12-23-2011 02:16 AM - edited 03-04-2019 02:43 PM
Could you please clarify whether the PBR is expected to work for the below scenario
Below SVI’s are present in the switch
Vlan 10 , vlan 20 , vlan 30 , vlan 40 , vlan 100
Vlan 10 , 20 , 30 , 40 -- different client vlans
Vlan 100 - firewall vlan
Default route in switch point towards the firewall ip address in Vlan 100.
We want to direct specific traffic from all the client vlans to go via a GRE Tunnel interface which exist on the switch.
Since the destination address is not known , all the client traffic to the specific destination takes the default route towards firewall .
PBR is configured to match the traffic towards this destination and set the next hop as Tunnel interface . The PBR is configured on the Vlan 100 and found to be - NOT – Working. Could you please help us understand whether this is the expected behavior or not with the explanation.
Platform is 6509 .
Kindly let us know if you need any clarification regarding the same.
Thanks & Regards,
Akhil
Solved! Go to Solution.
01-03-2012 04:08 AM
Hi Akhil,
What is the current status of thiw query.
Please rate the helpfull posts if anything helped you.
Please rate the helpfull posts.
Regards,
Naidu.
12-23-2011 04:01 AM
Hi Akhil,
What I understand is...
You have few vlans on 6509
Vlan 100 is facing internet
All unknown traffic from other vlans going to vlan100 -->firewall vlan
Now you want to redirect some traffic through GRE tunnel for which you have used PBR (set ip default next-hop vlan100)
Is that above correct.
My question is what is the purpose of configuring pbr at vlan100? as it is facing internet as gateway for all your local LAN vlans. I think you no need to configure PBR at vlan100.
What you are looking to achieve?
Could you please clarify us here....
Please rate the helpfull posts.
Regards,
Naidu.
12-23-2011 06:18 AM
Yes , we have a few VLANS , in fact close to 300 layer 3 VLANs.
We need to redirect the traffic from all these VLANS going to a specific destination ( for which we don’t have a specific route) to the GRE tunnel. We have two options here , either configure the specific PBR under all these VLANs or configure the PBR on the firewall VLAN where the traffic will be hitting since the default route is pointed towards the firewall.
Kindly let us know whether this makes sense ?
Regards
Akhil
12-23-2011 06:20 AM
Yes , we have a few VLANS , in fact close to 300 layer 3 VLANs.
We need to redirect the traffic from all these VLANS going to a specific destination ( for which we don’t have a specific route) to the GRE tunnel. We have two options here , either configure the specific PBR under all these VLANs or configure the PBR on the firewall VLAN where the traffic will be hitting since the default route is pointed towards the firewall.
Kindly let us know whether this makes sense ?
12-23-2011 08:05 AM
Instead of using 'set interface', use 'set ip next-hop' and the IP address of the remote tunnel interface.
Also, verify the remote IP address is reachable from this 6500.
Regards,
Edison
12-23-2011 10:04 PM
it's worth remember that:
– The PFC does not provides hardware support for PBR configured with the set ip next-hop keywords if the next hop is a tunnel interface.
Riccardo
12-24-2011 09:57 AM
Riccardo,
Good point - I forgot to check those caveats...
12-24-2011 11:22 AM
Hi,
The question here is whether the PBR will work or not for the mentioned scenario and not whether it is hardware switched or software switched !
Regards
Akhil
12-24-2011 04:06 PM
Hi Akhil P Jose,
well... if you say that it is not working I take it for granted that it does not work.
Regarding the fact whether this is supposed to be working or not I have the impression that you did not do your homeworks on PBR requirements in general.
Latchum put you on the right track but it is not clear if you followed his advise.
Since your destination is not known you gotta use 'set ip default next-hop' since:
"The set ip default next-hop command verifies the existence of the destination IP address in the routing table, and…
The set ip next-hop command verifies the existence of the next hop specified, and…
http://www.cisco.com/en/US/tech/tk364/technologies_configuration_example09186a00801f3b54.shtml
You are in the second bullet of the first scenario, hence you have to use set ip defaul next-hop. Have you tried that?
After you configure it you have to check the tcam programming for the interface where you applied the PBR
show tcam interface vlan 100 acl in ip
and
show tcam interface vlan 100 acl in ip detail
You should see see your acl there with the 'punt' operator (or the 'redirect' operator if you have copp on) since, as we said, your configuration is not supported in hardware.
Let me add that since you are handling a platform that is designed to switch traffic in hardware the fact that your configuration forces it to software switch the traffic is not a mere detail as you are implying from the previous post.
Having a PBR on a 6500 configured in software is extremely risky and I would not do it; but if this is your choice even though your are aware of the risks your are taking I will not comment on it further. Just be ready to open a TAC case as soon as the CPU jumps to the sky and you see lots of drops incase of high volume traffic going through that PBR
Riccardo
12-25-2011 11:17 PM
Hi Akhil,
From the above posts and your argue, I understand this..
You have default route from all vlans pointed to vlan100, is this correct?
You have a GRE tunnel configured in the 6509.
Now you want send some specific traffic (You knows the destination) through GRE tunnel interface, is this correct?
So configuring PBR under all vlans will he tuff and what about the unknown traffic if you apply the PBR to vlan interface?
I am presuming your GRE tunnel configured on your 6509, is this correct?
Here what I would suggest is define a PBR (Note: you knows the destination traffic .... permit ip 192.168.2.0 0.0.0.255 10.10.10.0 0.0.0.255) and apply to the interface (vlan100) whcih currently routing the default route.
Let me know if you have any question on above also update.
Please rate the helpfull posts.
Regards,
Naidu.
01-03-2012 04:08 AM
Hi Akhil,
What is the current status of thiw query.
Please rate the helpfull posts if anything helped you.
Please rate the helpfull posts.
Regards,
Naidu.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide