Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Policy Based Forwarding only works when using specific IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Policy Based Forwarding only works when using specific IP

Thinking outloud here...

I would like to record voice traffic for VPN connected customer service agents.

Traffic comes in a VPN-HomeRouters tunnel from a 10. IP range.

The PBF works when setting source Zone and IP, Next Hop and 1 destination IP.

When i change the IP to a range then the forwarding gets skipped (i'm thinking because of the Virtual Router static route)

So i'm wondering if skipping the PBF altogether in a favor of a second Virtual router will do the trick.

The second VR would include the tunnel interface and e1/5 (my desired egress interface into the LAN) and have static routes matching that of the Main VR.

Bottom line I need VPN traffic to egress e1/5 in order to hit a spanned port.

Any voices in my head would be most welcome!

gary

1 REPLY 1

Not applicable

Hi Gary,

I couldn't understand the exact scenario ;however I would like to mention few points...

- PBF would work well for a single destination IP,Group of IPs or a subnet

- PBF got priority over the VR static routes (if it is applicable to source and destination zones)and PBF works from top to bottom.Please check 

  if you have any PBF on the top  that overwirtes    your PBF

- If you dont have an IP for tunnel interface and if you are trying to do a PBF with next hop as the tunnel interface,the forwarding decicion

  wouldn't work . You should have tunnel interface with an IP address to make forwarding decision with PBF.

   Else what you can do is -make tunnel interface unnumbered ,then make PBF as no forwarding and then add a static route in the VR

Hope this helps ... Smiley Happy

thanks,Nikhil

  • 2047 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!