Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PBR on 6509 and Cisco ASA

Hi all,

I have the following problem..

I have a cisco 6509 switch which 4 networks are connected to it..

the default routed is pointed to our ISP's router. We are using NAT for address translation for these ranges.This works great

I now have a Cisco ASA that I want to deploy. I want the network to go through the ASA to get to the internet. So I have created the following PBR setup..

The IP of the router gateway is

The IP of the ASA is

access-list 172 permit ip any

route-map pix-172-20-200 permit 10

match ip address 172

set ip default next-hop

interface vlan 172

ip address

ip policy route-map pix-172-20-200

This policy map is working fine..

Here is why my problem lies...

I have a server at that I need to get to from outside the network (public IP).

I have made to correct configurations on the ASA.

I created a static mapping from to an external address - (not the real ip)

I allowed the correct ports on the ASA through for these addresses. I have about 7 yrs experience with the Pix Os.

The connection is permitted if I watch the debug logs on the ASA, but I can never get connected to the internal system. I am pretty sure it is related to the PBR on the 6509, but I can't think of a way around it. I only want the addresses going through the ASA, but I also need access to other parts of hte network from the network.


Don Hickey


Re: PBR on 6509 and Cisco ASA

Did you apply the static nat config on the appropriate interface?. I mean is this server connected to the same interface as other 172.20 networks is connected?.

I think the problem might be with the command "access-list 172 permit ip any" in the route map. It is also sending via the default next hop configured. But this alone can't be said as a reason.

Can you send me the debug log you received. Looking at that, I can get some idea.

CreatePlease to create content