networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: Routing Issue
PostPosted: Fri May 04, 2012 11:06 am 
Offline
New Member
New Member

Joined: Fri May 04, 2012 11:05 am
Posts: 24
Certs: CCNA
Hi All,

We are getting ready to implement tacacs into our network, and I came to a problem. We have over 300 devices to upgrade running EIGRP. The subnet that I have been given to use for loopback address for tacacs source is 172.10.10.1 255.255.255.255

I have to put that in the eigrp statement as
network 172.10.10.1 0.0.0.0

but the problem is that I cannot advertise that same block on all 300+ devices. is there a way around this using some fancy routing? The IT want to keep the source on a loopback so I cannot use any physical interfaces, and we dont have any other virtual interfaces configured like vlans etc

I have not been given more than that one IP address.

Any Ideas?
Thanks


Top
 Profile  
 
 Post subject: Re: Routing Issue
PostPosted: Fri May 04, 2012 11:40 am 
Offline
Member
Member

Joined: Fri Nov 13, 2009 4:42 pm
Posts: 199
Certs: CCIE R&S
How in the world to you plan on differentiating between your devices in your TACACS server? That is impossible.


Top
 Profile  
 
 Post subject: Re: Routing Issue
PostPosted: Fri May 04, 2012 11:52 am 
Offline
New Member
New Member

Joined: Fri May 04, 2012 11:05 am
Posts: 24
Certs: CCNA
I dont know what you are asking me. If you are telling me that this isnt working I can tell you that it is if I use diffrent subnet for each device.


Top
 Profile  
 
 Post subject: Re: Routing Issue
PostPosted: Fri May 04, 2012 12:48 pm 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Thu Jan 13, 2011 5:10 pm
Posts: 991
Location: Leeds, UK
Certs: CCIE R&S #38338, CCNP, CCIP
What willroute4food is saying is that if you were to have 300 routers all with the TACACS source of 192.168.1.1 then the return packet from the TACACS server would never (well 1/300) get back to the right router.

Are you sure they didn't give you the whole /23 or something to use for loopbacks and to only use a /32 on each one for the loopback?

_________________
---
David
CCIE R&S #38338, CCIP, CCNP

http://networkbroadcast.co.uk - My Blog
http://twitter.com/davidrothera


Top
 Profile  
 
 Post subject: Re: Routing Issue
PostPosted: Fri May 04, 2012 1:08 pm 
Offline
Member
Member

Joined: Fri Nov 13, 2009 4:42 pm
Posts: 199
Certs: CCIE R&S
davidrothera wrote:
What willroute4food is saying is that if you were to have 300 routers all with the TACACS source of 192.168.1.1 then the return packet from the TACACS server would never (well 1/300) get back to the right router.

Are you sure they didn't give you the whole /23 or something to use for loopbacks and to only use a /32 on each one for the loopback?


Correct, if you put this:
router eigrp 100
network 172.10.10.1 0.0.0.0

on every single router then your dicked (with the exact same ip on all your loopbacks). Thats exactly what Im saying. Now, if they gave you a /23 and said use a 32 bit mask for every address, then your ok. That snippet above, along with a /32 bit mask on the interface will only advertise a /32 (auto-summary be damned) to the network...and that is doable. But if what your saying is that you only have 1 ip address for 300 routers then your screwed from the git-go.


Top
 Profile  
 
 Post subject: Re: Routing Issue
PostPosted: Fri May 04, 2012 2:20 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8459
Location: Frederick MD
Certs: Instanity
ya, you will need a range of ip's
put in management vlan
secure.

watch out for routers it could mess up some routing if the RID changes at the next reboot.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
 Post subject: Re: Routing Issue
PostPosted: Mon May 07, 2012 12:59 pm 
Offline
New Member
New Member

Joined: Fri May 04, 2012 11:05 am
Posts: 24
Certs: CCNA
That is what I thought... I will ask for a /23 to do this upgrade.

thanks


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Exabot [Bot], FaceBook [Linkcheck], kerpap, srg and 21 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group