Cisco Support Community
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

GRE on 7606 and policy based routing

We have 3, 7606's with sup 720: A - B - C

We have connections from C to A and also from C to B to A.

C: has vpn blade

B: has fwsm

A: has only sup720 and switchports

The traffic, from C to A is in GRE tunnel

It appears that C can't do policy based routing from C to A works from C to B. Traffic from C to A is in GRE. It appears that traffic is encapsulated before policy based routing is can't make a decision based on ips in tunnel because of GRE.

Is there a way to make the policy decide something before traffic is encapsulated?

Cisco says policy based routing on this won't work. It will work on 7206 with GRE, but if it is coming from 7606 with GRE it won't work.

Can anyone provide details?



Re: GRE on 7606 and policy based routing

Yes policy based routing on this won't work. As to class based queuing on the 7600 with tunnel interface, the only thing

different is on the tunnel itself you configure

ip qos pre-classify ( on the tunnel interface )

apply the policy-map on the physical interface the tunnel traverses.

CreatePlease to create content