Policy Based Routing on Cisco L3 Switch 3550 with IOS 12.1(22)

Policy Based Routing on Cisco L3 Switch 3550 with IOS 12.1(22)

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Policy Based Routing on Cisco L3 Switch 3550 with IOS 12.1(22) Al 04-30-2008
Posted by Al on April 30, 2008, 11:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,

I have a 3550 L3 switch and I am trying to implement policy based
routing. My setup is as follows:

PC1
|
|
|
Switch 3550------- Appliance 1
| \
| \
| \
Firewall1 Firewall 2
| |
| |
VPN 1 VPN 2
| |
| |
|__Firewall 3__|
|
|
|
PC3


Currently, the switch sends all traffic bound for PC2 through Firewall
1

I want traffic from Appliance 1 going to PC2 to pass through Firewall
2 instead.

To do this, I went into the Switch config and added the following:

access-list 123 permit ip y.y.y.y 0.0.0.255 x.x.x.x 0.0.0.255
route-map test_map permit 10
match ip address 123
set ip next-hop 192.168.0.1 (IP of inside interface of Firewall 2)
int vlan1
ip policy route-map test_map

As far as I can tell, It's set up according to examples in Cisco
documentation, but doesn't work. Can anyone see something I missed?

Thanks.

Al

home networking made easy, greater protection, less stress, introducing nm 5.0, 728x90
Posted by on April 30, 2008, 12:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi all,
>
> I have a 3550 L3 switch and I am trying to implement policy based
> routing. My setup is as follows:
>
> =A0 =A0 =A0 =A0 PC1
> =A0 =A0 =A0 =A0 =A0 |
> =A0 =A0 =A0 =A0 =A0 |
> =A0 =A0 =A0 =A0 =A0 |
> =A0Switch 3550------- Appliance 1
> =A0 =A0| =A0 =A0 =A0 =A0 =A0 =A0 =A0\
> =A0 =A0| =A0 =A0 =A0 =A0 =A0 =A0 =A0 \
> =A0 =A0| =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0\
> Firewall1 =A0 =A0 =A0 =A0Firewall 2
> =A0 =A0 | =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 |
> =A0 =A0 | =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 |
> =A0VPN 1 =A0 =A0 =A0 =A0 =A0 =A0VPN 2
> =A0 =A0 | =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 |
> =A0 =A0 | =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 |
> =A0 =A0 |__Firewall 3__|
> =A0 =A0 =A0 =A0 =A0 =A0 =A0|
> =A0 =A0 =A0 =A0 =A0 =A0 =A0|
> =A0 =A0 =A0 =A0 =A0 =A0 =A0|
> =A0 =A0 =A0 =A0 =A0 PC3
>
> Currently, the switch sends all traffic bound for PC2 through Firewall
> 1
>
> I want traffic from Appliance 1 going to PC2 to pass through Firewall
> 2 instead.
>
> To do this, I went into the Switch config and added the following:
>
> access-list 123 permit ip y.y.y.y 0.0.0.255 x.x.x.x 0.0.0.255
> route-map test_map permit 10
> =A0 match ip address 123
> =A0 set ip next-hop 192.168.0.1 (IP of inside interface of Firewall 2)
> int vlan1
> ip policy route-map test_map
>
> As far as I can tell, It's set up according to examples in Cisco
> documentation, but doesn't work. Can anyone see something I missed?

http://www.cisco.com/en/US/tech/tk364/technologies_configuration_example0918=
6a00802135d3.shtml
Policy Routing with Catalyst 3550 Series Switch Configuration Example

"You must modify the SDM template, such that it supports the 144-bit
Layer 3 TCAM"

Get that bit?




Posted by Al on May 1, 2008, 12:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I performed this step at the very beginning... After logging into the
switch I entered the command:

sdm prefered routing

I then rebooted the switch. Once the switch reloaded, I entered the
Access-list, route-maps, etc. When I do a show sdm prefered, the IOS
confirms the current template is the Routing Template.

Al.

Similar ThreadsPosted
Policy Based Routing April 6, 2005, 9:20 am
PIX 7.0 policy based routing? October 24, 2005, 10:27 pm
policy based routing November 4, 2005, 2:14 am
Policy based routing on a ASA February 2, 2007, 5:03 pm
PIX 525, I think I need Policy-based routing?? April 23, 2007, 9:45 pm
Policy based routing April 30, 2008, 11:30 am
Policy Based Routing and/or NAT May 7, 2008, 8:15 am
policy based routing problem March 22, 2005, 11:03 am
HSRP and Policy based Routing October 26, 2005, 9:12 pm
Policy Based Routing Question November 13, 2005, 7:38 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map