- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-23-2012 02:11 PM
Thinking outloud here...
I would like to record voice traffic for VPN connected customer service agents.
Traffic comes in a VPN-HomeRouters tunnel from a 10. IP range.
The PBF works when setting source Zone and IP, Next Hop and 1 destination IP.
When i change the IP to a range then the forwarding gets skipped (i'm thinking because of the Virtual Router static route)
So i'm wondering if skipping the PBF altogether in a favor of a second Virtual router will do the trick.
The second VR would include the tunnel interface and e1/5 (my desired egress interface into the LAN) and have static routes matching that of the Main VR.
Bottom line I need VPN traffic to egress e1/5 in order to hit a spanned port.
Any voices in my head would be most welcome!
gary
12-13-2012 12:54 AM
Hi Gary,
I couldn't understand the exact scenario ;however I would like to mention few points...
- PBF would work well for a single destination IP,Group of IPs or a subnet
- PBF got priority over the VR static routes (if it is applicable to source and destination zones)and PBF works from top to bottom.Please check
if you have any PBF on the top that overwirtes your PBF
- If you dont have an IP for tunnel interface and if you are trying to do a PBF with next hop as the tunnel interface,the forwarding decicion
wouldn't work . You should have tunnel interface with an IP address to make forwarding decision with PBF.
Else what you can do is -make tunnel interface unnumbered ,then make PBF as no forwarding and then add a static route in the VR
Hope this helps ...
thanks,Nikhil
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!