Configuring an IPv4 PBR Policy with an IPv4 Address as the Next Hop
The following steps configure an IPv4 PBR by setting an IPv4 address as the next hop in the route map. This task uses Access Control Lists (ACLs), which are explained in greater detail in the RUCKUS FastIron Security Configuration Guide for your platform.
- Enter the
configure terminalcommand to enter global configuration mode. - Define the required IPv4 ACLs to be added to the route map.
- Enter the
route-mapcommand to define the route and specify the match criteria and the resulting action if all the match clauses are met. - Add IPv4 ACLs to match the IP address that is permitted by the ACL.
- Set the IPv4 address of the next hop to which the traffic that matches a match statement
in the route map must be routed.
device(config-routemap test-route)# set ip next-hop 192.168.3.1
Note: If the IP address used in this command is the IP address of a configured IPsec or GRE tunnel, the configuration will choose IPsec or GRE tunnel interface 192.168.3.1 as the next-hop address for matching packets. If you want to set the next hop using a GRE tunnel or IPsec tunnel, use theset next-hop-ip-tunnelcommand.Optionally, the route map can be configured to forward the packet to the neighbor router without decrementing the Time-to-Live (TTL) value in the packet header for the traffic matched by the policy using the no-ttl-decrement option.By default, the TTL value in the packet header is decremented (decreased) for routed traffic and the packet will be discarded when the TTL is exhausted. TTL functions as a hop count limit and every routing hop decrements the TTL value by one. When the TTL value becomes zero, the packet is discarded to prevent routing loops. The no-ttl-decrement option in theset ip next-hopcommand disables the TTL decrement and the packets will be forwarded without decrementing TTL for the traffic matched by the policy. - Enter the
exitcommand to return to global configuration mode. - Enable PBR by applying the route map globally or on an untagged interface or virtual
interface.
- Enable IPv4 PBR globally to apply the route map to all interfaces.
device(config)# ip policy route-map test-route
- Enable IPv4 PBR locally by applying the route map on an interface.
device(config)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# ip policy route-map test-route
- Enable IPv4 PBR globally to apply the route map to all interfaces.
The following example shows the configuration steps to configure an IPv4 PBR policy by setting an IPv4 address as the next hop in the route map.
device# configure terminal device(config)# ip access-list standard 99 device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255 device(config-std-ipacl-99)# exit device(config)# route-map test-route permit 99 device(config-routemap test-route)# match ip address 99 device(config-routemap test-route)# set ip next-hop 192.168.3.1 device(config-routemap test-route)# exit device(config)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# ip policy route-map test-route device(config-if-e1000-1/1/3)# end
The following example shows the configuration steps to configure an IPv4 PBR policy in which the route map is configured to forward the packet without decrementing the Time-to-Live (TTL) value in the packet header.
device(config)# ip access-list standard 99 device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255 device(config-std-ipacl-99)# exit device(config)# route-map test-route permit 99 device(config-routemap test-route)# match ip address 99 device(config-routemap test-route)# set ip next-hop 192.168.3.1 no-ttl-decrement device(config-routemap test-route)# exit device(config)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# ip policy route-map test-route device(config-if-e1000-1/1/3)# end