I have 2 vlan 30 and 32. ip routing is enabled on 3550-24-PWR.
PC 192.168.30.10/24 on vlan 30 can talk to pc 192.168.32.2 /24 on vlan 32
There's a default router 192.168.30.100 on vlan 30 to go to public Internet.
ip route 0.0.0.0 0.0.0.0 192.168.30.100
both pc can go to internet by router 192.168.30.100.
Now vlan 32 users got its own public IP address. Added new router 192.168.32.100.
Now I need to setup the PBR to route internet traffic on vlan 30 by router 192.168.30.100
route internet traffic on vlan 32 by router 192.168.32.100
So I removed default ip route to 192.168.30.100
setup 2 route-maps
access-list 10 permit 192.168.30.0 0.0.0.255
access-list 20 permit 192.168.32.0 0.0.0.255
route-map vlan30 permit 10
match ip address 10
set ip next-hop 192.168.30.100
route-map vlan32 permit 20
match ip address 20
set ip next-hop 192.168.32.100
int vlan 30
ip policy route-map vlan30
int vlan 32
ip policy route-map vlan 32
sdm prefer routing extend-match
It works on the traffic to public internet. But pc 192.168.30.10 failed to ping 192.168.32.2
the inter-vlan routing failed.
I tried to use the command "set ip default next-hop" instead of "set ip next-hop"
I can't apply the route-map to vlan interface.
Got error "route-map vlan30 not supported by policy-based routing"
Can't find any docs about this situation. Please help.
As suggested by Manish try with extended ACL with local lan subnet denied for PBR and rest of the traffic should gow ith PBR,Genrally there command difference between set ip next hop and default next hop is
Set ip next-hop command is put the matching traffic because a switch works on hardware based, The set ip next-hop is working all the time in hardware, because the routing table and process never get checked by the switch. It receives a packet and if that falls into the route-map statements then it is sent directly to the next hop that you specified, without checking the routing table.
Set ip default next-hop command first checks the entire routing table to see if there is another route to the destination. If no route is found, then the default next-hop is used.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...