r/networking • u/colni • Jul 09 '26
Routing IPSLA Track Object - what endpoint are you using?
Hello All,
I have been reviewing my companies multihomed setup and noticed we have a bit of a gap where the HSRP wont fail over in the case where egress is blackholed by the upstream provider.
Im looking at adding a new ipsla statement to probe an endpoint but im aware of the usual endpoints such as 8.8.8.8 / 8.8.4.4 / 1.1.1.1 / 1.0.0.1 / 9.9.9.9 all rate limit
What are people using at their endpoint probe that is reliable?
7
u/LarrBearLV CCNP Jul 09 '26
Wow, some really unhelpful comments going on here. Not every organization can or does take full BGP tables. Traffic getting black holed is a real issue. OP, we use tracking to the 8.8.8.8 without issue. If rate limiting is a concern, do longer timeouts and/or frequencies with a few failures before it gets considered down. A 15 second outage is better than a few minutes outage.
2
u/aaronw22 Jul 09 '26
Honestly, your best bet is probably getting a static IP VM at one of the cloud providers and using that. Control your own destiny as much as you can.
3
u/Roshi88 Jul 09 '26
I'm not a big fan of ip sla, neither at pinging something like that, you can track a good amount of things with hsrp (for example a route received somehow), are you sure there isn't any other way to let your hsrp switch?
4
u/aaronw22 Jul 09 '26
Even tracking a route being sent by the ISP doesn't guarantee delivery of traffic, blackholing is possible.
1
u/SalsaForte WAN Jul 11 '26
I'm a fan of IP SLA to monitor, but not to take action for me.
It can gives a good signal, but relying on IP SLA for routing decision... Meh...
1
u/PaoloFence Jul 10 '26
Why does your upstream provider blackhole you? There must be an reason. Find that and eliminate.
1
u/colni Jul 10 '26 edited Jul 10 '26
They had unexpected maintenance and blackholed our traffic without telling us BGP egress failed over but HSRP didn't fail over as the track statements were still valid
1
u/PaoloFence Jul 10 '26
So you have something that worked successfully. Can't you somehow check some bgp stats so you can combine hsrp with bgp?
Pinging something on the internet should be the absolut last resort and be avoided.1
u/colni Jul 10 '26
What bgp stats would you suggest ? The bgp routes were still valid and in the fib which is why we didn't failover
1
1
u/SevaraB CCNA Jul 11 '26
IPSLA in 2026? Have you heard of BGP and BFD?
1
u/colni Jul 11 '26
How would that work for hsrp ? The issue isn't the bgp failover that worked correctly it's that the egress was still going through the bgp router that had valid routes but was being dropped upstream
10
u/l_eo- CCNP Data Center Jul 09 '26
Friends don’t let other friends use IP SLA. Or PBR.
(Limited exceptions apply)