Configuring an IPv4 PBR Policy with an IPv4 Address as the Next Hop

The following steps configure an IPv4 PBR by setting an IPv4 address as the next hop in the route map. This task uses Access Control Lists (ACLs), which are explained in greater detail in the RUCKUS FastIron Security Configuration Guide for your platform.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Define the required IPv4 ACLs to be added to the route map.
    device(config)# ip access-list standard 99 
    device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
    device(config-std-ipacl-99)# exit
  3. Enter the route-map command to define the route and specify the match criteria and the resulting action if all the match clauses are met.
    device(config)# route-map test-route permit 99
  4. Add IPv4 ACLs to match the IP address that is permitted by the ACL.
    device(config-routemap test-route)# match ip address 99
  5. Set the IPv4 address of the next hop to which the traffic that matches a match statement in the route map must be routed.
    device(config-routemap test-route)# set ip next-hop 192.168.3.1
    Note: If the IP address used in this command is the IP address of a configured IPsec or GRE tunnel, the configuration will choose IPsec or GRE tunnel interface 192.168.3.1 as the next-hop address for matching packets. If you want to set the next hop using a GRE tunnel or IPsec tunnel, use the set next-hop-ip-tunnel command.
    Optionally, the route map can be configured to forward the packet to the neighbor router without decrementing the Time-to-Live (TTL) value in the packet header for the traffic matched by the policy using the no-ttl-decrement option.
    By default, the TTL value in the packet header is decremented (decreased) for routed traffic and the packet will be discarded when the TTL is exhausted. TTL functions as a hop count limit and every routing hop decrements the TTL value by one. When the TTL value becomes zero, the packet is discarded to prevent routing loops. The no-ttl-decrement option in the set ip next-hop command disables the TTL decrement and the packets will be forwarded without decrementing TTL for the traffic matched by the policy.
  6. Enter the exit command to return to global configuration mode.
    device(config-routemap test-route)# exit
  7. Enable PBR by applying the route map globally or on an untagged interface or virtual interface.
    • Enable IPv4 PBR globally to apply the route map to all interfaces.
      device(config)# ip policy route-map test-route
    • Enable IPv4 PBR locally by applying the route map on an interface.
      device(config)# interface ethernet 1/1/3
      device(config-if-e1000-1/1/3)# ip policy route-map test-route
    • Enable IPv4 PBR locally by applying the route map on a virtual interface.
      device(config)# interface ve 1
      device(config-vif-1)# ip policy route-map test-route

The following example shows the configuration steps to configure an IPv4 PBR policy by setting an IPv4 address as the next hop in the route map.

device# configure terminal
device(config)# ip access-list standard 99 
device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
device(config-std-ipacl-99)# exit
device(config)# route-map test-route permit 99
device(config-routemap test-route)# match ip address 99
device(config-routemap test-route)# set ip next-hop 192.168.3.1
device(config-routemap test-route)# exit
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# ip policy route-map test-route
device(config-if-e1000-1/1/3)# end

The following example shows the configuration steps to configure an IPv4 PBR policy in which the route map is configured to forward the packet without decrementing the Time-to-Live (TTL) value in the packet header.

device(config)# ip access-list standard 99 
device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
device(config-std-ipacl-99)# exit
device(config)# route-map test-route permit 99
device(config-routemap test-route)# match ip address 99
device(config-routemap test-route)# set ip next-hop 192.168.3.1 no-ttl-decrement
device(config-routemap test-route)# exit
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# ip policy route-map test-route
device(config-if-e1000-1/1/3)# end