Step 1 – define an ACL

Keep in mind that whatever is permitted by this ACL is what will be matched.
You don’t want to permit everything. Usually, I take advantage of the implicit deny at the bottom of the ACL
and just create an ACL that permits what I am going to take action on in the route-map.

So, just create a simple ACL:

Router(config)# ip access-list extended FROM_PRIVATE
Router(config-ext-nacl)# permit ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255

Step 2 – create a route-map

To create a route-map, go into route-map configuration mode, like this:

Router(config)# route-map reroute permit 10

Next, set your match policy to match the traffic in ACL REMOTEVPN, like this :
This will match all the traffic permitted through ACL REMOTEVPN.

Router(config-route-map)# match ip address FROM_PRIVATE

Next, you need to set some action on that traffic. What do you want to happen to that traffic?
Let’s tell the router to send it out interface Fast Ethernet 3/0, like this:

Router(config-route-map)# set interface FastEthernet0/0

!

This will match any IP from the major private networks, and will process them like normal
(The route map will not process
20 if it matches 10). The next map changes the next hop to 192.168.1.6
if it didn’t match the private IPs; in other words, if it’s a publicip, send it to 192.168.1.6

Router(config)# route-map reroute permit 20
description INTERNET_BOUND_TRAFFIC_TO_ISA_SERVER
set ip next-hop
192.168.1.6

Step 3 – Apply the route-map to the interface

Next, you need to apply this policy/route-map to the interface where the traffic is coming in.

Router(config)# interface Fast Ethernet 3/0
Router(config-if)# ip policy route-map reroute


According to the official Cisco Policy Routing documentation,
“One interface can have a only one route map policy applied“.tag; but you can have
several route map entries, each with its own sequence number.

Entries are evaluated in order of their sequence numbers until the first match occurs. If no match occurs,
packets are routed as usual
.”

Now exit and you are done!
You can view your route-maps with show route-map.

Config in Place :

Router(config)# ip access-list extended FROM_PRIVATE
Router(config-ext-nacl)# permit ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255
!
Router(config)# route-map reroute_remotevpn permit 10
Router(config-route-map)# match ip address FROM_PRIVATE
Router(config-route-map)# set interface fastethernet0/0
!
!

Router(config)# route-map reroute permit 20
Router(config-route-map)# description INTERNET_BOUND_TRAFFIC_TO_ISA_SERVER
Router(config-route-map)# set ip next-hop
192.168.1.6

!
Router(config)# interface Fa0/1
Router(config-if)#
ip policy route-map reroute

Static Routes in place :

ip route 0.0.0.0 0.0.0.0 192.168.1.6
ip route 80.74.16.8 255.255.255.248 81.134.196.177
ip route 80.74.16.240 255.255.255.255 81.134.196.177
ip route 80.74.17.9 255.255.255.255 81.134.196.177

***************************************************************************************

Because it’s using route maps, and ACLs, you can create some complex rules, for example :

ip access-list extended FROM-PRIVATE
permit ip 10.0.0.0 0.255.255.255  any
permit ip 172.16.0.0 0.0.15.255  any
permit ip 192.168.0.0 0.0.255.255  any

!
route-map Modify-Default permit 5
description “Match Private IPs“
match ip address FROM-PRIVATE

!
route-map Modify-Default permit 10
description “Match all public IPs“
set ip next-hop 100.100.100.1


This will match any IP from the three major private networks, and will process them like normal
(
The route map will not process 10 if it matches 5).  The next map changes the next hop to 100.100.100.1
if it didn’t match the private IPs; in other words, if it’s a publicip, send it to 100.100.100.1.

***************************************************************************************