دے۔ IP SLA وہ چوکیدار ہے جو پل کی حالت چیک کرتا رہتا ہے اور خراب ہونے پر ٹریفک دوسرے پل پر موڑ دیتا ہے۔Aam routing aise hai jaise sab gariyan ek hi sign board dekh kar chalein. PBR aisa hai jaise traffic police makhsoos gariyon (masalan ambulance) ko alag raste par bhej de. IP SLA woh chokidar hai jo pul ki haalat check karta rehta hai aur kharab hone par traffic doosre pul par mor deta hai.Normal routing is like all cars following the same signboard. PBR is like traffic police sending specific vehicles (e.g. ambulances) down a different road. IP SLA is the watchman who keeps checking the bridge and diverts traffic to another bridge when it fails.

سیٹ اپLab SetupLab Setup

R1 کے دو WAN لنکس ہیں: R2 کی طرف primary لنک اور R3 کی طرف backup لنک۔ R1 کے LAN سے کچھ ٹریفک ہمیشہ R2 والے راستے سے جانا چاہیے (پالیسی)، چاہے routing table کچھ بھی کہے۔R1 ke do WAN links hain: R2 ki taraf primary link aur R3 ki taraf backup link. R1 ke LAN se kuch traffic hamesha R2 wale raste se jana chahiye (policy), chahe routing table kuch bhi kahe.R1 has two WAN links: a primary link toward R2 and a backup link toward R3. Some traffic from R1's LAN must always take the R2 path (policy), no matter what the routing table says.

اقداماتStepsSteps

Step 1

PBR کے لیے ٹریفک کی شناخت کریں۔ Access-list بنائیں جو اس ٹریفک کو match کرے جسے پالیسی پر چلانا ہے — مثلاً LAN کے مخصوص ہوسٹ سے آنے والا ٹریفک۔PBR ke liye traffic ki shinakht karein. Access-list banayein jo us traffic ko match kare jise policy par chalana hai — masalan LAN ke makhsoos host se aane wala traffic.Identify the traffic for PBR. Create an access-list matching the traffic to policy-route — e.g. traffic from a specific LAN host.

configure terminal
ip access-list extended PBR-TRAFFIC
permit ip 10.1.1.0 0.0.0.255 any
exit

Step 2

Route-map بنائیں۔ Route-map میں match access-list اور set ip next-hop لگائیں — یہی PBR کا دل ہے: routing table کو نظرانداز کر کے next-hop خود طے کرنا۔Route-map banayein. Route-map mein match access-list aur set ip next-hop lagayein — yehi PBR ka dil hai: routing table ko nazar-andaz kar ke next-hop khud tay karna.Create the route-map. In the route-map, match the access-list and set ip next-hop — this is the heart of PBR: overriding the routing table to pick the next hop yourself.

configure terminal
route-map PBR-POLICY permit 10
match ip address PBR-TRAFFIC
set ip next-hop 192.168.12.2
exit

Step 3

Route-map کو انٹرفیس پر لگائیں۔ ip policy route-map کمانڈ LAN والے انٹرفیس (inbound) پر لگتی ہے — آنے والے ٹریفک پر پالیسی لاگو ہوتی ہے۔Route-map ko interface par lagayein. ip policy route-map command LAN wale interface (inbound) par lagti hai — aane wale traffic par policy lagu hoti hai.Apply the route-map to the interface. ip policy route-map goes on the LAN-facing interface (inbound) — the policy applies to incoming traffic.

configure terminal
interface GigabitEthernet0/1
ip policy route-map PBR-POLICY
exit

Step 4

PBR کی تصدیق کریں۔ show route-map اور show ip policy سے دیکھیں کہ پالیسی لگی ہے۔ LAN سے ping کر کے traceroute سے راستہ چیک کریں۔PBR ki tasdeeq karein. show route-map aur show ip policy se dekhein ke policy lagi hai. LAN se ping kar ke traceroute se rasta check karein.Verify PBR. Use show route-map and show ip policy to confirm the policy is applied. Ping from the LAN and check the path with traceroute.

show route-map
show ip policy

Step 5

IP SLA بنائیں۔ IP SLA operation بنائیں جو primary next-hop کو ICMP echo سے چیک کرے — ہر 10 سیکنڈ میں ایک ping۔ یہ لنک کی صحت کی نگرانی ہے۔IP SLA banayein. IP SLA operation banayein jo primary next-hop ko ICMP echo se check kare — har 10 second mein ek ping. Ye link ki sehat ki nigrani hai.Create an IP SLA. Build an IP SLA operation that probes the primary next-hop with ICMP echo — one ping every 10 seconds. This monitors link health.

configure terminal
ip sla 1
icmp-echo 192.168.12.2
frequency 10
exit
ip sla schedule 1 life forever start-time now
exit

Step 6

Track object بنائیں اور PBR سے جوڑیں۔ Track object IP SLA کے نتیجے کو دیکھتا ہے۔ Route-map میں set ip next-hop verify-availability لگا کر کہیں: اگر primary down ہو تو backup next-hop استعمال کرو۔Track object banayein aur PBR se jorein. Track object IP SLA ke nateeje ko dekhta hai. Route-map mein set ip next-hop verify-availability laga kar kahein: agar primary down ho to backup next-hop istemal karo.Create a track object and tie it to PBR. The track object watches the IP SLA result. In the route-map, use set ip next-hop verify-availability: if the primary is down, use the backup next-hop.

configure terminal
track 1 ip sla 1 reachability
exit
configure terminal
route-map PBR-POLICY permit 10
set ip next-hop verify-availability 192.168.12.2 1 track 1
set ip next-hop 192.168.13.3
exit

Step 7

Failover ٹیسٹ کریں۔ Primary لنک down کریں (shutdown) اور دیکھیں کہ ٹریفک خود بخود backup لنک پر چلا جاتا ہے۔ show track سے state چیک کریں۔Failover test karein. Primary link down karein (shutdown) aur dekhein ke traffic khud bakhud backup link par chala jata hai. show track se state check karein.Test the failover. Shut down the primary link and watch traffic automatically move to the backup link. Check state with show track.

show track
show ip sla statistics 1

تصدیقVerifyVerify

PBR لگنے پر ٹریفک routing table کے خلاف بھی R2 والے راستے سے جائے۔ Primary لنک down کرنے پر track state down ہو اور ٹریفک backup پر منتقل ہو جائے۔PBR lagne par traffic routing table ke khilaf bhi R2 wale raste se jaye. Primary link down karne par track state down ho aur traffic backup par muntaqil ho jaye.With PBR applied, traffic should take the R2 path even against the routing table. After shutting the primary link, the track state should go down and traffic should shift to backup.

show route-map
show track
show ip sla statistics 1

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ PBR لگانے کے باوجود ٹریفک پالیسی پر نہیں جا رہا۔PBR lagane ke bawajood traffic policy par nahi ja raha.Traffic isn't following the policy despite PBR.

✅ چیک کریں کہ route-map صحیح انٹرفیس پر inbound لگی ہے، access-list ٹریفک کو match کر رہی ہے، اور راؤٹر خود کا generated ٹریفک PBR سے نہیں گزرتا (صرف transit ٹریفک)۔Check karein ke route-map sahi interface par inbound lagi hai, access-list traffic ko match kar rahi hai, aur router khud ka generated traffic PBR se nahi guzarta (sirf transit traffic).Check the route-map is inbound on the right interface, the access-list matches the traffic, and remember locally-generated traffic bypasses PBR (only transit traffic is policy-routed).

⚠️ IP SLA up ہے مگر failover نہیں ہو رہا۔IP SLA up hai magar failover nahi ho raha.IP SLA is up but failover isn't happening.

✅ Track object کی state چیک کریں — شاید track IP SLA سے جڑا ہی نہیں۔ show track میں delay یا غلط operation number عام وجہ ہے۔Track object ki state check karein — shayad track IP SLA se jura hi nahi. show track mein delay ya ghalat operation number aam wajah hai.Check the track object's state — it may not be tied to the IP SLA. In show track, a delay or wrong operation number is the common cause.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ PBR اور عام routing میں کیا فرق ہے؟PBR aur aam routing mein kya farq hai?What is the difference between PBR and normal routing?

عام routing destination IP کی بنیاد پر routing table سے فیصلہ کرتی ہے۔ PBR source، protocol، یا port جیسی شرائط پر فیصلہ کرتی ہے اور routing table کو override کر دیتی ہے۔Aam routing destination IP ki bunyad par routing table se faisla karti hai. PBR source, protocol, ya port jaisi sharait par faisla karti hai aur routing table ko override kar deti hai.Normal routing decides from the routing table based on destination IP. PBR decides on conditions like source, protocol, or port, and overrides the routing table.

❓ IP SLA کس کام آتا ہے؟IP SLA kis kaam aata hai?What is IP SLA used for?

IP SLA نیٹ ورک کی کارکردگی اور لنک کی دستیابی کی نگرانی کرتا ہے (ping، jitter وغیرہ)۔ Track objects کے ساتھ مل کر automatic failover جیسے فیصلے کرتا ہے۔IP SLA network ki karkardagi aur link ki dastyabi ki nigrani karta hai (ping, jitter waghera). Track objects ke saath mil kar automatic failover jaise faisle karta hai.IP SLA monitors network performance and link availability (ping, jitter, etc.). Combined with track objects it drives decisions like automatic failover.