Networking-Blog

My WordPress Blog

ROUTE-MAP RE-ROUTE TRAFFIC

ip access-list extended REROUTE1
permit ip any 85.234.86.0 0.0.0.255
!
!
ip access-list extended REROUTE2
permit ip any 85.234.86.0 0.0.0.255
!
!
route-map Alternative_route permit 20
match ip address REROUTE1
set interface Dialer0
!
route-map Alternative_route permit 30
match ip address REROUTE2
set metric 200
set default interface Vlan1
!
!
int vlan 1
ip policy route-map Alternative_route
!
!
ip route 0.0.0.0 0.0.0.0 192.168.0.222
ip route 80.74.16.0 255.255.255.0 Dialer0
ip route 80.74.17.9 255.255.255.255 Dialer0

ROUTE-MAP RE-ROUTE NAT TRAFFIC..

ip nat inside source route-map wireless interface fastethernet0/0 overload
ip nat inside source route-map t1 interface fastethernet0/1 overload

!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 2 permit 192.168.1.0 0.0.0.255

!
route-map wireless permit 10
match ip address 1
match interface fastethernet0/0

!
route-map t1 permit 10
match ip address 2
match interface fastethernet0/1

!
ip route 0.0.0.0 0.0.0.0 1.1.1.1
ip route 0.0.0.0 0.0.0.0 2.2.2.1 20

CISCO Policy based Routing (PBR) : route-map & co.

Route-map can be used in a lot of application, in most of them, the aim is enabling the network engineer
to override the route table and influence which way traffic flows.

Below you will find a configuration sample of Policy Based Routing (PBR) we use to route different
subnet through different equipments.

!

!
!
!
!
!
!
!
!
!

We’ll route :

– Packets from 10.20.10.0/24 (vlan 10) to 172.20.10.0/24 thru Link 2
– Packets from 10.20.20.0/24 (vlan 20) to 172.20.10.0/24 thru Link 1
– Other Packets thru gateway 10.20.5.254 on Gigabit Ethernet interface 3/48

Policy based routing in Cisco Routers can be performed by using “route-map” and then applying as a
policy to the interface of the IP Packets.

The route-map has a list of “match” and “set” commands where match defines the criteria under which the
policy routing is performed (standard or Extended ACL) and set defines the actions to perform when match
criteris met (i.e., set next hop)
.

I change the routing to a particular network only from a particular subnet which is defined
in a standard ACL. This ACL is then matched in a route-map and applied as an IP policy for
routing change for the change in routing behaviour.

First Step create ACLs :

BraveHeart-R-C#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
BraveHeart-R-C(config)# access-list 100 permit ip 10.20.10.0 0.255.255.255 172.20.10.0 0.255.255.255
BraveHeart-R-C(config)# access-list 101 permit ip 10.20.20.0 0.255.255.255 172.20.10.0 0.255.255.255
BraveHeart-R-C(config)# access-list 102 permit ip 10.20.10.0 0.255.255.255 any
BraveHeart-R-C(config)# access-list 102 permit ip 10.20.20.0 0.255.255.255 any

The access list id doesn’t matter for the matching order.

Second Step create route-map :

We will create a route map named Global-route map.
The matching order is the id number of the route map 9->10->11

BraveHeart-R-C#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
BraveHeart-R-C(config)# route-map Sample-routemap permit 9
BraveHeart-R-C(config-route-map)# match ip address 101
BraveHeart-R-C(config-route-map)# set ip next-hop 10.20.6.1
BraveHeart-R-C(config)# route-map Sample-routemap permit 10
BraveHeart-R-C(config-route-map)#  match ip address 100
BraveHeart-R-C(config-route-map)#  set ip next-hop 10.20.7.1
BraveHeart-R-C(config)# route-map Sample-routemap permit 11
BraveHeart-R-C(config-route-map)#  match ip address 102
BraveHeart-R-C(config-route-map)# set default interface GigabitEthernet 3/48

That creates a route-map called “Sample-routemap” and matches the ACLs 100,101,102 where the
source network for which the route-map should be actioned.

Apply Policy Route-map to interface

This route-map is now applied to the interface vlan 10 and 20.

BraveHeart-R-C#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
BraveHeart-R-C(config)#int vlan 10
BraveHeart-R-C(config-if)# ip policy route-map Sample-routemap
BraveHeart-R-C(config-if)#exit
!
BraveHeart-R-C(config)#int vlan 20
BraveHeart-R-C(config-if)# ip policy route-map Sample-routemap
BraveHeart-R-C(config-if)#end

Now all rules configured should work (use traceroute to check the link you use ;-)

Route-Map NaTing

ip nat inside source route-map nonat interface GigabitEthernet0/1 overload
!
route-map nonat permit 12
match ip address NONAT
!
!
ip access-list extended NONAT
deny   ip 10.10.10.0 0.0.0.255 10.10.11.0 0.0.0.255 (deny NaTing across the link via ipsec vpn)
permit ip 10.10.10.0 0.0.0.255 any