Configuring an IPv6 PBR Policy with a Tunnel as the Next Hop
Traffic can be configured to route IPv6 packets over an IPsec tunnel or GRE tunnel using PBR. The following steps configure an IPsec or GRE tunnel interface as the next hop of a PBR route map.
You must configure the IPsec tunnel or GRE tunnel before configuring the traffic to route over a tunnel. For more information about IPsec tunnel configuration, refer to the Routing Traffic over an IPsec Tunnel Using PBR task. For more information about GRE tunnel configuration, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.
- Enter the
configure terminalcommand to enter global configuration mode. - Define the required IPv6 ACLs to be added to the route map.
- Enter the
route-mapcommand to define the route and specify the match criteria and the resulting action if all the match clauses are met. - Add IPv6 ACLs to match the IP address that is permitted by the ACL.
- Set the configured tunnel as the next hop for a route map.
- Enter the
endcommand to return to global configuration mode. - Enter configuration mode on the interface where you want to enable the IPv6 PBR policy by applying the route map.
- Enable PBR on the interface and specify the route map to be used.
The following example shows the configuration steps to forward IPv6 routing traffic over an IPsec tunnel using PBR. The initial VRF and IPsec tunnel configuration is included to give a complete example.
device(config)# interface tunnel 1 device(config-tnif-1)# vrf forwarding marketing device(config-tnif-1)# tunnel source ethernet 1/1/1 device(config-tnif-1)# tunnel destination 2001:DB8:2::1 device(config-tnif-1)# tunnel mode ipsec ipv6 device(config-tnif-1)# tunnel protection ipsec profile prof-blue device(config-tnif-1)# ipv6 address 2001:DB8:4::/64 device(config-tnif-1)# exit device(config)# ipv6 access-list acl99 device(config-ipv6-access-list-acl99)# permit ipv6 2001:DB8:90::22/64 any device(config-ipv6-access-list-acl99)# exit device(config)# route-map tunnel-route permit acl99 device(config-routemap tunnel-route)# match ipv6 address acl99 device(config-routemap tunnel-route)# set next-hop-ipv6-tunnel 1 device(config-routemap tunnel-route)# end device(config)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# vrf forwarding marketing device(config-if-e1000-1/1/3)# ipv6 policy route-map tunnel-route device(config-if-e1000-1/1/3)# end