Configuring an IPv6 PBR Policy with a Tunnel as the Next Hop

Traffic can be configured to route IPv6 packets over an IPsec tunnel or GRE tunnel using PBR. The following steps configure an IPsec or GRE tunnel interface as the next hop of a PBR route map.

You must configure the IPsec tunnel or GRE tunnel before configuring the traffic to route over a tunnel. For more information about IPsec tunnel configuration, refer to the Routing Traffic over an IPsec Tunnel Using PBR task. For more information about GRE tunnel configuration, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Define the required IPv6 ACLs to be added to the route map.
    device(config)# ipv6 access-list acl99 
    device(config-ipv6-access-list-acl99)# permit ipv6 2001:DB8:90::22/64 any
    device(config-ipv6-access-list-acl99)# exit
  3. Enter the route-map command to define the route and specify the match criteria and the resulting action if all the match clauses are met.
    device(config# route-map tunnel-route permit acl99
  4. Add IPv6 ACLs to match the IP address that is permitted by the ACL.
    device(config-routemap tunnel-route)# match ipv6 address acl99
  5. Set the configured tunnel as the next hop for a route map.
    device(config-routemap tunnel-route)# set next-hop-ipv6-tunnel 1
  6. Enter the end command to return to global configuration mode.
    device(config-routemap tunnel-route)# end
  7. Enter configuration mode on the interface where you want to enable the IPv6 PBR policy by applying the route map.
    device(config)# interface ethernet 1/1/3
    The IPv6 PBR policy can be enabled globally when the route map is applied to all interfaces using the ipv6 policy route-map command from global configuration mode.
  8. Enable PBR on the interface and specify the route map to be used.
    device(config-if-e1000-1/1/3)# ipv6 policy route-map tunnel-route

The following example shows the configuration steps to forward IPv6 routing traffic over an IPsec tunnel using PBR. The initial VRF and IPsec tunnel configuration is included to give a complete example.

device(config)# interface tunnel 1
device(config-tnif-1)# vrf forwarding marketing
device(config-tnif-1)# tunnel source ethernet 1/1/1
device(config-tnif-1)# tunnel destination 2001:DB8:2::1
device(config-tnif-1)# tunnel mode ipsec ipv6
device(config-tnif-1)# tunnel protection ipsec profile prof-blue
device(config-tnif-1)# ipv6 address 2001:DB8:4::/64
device(config-tnif-1)# exit
device(config)# ipv6 access-list acl99 
device(config-ipv6-access-list-acl99)# permit ipv6 2001:DB8:90::22/64 any
device(config-ipv6-access-list-acl99)# exit
device(config)# route-map tunnel-route permit acl99
device(config-routemap tunnel-route)# match ipv6 address acl99
device(config-routemap tunnel-route)# set next-hop-ipv6-tunnel 1
device(config-routemap tunnel-route)# end
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# vrf forwarding marketing
device(config-if-e1000-1/1/3)# ipv6 policy route-map tunnel-route
device(config-if-e1000-1/1/3)# end