Hi Ivan_B, thank you for your reply.
I received now the switch and, after changing the layout and the vlan, I am trying to configure the PBRs.
But unfortunately doesn't work. It seems that acl are ignored.
This is my configuration:
UPE 5130 EI 24 SFP with firmware: 7.1.070 Release 3506P06
default internet gateway: 192.168.178.1
Secondary internet gateway: 192.168.178.2
VLAN10: 192.168.178.0/24 -> is the subnet where I put the two internet gateway
VLAN20: 10.0.12.0/24 -> subnet with normal client that use the default internet gateway (192.168.178.1)
VLAN30: 10.0.13.0./24 -> subnet with client that need to used the secondary internet gateway (192.168.178.2)
VLAN40: 10.0.14.0/24 -> subnet with server that use the default internet gateway (192.168.178.1)
I need the intervlan routing.
I have defined the static route for all internet traffic 0.0.0.0/0.0.0.0 -> next hop 192.168.178.1
for the PBR of VLAN30 I wrote the following ACL and PBR.
access-list advanced 3332
rule 10 permit ip destination 10.0.0.0 0.255.255.255
rule 20 permit ip destination 192.168.0.0 0.0.255.255
#
access-list advanced 3333
rule 10 permit ip
#
policy-based-route VLAN30 deny node 10
if-match acl 3332
#
policy-based-route VLAN30 permit node 20
if-match acl 3333
apply next-hop 192.168.178.2
#
interface Vlan-interface30
ip policy-based-route VLAN30
What i expect with this configuration:
- Clients/servers on VLAN10, VLAN20, VLAN40 use the defaul internet gateway (192.168.18.1) defined on the static route.
- Clients on VLAN30 that need to reach another VLAN (interVLAN routing) can do so thanks to VLAN30 deny node 10 when ACL3332 as matched.
- Internet traffic from VLAN30 is routed through the secondary internet gateway (192.168.178.2), thanks to VLAN30 permit node 20 and next hop.
how it works instead:
- All vlan use the default gateway for internet traffic
- Intervlan routing is ok
- If I connect the PC to the vlan 30, the traffic still exits on the default gateway, not with secondary GW
Where is the error?
The PBR has priority over static route, right ?
<CORE>display ip policy-based-route policy VLAN30
Policy name: VLAN30
node 10 deny:
if-match acl 3332
node 20 permit:
if-match acl 3333
apply next-hop 192.168.178.2
<CORE>dis ip policy-based-route setup
Policy name Type Interface
VLAN30 Forward Vlan-interface30
<CORE>display ip policy-based-route interface Vlan-interface 30 slot 1
Policy-based routing information for interface Vlan-interface30:
Policy name: VLAN30
node 10 deny:
if-match acl 3332
Matched: 0
node 20 permit:
if-match acl 3333
apply next-hop 192.168.178.2
Matched: 0
Total matched: 0
<CORE>display ip policy-based-route local slot 1
Local policy-based routing is not enabled.
Thank you
Best regards
Luca
#pbr