Configuring an IPv4 PBR Policy with the NULL0 Interface as the Next Hop

The following steps configure an IPv4 PBR policy by setting the NULL0 interface as the next hop in the route map.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Define the required IPv4 ACLs to be added to the route map.
    device(config)# ip access-list standard 99 
    device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
    device(config-std-ipacl-99)# exit
  3. Enter the route-map command to define the route and specify the match criteria and the resulting action if all the match clauses are met.
    device(config)# route-map test-route permit 99
  4. Add IPv4 ACLs to match the IP address that is permitted by the ACL.
    device(config-routemap test-route)# match ip address 99
  5. Set the next hop as NULL0 interface to send the traffic to the null interface, thus dropping the packet instead of forwarding it.
    device(config-routemap test-route)# set interface null0
  6. Enter the exit command to return to global configuration mode.
    device(config-routemap test-route)# exit
  7. Enter configuration mode on the interface where you want to enable PBR by applying the route map.
    device(config)# interface ethernet 1/1/3
    PBR can be enabled globally by which the route map is applied to all interfaces using the ip policy route-map command from the global configuration mode.
  8. Enable PBR on the interface and specify the route map to be used.
    device(config-if-e1000-1/1/3)# ip policy route-map test-route

The following example shows the configuration steps to configure an IPv4 PBR policy to send all traffic from 10.157.23.0 0.0.0.255 to the NULL0 interface, thus dropping the traffic instead of forwarding it.

device# configure terminal
device(config)# ip access-list standard 99 
device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255
device(config-std-ipacl-99)# exit
device(config)# route-map test-route permit 99
device(config-routemap test-route)# match ip address 99
device(config-routemap test-route)# set interface null0
device(config-routemap test-route)# exit
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# ip policy route-map test-route
device(config-if-e1000-1/1/3)# end