Policy Based Routing Issue
Posted: 06 Mar 2011 22:08
Hi,
Below is the Network Logical Diagram of mine existing setup
FW1 (192.168.16.2) <=====> CSW1 <====> ESW1
FW2 (192.168.16.3) <=====> CSW1 <====> ESW1
FW3 (192.168.16.4) <=====> CSW1 <====> ESW1
My Core Switch (CSW1) consist of a few VLANs and I am trying to using Policy Based Routing to divert the different VLAN to their specific FW for traffic to go out.
I had setup a client under the Guest VLAN (192.168.14.0) at the Edge switch (ESW1).
I had setup a client under the Student VLAN (192.168.10.0) at the Edge switch (ESW1).
Before I put in the Policy Based Routing (PBR), pinging to all the gateway on the Core switch is OK
================================================================
ip static-route 0.0.0.0/0 gateway 192.168.15.2 metric 1
================================================================
policy condition StudentVLAN source ip 192.168.10.0 mask 255.255.255.0
policy action toFW2 permanent gateway ip 192.168.15.3
policy rule redirectStud condition StudentVLAN action toFW2
qos apply
================================================================
policy condition WStudentVLAN source ip 192.168.12.0 mask 255.255.255.0
policy action toFW2 permanent gateway ip 192.168.15.3
policy rule redirectWStud condition WStudentVLAN action toFW2
qos apply
================================================================
policy condition GuestVLAN source ip 192.168.14.0 mask 255.255.255.0
policy action toFW3 permanent gateway ip 192.168.15.4
policy rule redirectGuest condition GuestVLAN action toFW3
qos apply
================================================================
After I put in the Policy Based Routing (PBR), did a test ping to own gateway is ok, but to other VLAN interface, there is no respond.
However when I do a tracert, I can reach the destination. Had check on the firewall that traffic had goes to the correct FW pointed to and routed had also been added to point back to the Core Switch.
So is it due to the policy based routing blocking Ping functions or I had miss out something which cause the traffic unable to route back correctly? Below is the configuration on the Core Switch and thank for your reply in advanced.
=============================================================
! Stack Manager :
! Chassis :
system name L3-CSW-01
! Configuration:
! VLAN :
vlan 1 enable name "Disabled"
vlan 2 enable name "Management"
vlan 2 port default 1/24
vlan 2 port default 1/25
vlan 2 port default 1/26
vlan 2 port default 1/27
vlan 2 port default 1/28
vlan 2 port default 1/29
vlan 2 port default 1/30
vlan 2 port default 1/31
vlan 2 port default 1/32
vlan 2 port default 1/33
vlan 2 port default 1/34
vlan 2 port default 1/35
vlan 2 port default 1/36
vlan 2 port default 1/45
vlan 2 port default 2/20
vlan 2 port default 2/25
vlan 2 port default 2/26
vlan 2 port default 2/27
vlan 2 port default 2/28
vlan 2 port default 2/29
vlan 2 port default 2/30
vlan 2 port default 2/31
vlan 2 port default 2/32
vlan 2 port default 2/33
vlan 2 port default 2/34
vlan 2 port default 2/35
vlan 2 port default 2/36
vlan 3 enable name "Wireless Management"
vlan 3 port default 1/22
vlan 4 enable name "Student"
vlan 4 port default 1/18
vlan 5 enable name "Staff"
vlan 5 port default 1/19
vlan 5 port default 1/20
vlan 6 enable name "Wireless Student"
vlan 7 enable name "Wireless Staff"
vlan 8 enable name "Guest"
vlan 9 enable name "Firewall"
vlan 9 port default 1/46
vlan 9 port default 1/47
vlan 9 port default 2/47
vlan 10 enable name "Wireless VIP"
! VLAN SL:
! IP :
ip service all
ip interface "Vlan2" address 192.168.8.1 mask 255.255.255.0 vlan 2 ifindex 2
ip interface "Vlan3" address 192.168.9.1 mask 255.255.255.0 vlan 3 ifindex 3
ip interface "Vlan4" address 192.168.10.1 mask 255.255.255.0 vlan 4 ifindex 4
ip interface "Vlan5" address 192.168.11.1 mask 255.255.255.0 vlan 5 ifindex 5
ip interface "Vlan6" address 192.168.12.1 mask 255.255.255.0 vlan 6 ifindex 6
ip interface "Vlan7" address 192.168.13.1 mask 255.255.255.0 vlan 7 ifindex 7
ip interface "Vlan8" address 192.168.14.1 mask 255.255.255.0 vlan 8 ifindex 8
ip interface "Vlan9" address 192.168.15.1 mask 255.255.255.0 vlan 9 ifindex 9
ip interface "vlan10" address 192.168.16.1 mask 255.255.255.0 vlan 10 ifindex 10
! IPX :
! IPMS :
! AAA :
aaa radius-server "192.168.8.9" host 192.168.8.9 key c9ab906dcb630054cf41331b7f81f42c retransmit 3 timeout 2 auth-port 1812 acct-port 1813
aaa radius-server "192.168.8.11" host 192.168.8.11 key c9ab906dcb630054cf41331b7f81f42c retransmit 3 timeout 2 auth-port 1812 acct-port 1813
aaa authentication default "192.168.8.9"
aaa authentication console "local"
aaa authentication telnet "local"
aaa authentication http "local"
! PARTM :
! AVLAN :
! 802.1x :
! QOS :
policy condition GuestVLAN source ip 192.168.14.0 mask 255.255.255.0
policy condition StudentVLAN source ip 192.168.10.0 mask 255.255.255.0
policy condition WStudentVLAN source ip 192.168.12.0 mask 255.255.255.0
policy action toFW2 permanent gateway ip 192.168.15.3
policy action toFW3 permanent gateway ip 192.168.15.4
policy rule redirectWStud condition WStudentVLAN action toFW2
policy rule redirectStud condition StudentVLAN action toFW2
policy rule redirectGuest condition GuestVLAN action toFW3
qos apply
! Policy manager :
! Session manager :
session prompt default "L3-CSW-01->"
! SNMP :
! RIP :
! OSPF :
! BFD-STD :
! ISIS :
! IPv6 :
! IPSec :
! IP multicast :
ip static-route 0.0.0.0/0 gateway 192.168.15.2 metric 1
! RIPng :
! OSPF3 :
! BGP :
! Health monitor :
! Interface :
! Udld :
! Netsec :
! Link Aggregate :
lacp linkagg 1 size 2 admin state enable
lacp linkagg 1 name "L3-CSW-01 P1/1,2/1 to L1-ESW-01 P1/1,1/2"
lacp linkagg 1 actor admin key 1
lacp linkagg 2 size 2 admin state enable
lacp linkagg 2 actor admin key 2
lacp linkagg 3 size 2 admin state enable
lacp linkagg 3 actor admin key 3
lacp linkagg 4 size 2 admin state enable
lacp linkagg 4 actor admin key 4
lacp linkagg 5 size 2 admin state enable
lacp linkagg 5 actor admin key 5
lacp linkagg 6 size 2 admin state enable
lacp linkagg 6 actor admin key 6
lacp linkagg 7 size 2 admin state enable
lacp linkagg 7 actor admin key 7
lacp linkagg 8 size 2 admin state enable
lacp linkagg 8 actor admin key 8
lacp linkagg 9 size 2 admin state enable
lacp linkagg 9 actor admin key 9
lacp linkagg 10 size 2 admin state enable
lacp linkagg 10 actor admin key 10
lacp linkagg 11 size 2 admin state enable
lacp linkagg 11 actor admin key 11
lacp linkagg 12 size 2 admin state enable
lacp linkagg 12 actor admin key 12
lacp linkagg 13 size 2 admin state enable
lacp linkagg 13 actor admin key 13
lacp linkagg 14 size 2 admin state enable
lacp linkagg 14 actor admin key 14
lacp linkagg 15 size 2 admin state enable
lacp linkagg 15 actor admin key 15
lacp linkagg 16 size 2 admin state enable
lacp linkagg 16 actor admin key 16
lacp linkagg 17 size 2 admin state enable
lacp linkagg 17 actor admin key 17
static linkagg 18 size 2 admin state enable
lacp agg 1/1 actor admin key 1
lacp agg 1/2 actor admin key 2
lacp agg 1/3 actor admin key 3
lacp agg 1/4 actor admin key 4
lacp agg 1/5 actor admin key 5
lacp agg 1/6 actor admin key 6
lacp agg 1/7 actor admin key 7
lacp agg 1/8 actor admin key 8
lacp agg 1/9 actor admin key 9
lacp agg 1/10 actor admin key 10
lacp agg 1/11 actor admin key 11
lacp agg 1/12 actor admin key 12
lacp agg 1/13 actor admin key 13
lacp agg 1/14 actor admin key 14
lacp agg 1/15 actor admin key 15
lacp agg 1/16 actor admin key 16
lacp agg 1/17 actor admin key 17
static agg 1/48 agg num 18
lacp agg 2/1 actor admin key 1
lacp agg 2/2 actor admin key 2
lacp agg 2/3 actor admin key 3
lacp agg 2/4 actor admin key 4
lacp agg 2/5 actor admin key 5
lacp agg 2/6 actor admin key 6
lacp agg 2/7 actor admin key 7
lacp agg 2/8 actor admin key 8
lacp agg 2/9 actor admin key 9
lacp agg 2/10 actor admin key 10
lacp agg 2/11 actor admin key 11
lacp agg 2/12 actor admin key 12
lacp agg 2/13 actor admin key 13
lacp agg 2/14 actor admin key 14
lacp agg 2/15 actor admin key 15
lacp agg 2/16 actor admin key 16
lacp agg 2/17 actor admin key 17
static agg 2/48 agg num 18
! Port Mapping :
! VLAN AGG:
! 802.1Q :
vlan 2 802.1q 2/19 "TAG AGGREGATE 2 VLAN 2"
vlan 3 802.1q 2/19 "TAG AGGREGATE 2 VLAN 3"
vlan 4 802.1q 2/19 "TAG AGGREGATE 2 VLAN 4"
vlan 5 802.1q 2/19 "TAG AGGREGATE 2 VLAN 5"
vlan 6 802.1q 2/19 "TAG AGGREGATE 2 VLAN 6"
vlan 7 802.1q 2/19 "TAG AGGREGATE 2 VLAN 7"
vlan 8 802.1q 2/19 "TAG AGGREGATE 2 VLAN 8"
vlan 9 802.1q 2/19 "TAG AGGREGATE 2 VLAN 9"
vlan 10 802.1q 2/19 "TAG AGGREGATE 2 VLAN 10"
vlan 2 802.1q 1 "TAG AGGREGATE 1 VLAN 2"
vlan 3 802.1q 1 "TAG AGGREGATE 1 VLAN 3"
vlan 4 802.1q 1 "TAG AGGREGATE 1 VLAN 4"
vlan 5 802.1q 1 "TAG AGGREGATE 1 VLAN 5"
vlan 6 802.1q 1 "TAG AGGREGATE 1 VLAN 6"
vlan 7 802.1q 1 "TAG AGGREGATE 1 VLAN 7"
vlan 8 802.1q 1 "TAG AGGREGATE 1 VLAN 8"
vlan 9 802.1q 1 "TAG AGGREGATE 1 VLAN 9"
vlan 10 802.1q 1 "TAG AGGREGATE 1 VLAN 10"
vlan 2 802.1q 2 "TAG AGGREGATE 2 VLAN 2"
vlan 3 802.1q 2 "TAG AGGREGATE 2 VLAN 3"
vlan 4 802.1q 2 "TAG AGGREGATE 2 VLAN 4"
vlan 5 802.1q 2 "TAG AGGREGATE 2 VLAN 5"
vlan 6 802.1q 2 "TAG AGGREGATE 2 VLAN 6"
vlan 7 802.1q 2 "TAG AGGREGATE 2 VLAN 7"
vlan 8 802.1q 2 "TAG AGGREGATE 2 VLAN 8"
vlan 9 802.1q 2 "TAG AGGREGATE 2 VLAN 9"
vlan 10 802.1q 2 "TAG AGGREGATE 2 VLAN 10"
vlan 2 802.1q 3 "TAG AGGREGATE 3 VLAN 2"
vlan 3 802.1q 3 "TAG AGGREGATE 3 VLAN 3"
vlan 4 802.1q 3 "TAG AGGREGATE 3 VLAN 4"
vlan 5 802.1q 3 "TAG AGGREGATE 3 VLAN 5"
vlan 6 802.1q 3 "TAG AGGREGATE 3 VLAN 6"
vlan 7 802.1q 3 "TAG AGGREGATE 3 VLAN 7"
vlan 8 802.1q 3 "TAG AGGREGATE 3 VLAN 8"
vlan 9 802.1q 3 "TAG AGGREGATE 3 VLAN 9"
vlan 10 802.1q 3 "TAG AGGREGATE 3 VLAN 10"
vlan 2 802.1q 4 "TAG AGGREGATE 4 VLAN 2"
vlan 3 802.1q 4 "TAG AGGREGATE 4 VLAN 4"
vlan 4 802.1q 4 "TAG AGGREGATE 4 VLAN 4"
vlan 5 802.1q 4 "TAG AGGREGATE 4 VLAN 5"
vlan 6 802.1q 4 "TAG AGGREGATE 4 VLAN 6"
vlan 7 802.1q 4 "TAG AGGREGATE 4 VLAN 7"
vlan 8 802.1q 4 "TAG AGGREGATE 4 VLAN 8"
vlan 9 802.1q 4 "TAG AGGREGATE 4 VLAN 9"
vlan 10 802.1q 4 "TAG AGGREGATE 4 VLAN 10"
vlan 2 802.1q 5 "TAG AGGREGATE 5 VLAN 2"
vlan 3 802.1q 5 "TAG AGGREGATE 5 VLAN 3"
vlan 4 802.1q 5 "TAG AGGREGATE 5 VLAN 4"
vlan 5 802.1q 5 "TAG AGGREGATE 5 VLAN 5"
vlan 6 802.1q 5 "TAG AGGREGATE 5 VLAN 6"
vlan 7 802.1q 5 "TAG AGGREGATE 5 VLAN 7"
vlan 8 802.1q 5 "TAG AGGREGATE 5 VLAN 8"
vlan 9 802.1q 5 "TAG AGGREGATE 5 VLAN 9"
vlan 10 802.1q 5 "TAG AGGREGATE 5 VLAN 10"
vlan 2 802.1q 6 "TAG AGGREGATE 6 VLAN 2"
vlan 3 802.1q 6 "TAG AGGREGATE 6 VLAN 3"
vlan 4 802.1q 6 "TAG AGGREGATE 6 VLAN 4"
vlan 5 802.1q 6 "TAG AGGREGATE 6 VLAN 5"
vlan 6 802.1q 6 "TAG AGGREGATE 6 VLAN 6"
vlan 7 802.1q 6 "TAG AGGREGATE 6 VLAN 7"
vlan 8 802.1q 6 "TAG AGGREGATE 6 VLAN 8"
vlan 9 802.1q 6 "TAG AGGREGATE 6 VLAN 9"
vlan 10 802.1q 6 "TAG AGGREGATE 6 VLAN 10"
vlan 2 802.1q 7 "TAG AGGREGATE 7 VLAN 2"
vlan 3 802.1q 7 "TAG AGGREGATE 7 VLAN 3"
vlan 4 802.1q 7 "TAG AGGREGATE 7 VLAN 4"
vlan 5 802.1q 7 "TAG AGGREGATE 7 VLAN 5"
vlan 6 802.1q 7 "TAG AGGREGATE 7 VLAN 6"
vlan 7 802.1q 7 "TAG AGGREGATE 7 VLAN 7"
vlan 8 802.1q 7 "TAG AGGREGATE 7 VLAN 8"
vlan 9 802.1q 7 "TAG AGGREGATE 7 VLAN 9"
vlan 10 802.1q 7 "TAG AGGREGATE 7 VLAN 10"
vlan 2 802.1q 8 "TAG AGGREGATE 8 VLAN 2"
vlan 3 802.1q 8 "TAG AGGREGATE 8 VLAN 3"
vlan 4 802.1q 8 "TAG AGGREGATE 8 VLAN 4"
vlan 5 802.1q 8 "TAG AGGREGATE 8 VLAN 5"
vlan 6 802.1q 8 "TAG AGGREGATE 8 VLAN 6"
vlan 7 802.1q 8 "TAG AGGREGATE 8 VLAN 7"
vlan 8 802.1q 8 "TAG AGGREGATE 8 VLAN 8"
vlan 9 802.1q 8 "TAG AGGREGATE 8 VLAN 9"
vlan 10 802.1q 8 "TAG AGGREGATE 8 VLAN 10"
vlan 2 802.1q 9 "TAG AGGREGATE 9 VLAN 2"
vlan 3 802.1q 9 "TAG AGGREGATE 9 VLAN 3"
vlan 4 802.1q 9 "TAG AGGREGATE 9 VLAN 4"
vlan 5 802.1q 9 "TAG AGGREGATE 9 VLAN 5"
vlan 6 802.1q 9 "TAG AGGREGATE 9 VLAN 6"
vlan 7 802.1q 9 "TAG AGGREGATE 9 VLAN 7"
vlan 8 802.1q 9 "TAG AGGREGATE 9 VLAN 8"
vlan 9 802.1q 9 "TAG AGGREGATE 9 VLAN 9"
vlan 10 802.1q 9 "TAG AGGREGATE 9 VLAN 10"
vlan 2 802.1q 10 "TAG AGGREGATE 10 VLAN 2"
vlan 3 802.1q 10 "TAG AGGREGATE 10 VLAN 3"
vlan 4 802.1q 10 "TAG AGGREGATE 10 VLAN 4"
vlan 5 802.1q 10 "TAG AGGREGATE 10 VLAN 5"
vlan 6 802.1q 10 "TAG AGGREGATE 10 VLAN 6"
vlan 7 802.1q 10 "TAG AGGREGATE 10 VLAN 7"
vlan 8 802.1q 10 "TAG AGGREGATE 10 VLAN 8"
vlan 9 802.1q 10 "TAG AGGREGATE 10 VLAN 9"
vlan 10 802.1q 10 "TAG AGGREGATE 10 VLAN 10"
vlan 2 802.1q 11 "TAG AGGREGATE 11 VLAN 2"
vlan 3 802.1q 11 "TAG AGGREGATE 11 VLAN 3"
vlan 4 802.1q 11 "TAG AGGREGATE 11 VLAN 4"
vlan 5 802.1q 11 "TAG AGGREGATE 11 VLAN 5"
vlan 6 802.1q 11 "TAG AGGREGATE 11 VLAN 6"
vlan 7 802.1q 11 "TAG AGGREGATE 11 VLAN 7"
vlan 8 802.1q 11 "TAG AGGREGATE 11 VLAN 8"
vlan 9 802.1q 11 "TAG AGGREGATE 11 VLAN 9"
vlan 10 802.1q 11 "TAG AGGREGATE 11 VLAN 10"
vlan 2 802.1q 12 "TAG AGGREGATE 12 VLAN 2"
vlan 3 802.1q 12 "TAG AGGREGATE 12 VLAN 3"
vlan 4 802.1q 12 "TAG AGGREGATE 12 VLAN 4"
vlan 5 802.1q 12 "TAG AGGREGATE 12 VLAN 5"
vlan 6 802.1q 12 "TAG AGGREGATE 12 VLAN 6"
vlan 7 802.1q 12 "TAG AGGREGATE 12 VLAN 7"
vlan 8 802.1q 12 "TAG AGGREGATE 12 VLAN 8"
vlan 9 802.1q 12 "TAG AGGREGATE 12 VLAN 9"
vlan 10 802.1q 12 "TAG AGGREGATE 12 VLAN 10"
vlan 2 802.1q 13 "TAG AGGREGATE 13 VLAN 2"
vlan 3 802.1q 13 "TAG AGGREGATE 13 VLAN 3"
vlan 4 802.1q 13 "TAG AGGREGATE 13 VLAN 4"
vlan 5 802.1q 13 "TAG AGGREGATE 13 VLAN 5"
vlan 6 802.1q 13 "TAG AGGREGATE 13 VLAN 6"
vlan 7 802.1q 13 "TAG AGGREGATE 13 VLAN 7"
vlan 8 802.1q 13 "TAG AGGREGATE 13 VLAN 8"
vlan 9 802.1q 13 "TAG AGGREGATE 13 VLAN 9"
vlan 10 802.1q 13 "TAG AGGREGATE 13 VLAN 10"
vlan 2 802.1q 14 "TAG AGGREGATE 14 VLAN 2"
vlan 3 802.1q 14 "TAG AGGREGATE 14 VLAN 3"
vlan 4 802.1q 14 "TAG AGGREGATE 14 VLAN 4"
vlan 5 802.1q 14 "TAG AGGREGATE 14 VLAN 5"
vlan 6 802.1q 14 "TAG AGGREGATE 14 VLAN 6"
vlan 7 802.1q 14 "TAG AGGREGATE 14 VLAN 7"
vlan 8 802.1q 14 "TAG AGGREGATE 14 VLAN 8"
vlan 9 802.1q 14 "TAG AGGREGATE 14 VLAN 9"
vlan 10 802.1q 14 "TAG AGGREGATE 14 VLAN 10"
vlan 2 802.1q 15 "TAG AGGREGATE 15 VLAN 2"
vlan 3 802.1q 15 "TAG AGGREGATE 15 VLAN 3"
vlan 4 802.1q 15 "TAG AGGREGATE 15 VLAN 4"
vlan 5 802.1q 15 "TAG AGGREGATE 15 VLAN 5"
vlan 6 802.1q 15 "TAG AGGREGATE 15 VLAN 6"
vlan 7 802.1q 15 "TAG AGGREGATE 15 VLAN 7"
vlan 8 802.1q 15 "TAG AGGREGATE 15 VLAN 8"
vlan 9 802.1q 15 "TAG AGGREGATE 15 VLAN 9"
vlan 10 802.1q 15 "TAG AGGREGATE 15 VLAN 10"
vlan 2 802.1q 16 "TAG AGGREGATE 16 VLAN 2"
vlan 3 802.1q 16 "TAG AGGREGATE 16 VLAN 3"
vlan 4 802.1q 16 "TAG AGGREGATE 16 VLAN 4"
vlan 5 802.1q 16 "TAG AGGREGATE 16 VLAN 5"
vlan 6 802.1q 16 "TAG AGGREGATE 16 VLAN 6"
vlan 7 802.1q 16 "TAG AGGREGATE 16 VLAN 7"
vlan 8 802.1q 16 "TAG AGGREGATE 16 VLAN 8"
vlan 9 802.1q 16 "TAG AGGREGATE 16 VLAN 9"
vlan 10 802.1q 16 "TAG AGGREGATE 16 VLAN 10"
vlan 2 802.1q 17 "TAG AGGREGATE 17 VLAN 2"
vlan 3 802.1q 17 "TAG AGGREGATE 17 VLAN 3"
vlan 4 802.1q 17 "TAG AGGREGATE 17 VLAN 4"
vlan 5 802.1q 17 "TAG AGGREGATE 17 VLAN 5"
vlan 6 802.1q 17 "TAG AGGREGATE 17 VLAN 6"
vlan 7 802.1q 17 "TAG AGGREGATE 17 VLAN 7"
vlan 8 802.1q 17 "TAG AGGREGATE 17 VLAN 8"
vlan 9 802.1q 17 "TAG AGGREGATE 17 VLAN 9"
vlan 10 802.1q 17 "TAG AGGREGATE 17 VLAN 10"
vlan 3 802.1q 18 "TAG AGGREGATE 18 VLAN 3"
vlan 6 802.1q 18 "TAG AGGREGATE 18 VLAN 6"
vlan 7 802.1q 18 "TAG AGGREGATE 18 VLAN 7"
vlan 8 802.1q 18 "TAG AGGREGATE 18 VLAN 8"
vlan 10 802.1q 18 "TAG AGGREGATE 18 VLAN 10"
! Spanning tree :
bridge mode 1x1
! Bridging :
! Bridging :
! Port mirroring :
! UDP Relay :
ip helper address 192.168.8.12
! Server load balance :
! System service :
swlog console level info
! SSH :
! VRRP :
! Web :
! AMAP :
! LLDP :
! Lan Power :
! NTP :
! RDP :
! VLAN STACKING:
! Ethernet-OAM :
! EFM-OAM :
! ERP :
! SAA :
! DHCP Server :
Thank you very much for your assistance.
Below is the Network Logical Diagram of mine existing setup
FW1 (192.168.16.2) <=====> CSW1 <====> ESW1
FW2 (192.168.16.3) <=====> CSW1 <====> ESW1
FW3 (192.168.16.4) <=====> CSW1 <====> ESW1
My Core Switch (CSW1) consist of a few VLANs and I am trying to using Policy Based Routing to divert the different VLAN to their specific FW for traffic to go out.
I had setup a client under the Guest VLAN (192.168.14.0) at the Edge switch (ESW1).
I had setup a client under the Student VLAN (192.168.10.0) at the Edge switch (ESW1).
Before I put in the Policy Based Routing (PBR), pinging to all the gateway on the Core switch is OK
================================================================
ip static-route 0.0.0.0/0 gateway 192.168.15.2 metric 1
================================================================
policy condition StudentVLAN source ip 192.168.10.0 mask 255.255.255.0
policy action toFW2 permanent gateway ip 192.168.15.3
policy rule redirectStud condition StudentVLAN action toFW2
qos apply
================================================================
policy condition WStudentVLAN source ip 192.168.12.0 mask 255.255.255.0
policy action toFW2 permanent gateway ip 192.168.15.3
policy rule redirectWStud condition WStudentVLAN action toFW2
qos apply
================================================================
policy condition GuestVLAN source ip 192.168.14.0 mask 255.255.255.0
policy action toFW3 permanent gateway ip 192.168.15.4
policy rule redirectGuest condition GuestVLAN action toFW3
qos apply
================================================================
After I put in the Policy Based Routing (PBR), did a test ping to own gateway is ok, but to other VLAN interface, there is no respond.
However when I do a tracert, I can reach the destination. Had check on the firewall that traffic had goes to the correct FW pointed to and routed had also been added to point back to the Core Switch.
So is it due to the policy based routing blocking Ping functions or I had miss out something which cause the traffic unable to route back correctly? Below is the configuration on the Core Switch and thank for your reply in advanced.
=============================================================
! Stack Manager :
! Chassis :
system name L3-CSW-01
! Configuration:
! VLAN :
vlan 1 enable name "Disabled"
vlan 2 enable name "Management"
vlan 2 port default 1/24
vlan 2 port default 1/25
vlan 2 port default 1/26
vlan 2 port default 1/27
vlan 2 port default 1/28
vlan 2 port default 1/29
vlan 2 port default 1/30
vlan 2 port default 1/31
vlan 2 port default 1/32
vlan 2 port default 1/33
vlan 2 port default 1/34
vlan 2 port default 1/35
vlan 2 port default 1/36
vlan 2 port default 1/45
vlan 2 port default 2/20
vlan 2 port default 2/25
vlan 2 port default 2/26
vlan 2 port default 2/27
vlan 2 port default 2/28
vlan 2 port default 2/29
vlan 2 port default 2/30
vlan 2 port default 2/31
vlan 2 port default 2/32
vlan 2 port default 2/33
vlan 2 port default 2/34
vlan 2 port default 2/35
vlan 2 port default 2/36
vlan 3 enable name "Wireless Management"
vlan 3 port default 1/22
vlan 4 enable name "Student"
vlan 4 port default 1/18
vlan 5 enable name "Staff"
vlan 5 port default 1/19
vlan 5 port default 1/20
vlan 6 enable name "Wireless Student"
vlan 7 enable name "Wireless Staff"
vlan 8 enable name "Guest"
vlan 9 enable name "Firewall"
vlan 9 port default 1/46
vlan 9 port default 1/47
vlan 9 port default 2/47
vlan 10 enable name "Wireless VIP"
! VLAN SL:
! IP :
ip service all
ip interface "Vlan2" address 192.168.8.1 mask 255.255.255.0 vlan 2 ifindex 2
ip interface "Vlan3" address 192.168.9.1 mask 255.255.255.0 vlan 3 ifindex 3
ip interface "Vlan4" address 192.168.10.1 mask 255.255.255.0 vlan 4 ifindex 4
ip interface "Vlan5" address 192.168.11.1 mask 255.255.255.0 vlan 5 ifindex 5
ip interface "Vlan6" address 192.168.12.1 mask 255.255.255.0 vlan 6 ifindex 6
ip interface "Vlan7" address 192.168.13.1 mask 255.255.255.0 vlan 7 ifindex 7
ip interface "Vlan8" address 192.168.14.1 mask 255.255.255.0 vlan 8 ifindex 8
ip interface "Vlan9" address 192.168.15.1 mask 255.255.255.0 vlan 9 ifindex 9
ip interface "vlan10" address 192.168.16.1 mask 255.255.255.0 vlan 10 ifindex 10
! IPX :
! IPMS :
! AAA :
aaa radius-server "192.168.8.9" host 192.168.8.9 key c9ab906dcb630054cf41331b7f81f42c retransmit 3 timeout 2 auth-port 1812 acct-port 1813
aaa radius-server "192.168.8.11" host 192.168.8.11 key c9ab906dcb630054cf41331b7f81f42c retransmit 3 timeout 2 auth-port 1812 acct-port 1813
aaa authentication default "192.168.8.9"
aaa authentication console "local"
aaa authentication telnet "local"
aaa authentication http "local"
! PARTM :
! AVLAN :
! 802.1x :
! QOS :
policy condition GuestVLAN source ip 192.168.14.0 mask 255.255.255.0
policy condition StudentVLAN source ip 192.168.10.0 mask 255.255.255.0
policy condition WStudentVLAN source ip 192.168.12.0 mask 255.255.255.0
policy action toFW2 permanent gateway ip 192.168.15.3
policy action toFW3 permanent gateway ip 192.168.15.4
policy rule redirectWStud condition WStudentVLAN action toFW2
policy rule redirectStud condition StudentVLAN action toFW2
policy rule redirectGuest condition GuestVLAN action toFW3
qos apply
! Policy manager :
! Session manager :
session prompt default "L3-CSW-01->"
! SNMP :
! RIP :
! OSPF :
! BFD-STD :
! ISIS :
! IPv6 :
! IPSec :
! IP multicast :
ip static-route 0.0.0.0/0 gateway 192.168.15.2 metric 1
! RIPng :
! OSPF3 :
! BGP :
! Health monitor :
! Interface :
! Udld :
! Netsec :
! Link Aggregate :
lacp linkagg 1 size 2 admin state enable
lacp linkagg 1 name "L3-CSW-01 P1/1,2/1 to L1-ESW-01 P1/1,1/2"
lacp linkagg 1 actor admin key 1
lacp linkagg 2 size 2 admin state enable
lacp linkagg 2 actor admin key 2
lacp linkagg 3 size 2 admin state enable
lacp linkagg 3 actor admin key 3
lacp linkagg 4 size 2 admin state enable
lacp linkagg 4 actor admin key 4
lacp linkagg 5 size 2 admin state enable
lacp linkagg 5 actor admin key 5
lacp linkagg 6 size 2 admin state enable
lacp linkagg 6 actor admin key 6
lacp linkagg 7 size 2 admin state enable
lacp linkagg 7 actor admin key 7
lacp linkagg 8 size 2 admin state enable
lacp linkagg 8 actor admin key 8
lacp linkagg 9 size 2 admin state enable
lacp linkagg 9 actor admin key 9
lacp linkagg 10 size 2 admin state enable
lacp linkagg 10 actor admin key 10
lacp linkagg 11 size 2 admin state enable
lacp linkagg 11 actor admin key 11
lacp linkagg 12 size 2 admin state enable
lacp linkagg 12 actor admin key 12
lacp linkagg 13 size 2 admin state enable
lacp linkagg 13 actor admin key 13
lacp linkagg 14 size 2 admin state enable
lacp linkagg 14 actor admin key 14
lacp linkagg 15 size 2 admin state enable
lacp linkagg 15 actor admin key 15
lacp linkagg 16 size 2 admin state enable
lacp linkagg 16 actor admin key 16
lacp linkagg 17 size 2 admin state enable
lacp linkagg 17 actor admin key 17
static linkagg 18 size 2 admin state enable
lacp agg 1/1 actor admin key 1
lacp agg 1/2 actor admin key 2
lacp agg 1/3 actor admin key 3
lacp agg 1/4 actor admin key 4
lacp agg 1/5 actor admin key 5
lacp agg 1/6 actor admin key 6
lacp agg 1/7 actor admin key 7
lacp agg 1/8 actor admin key 8
lacp agg 1/9 actor admin key 9
lacp agg 1/10 actor admin key 10
lacp agg 1/11 actor admin key 11
lacp agg 1/12 actor admin key 12
lacp agg 1/13 actor admin key 13
lacp agg 1/14 actor admin key 14
lacp agg 1/15 actor admin key 15
lacp agg 1/16 actor admin key 16
lacp agg 1/17 actor admin key 17
static agg 1/48 agg num 18
lacp agg 2/1 actor admin key 1
lacp agg 2/2 actor admin key 2
lacp agg 2/3 actor admin key 3
lacp agg 2/4 actor admin key 4
lacp agg 2/5 actor admin key 5
lacp agg 2/6 actor admin key 6
lacp agg 2/7 actor admin key 7
lacp agg 2/8 actor admin key 8
lacp agg 2/9 actor admin key 9
lacp agg 2/10 actor admin key 10
lacp agg 2/11 actor admin key 11
lacp agg 2/12 actor admin key 12
lacp agg 2/13 actor admin key 13
lacp agg 2/14 actor admin key 14
lacp agg 2/15 actor admin key 15
lacp agg 2/16 actor admin key 16
lacp agg 2/17 actor admin key 17
static agg 2/48 agg num 18
! Port Mapping :
! VLAN AGG:
! 802.1Q :
vlan 2 802.1q 2/19 "TAG AGGREGATE 2 VLAN 2"
vlan 3 802.1q 2/19 "TAG AGGREGATE 2 VLAN 3"
vlan 4 802.1q 2/19 "TAG AGGREGATE 2 VLAN 4"
vlan 5 802.1q 2/19 "TAG AGGREGATE 2 VLAN 5"
vlan 6 802.1q 2/19 "TAG AGGREGATE 2 VLAN 6"
vlan 7 802.1q 2/19 "TAG AGGREGATE 2 VLAN 7"
vlan 8 802.1q 2/19 "TAG AGGREGATE 2 VLAN 8"
vlan 9 802.1q 2/19 "TAG AGGREGATE 2 VLAN 9"
vlan 10 802.1q 2/19 "TAG AGGREGATE 2 VLAN 10"
vlan 2 802.1q 1 "TAG AGGREGATE 1 VLAN 2"
vlan 3 802.1q 1 "TAG AGGREGATE 1 VLAN 3"
vlan 4 802.1q 1 "TAG AGGREGATE 1 VLAN 4"
vlan 5 802.1q 1 "TAG AGGREGATE 1 VLAN 5"
vlan 6 802.1q 1 "TAG AGGREGATE 1 VLAN 6"
vlan 7 802.1q 1 "TAG AGGREGATE 1 VLAN 7"
vlan 8 802.1q 1 "TAG AGGREGATE 1 VLAN 8"
vlan 9 802.1q 1 "TAG AGGREGATE 1 VLAN 9"
vlan 10 802.1q 1 "TAG AGGREGATE 1 VLAN 10"
vlan 2 802.1q 2 "TAG AGGREGATE 2 VLAN 2"
vlan 3 802.1q 2 "TAG AGGREGATE 2 VLAN 3"
vlan 4 802.1q 2 "TAG AGGREGATE 2 VLAN 4"
vlan 5 802.1q 2 "TAG AGGREGATE 2 VLAN 5"
vlan 6 802.1q 2 "TAG AGGREGATE 2 VLAN 6"
vlan 7 802.1q 2 "TAG AGGREGATE 2 VLAN 7"
vlan 8 802.1q 2 "TAG AGGREGATE 2 VLAN 8"
vlan 9 802.1q 2 "TAG AGGREGATE 2 VLAN 9"
vlan 10 802.1q 2 "TAG AGGREGATE 2 VLAN 10"
vlan 2 802.1q 3 "TAG AGGREGATE 3 VLAN 2"
vlan 3 802.1q 3 "TAG AGGREGATE 3 VLAN 3"
vlan 4 802.1q 3 "TAG AGGREGATE 3 VLAN 4"
vlan 5 802.1q 3 "TAG AGGREGATE 3 VLAN 5"
vlan 6 802.1q 3 "TAG AGGREGATE 3 VLAN 6"
vlan 7 802.1q 3 "TAG AGGREGATE 3 VLAN 7"
vlan 8 802.1q 3 "TAG AGGREGATE 3 VLAN 8"
vlan 9 802.1q 3 "TAG AGGREGATE 3 VLAN 9"
vlan 10 802.1q 3 "TAG AGGREGATE 3 VLAN 10"
vlan 2 802.1q 4 "TAG AGGREGATE 4 VLAN 2"
vlan 3 802.1q 4 "TAG AGGREGATE 4 VLAN 4"
vlan 4 802.1q 4 "TAG AGGREGATE 4 VLAN 4"
vlan 5 802.1q 4 "TAG AGGREGATE 4 VLAN 5"
vlan 6 802.1q 4 "TAG AGGREGATE 4 VLAN 6"
vlan 7 802.1q 4 "TAG AGGREGATE 4 VLAN 7"
vlan 8 802.1q 4 "TAG AGGREGATE 4 VLAN 8"
vlan 9 802.1q 4 "TAG AGGREGATE 4 VLAN 9"
vlan 10 802.1q 4 "TAG AGGREGATE 4 VLAN 10"
vlan 2 802.1q 5 "TAG AGGREGATE 5 VLAN 2"
vlan 3 802.1q 5 "TAG AGGREGATE 5 VLAN 3"
vlan 4 802.1q 5 "TAG AGGREGATE 5 VLAN 4"
vlan 5 802.1q 5 "TAG AGGREGATE 5 VLAN 5"
vlan 6 802.1q 5 "TAG AGGREGATE 5 VLAN 6"
vlan 7 802.1q 5 "TAG AGGREGATE 5 VLAN 7"
vlan 8 802.1q 5 "TAG AGGREGATE 5 VLAN 8"
vlan 9 802.1q 5 "TAG AGGREGATE 5 VLAN 9"
vlan 10 802.1q 5 "TAG AGGREGATE 5 VLAN 10"
vlan 2 802.1q 6 "TAG AGGREGATE 6 VLAN 2"
vlan 3 802.1q 6 "TAG AGGREGATE 6 VLAN 3"
vlan 4 802.1q 6 "TAG AGGREGATE 6 VLAN 4"
vlan 5 802.1q 6 "TAG AGGREGATE 6 VLAN 5"
vlan 6 802.1q 6 "TAG AGGREGATE 6 VLAN 6"
vlan 7 802.1q 6 "TAG AGGREGATE 6 VLAN 7"
vlan 8 802.1q 6 "TAG AGGREGATE 6 VLAN 8"
vlan 9 802.1q 6 "TAG AGGREGATE 6 VLAN 9"
vlan 10 802.1q 6 "TAG AGGREGATE 6 VLAN 10"
vlan 2 802.1q 7 "TAG AGGREGATE 7 VLAN 2"
vlan 3 802.1q 7 "TAG AGGREGATE 7 VLAN 3"
vlan 4 802.1q 7 "TAG AGGREGATE 7 VLAN 4"
vlan 5 802.1q 7 "TAG AGGREGATE 7 VLAN 5"
vlan 6 802.1q 7 "TAG AGGREGATE 7 VLAN 6"
vlan 7 802.1q 7 "TAG AGGREGATE 7 VLAN 7"
vlan 8 802.1q 7 "TAG AGGREGATE 7 VLAN 8"
vlan 9 802.1q 7 "TAG AGGREGATE 7 VLAN 9"
vlan 10 802.1q 7 "TAG AGGREGATE 7 VLAN 10"
vlan 2 802.1q 8 "TAG AGGREGATE 8 VLAN 2"
vlan 3 802.1q 8 "TAG AGGREGATE 8 VLAN 3"
vlan 4 802.1q 8 "TAG AGGREGATE 8 VLAN 4"
vlan 5 802.1q 8 "TAG AGGREGATE 8 VLAN 5"
vlan 6 802.1q 8 "TAG AGGREGATE 8 VLAN 6"
vlan 7 802.1q 8 "TAG AGGREGATE 8 VLAN 7"
vlan 8 802.1q 8 "TAG AGGREGATE 8 VLAN 8"
vlan 9 802.1q 8 "TAG AGGREGATE 8 VLAN 9"
vlan 10 802.1q 8 "TAG AGGREGATE 8 VLAN 10"
vlan 2 802.1q 9 "TAG AGGREGATE 9 VLAN 2"
vlan 3 802.1q 9 "TAG AGGREGATE 9 VLAN 3"
vlan 4 802.1q 9 "TAG AGGREGATE 9 VLAN 4"
vlan 5 802.1q 9 "TAG AGGREGATE 9 VLAN 5"
vlan 6 802.1q 9 "TAG AGGREGATE 9 VLAN 6"
vlan 7 802.1q 9 "TAG AGGREGATE 9 VLAN 7"
vlan 8 802.1q 9 "TAG AGGREGATE 9 VLAN 8"
vlan 9 802.1q 9 "TAG AGGREGATE 9 VLAN 9"
vlan 10 802.1q 9 "TAG AGGREGATE 9 VLAN 10"
vlan 2 802.1q 10 "TAG AGGREGATE 10 VLAN 2"
vlan 3 802.1q 10 "TAG AGGREGATE 10 VLAN 3"
vlan 4 802.1q 10 "TAG AGGREGATE 10 VLAN 4"
vlan 5 802.1q 10 "TAG AGGREGATE 10 VLAN 5"
vlan 6 802.1q 10 "TAG AGGREGATE 10 VLAN 6"
vlan 7 802.1q 10 "TAG AGGREGATE 10 VLAN 7"
vlan 8 802.1q 10 "TAG AGGREGATE 10 VLAN 8"
vlan 9 802.1q 10 "TAG AGGREGATE 10 VLAN 9"
vlan 10 802.1q 10 "TAG AGGREGATE 10 VLAN 10"
vlan 2 802.1q 11 "TAG AGGREGATE 11 VLAN 2"
vlan 3 802.1q 11 "TAG AGGREGATE 11 VLAN 3"
vlan 4 802.1q 11 "TAG AGGREGATE 11 VLAN 4"
vlan 5 802.1q 11 "TAG AGGREGATE 11 VLAN 5"
vlan 6 802.1q 11 "TAG AGGREGATE 11 VLAN 6"
vlan 7 802.1q 11 "TAG AGGREGATE 11 VLAN 7"
vlan 8 802.1q 11 "TAG AGGREGATE 11 VLAN 8"
vlan 9 802.1q 11 "TAG AGGREGATE 11 VLAN 9"
vlan 10 802.1q 11 "TAG AGGREGATE 11 VLAN 10"
vlan 2 802.1q 12 "TAG AGGREGATE 12 VLAN 2"
vlan 3 802.1q 12 "TAG AGGREGATE 12 VLAN 3"
vlan 4 802.1q 12 "TAG AGGREGATE 12 VLAN 4"
vlan 5 802.1q 12 "TAG AGGREGATE 12 VLAN 5"
vlan 6 802.1q 12 "TAG AGGREGATE 12 VLAN 6"
vlan 7 802.1q 12 "TAG AGGREGATE 12 VLAN 7"
vlan 8 802.1q 12 "TAG AGGREGATE 12 VLAN 8"
vlan 9 802.1q 12 "TAG AGGREGATE 12 VLAN 9"
vlan 10 802.1q 12 "TAG AGGREGATE 12 VLAN 10"
vlan 2 802.1q 13 "TAG AGGREGATE 13 VLAN 2"
vlan 3 802.1q 13 "TAG AGGREGATE 13 VLAN 3"
vlan 4 802.1q 13 "TAG AGGREGATE 13 VLAN 4"
vlan 5 802.1q 13 "TAG AGGREGATE 13 VLAN 5"
vlan 6 802.1q 13 "TAG AGGREGATE 13 VLAN 6"
vlan 7 802.1q 13 "TAG AGGREGATE 13 VLAN 7"
vlan 8 802.1q 13 "TAG AGGREGATE 13 VLAN 8"
vlan 9 802.1q 13 "TAG AGGREGATE 13 VLAN 9"
vlan 10 802.1q 13 "TAG AGGREGATE 13 VLAN 10"
vlan 2 802.1q 14 "TAG AGGREGATE 14 VLAN 2"
vlan 3 802.1q 14 "TAG AGGREGATE 14 VLAN 3"
vlan 4 802.1q 14 "TAG AGGREGATE 14 VLAN 4"
vlan 5 802.1q 14 "TAG AGGREGATE 14 VLAN 5"
vlan 6 802.1q 14 "TAG AGGREGATE 14 VLAN 6"
vlan 7 802.1q 14 "TAG AGGREGATE 14 VLAN 7"
vlan 8 802.1q 14 "TAG AGGREGATE 14 VLAN 8"
vlan 9 802.1q 14 "TAG AGGREGATE 14 VLAN 9"
vlan 10 802.1q 14 "TAG AGGREGATE 14 VLAN 10"
vlan 2 802.1q 15 "TAG AGGREGATE 15 VLAN 2"
vlan 3 802.1q 15 "TAG AGGREGATE 15 VLAN 3"
vlan 4 802.1q 15 "TAG AGGREGATE 15 VLAN 4"
vlan 5 802.1q 15 "TAG AGGREGATE 15 VLAN 5"
vlan 6 802.1q 15 "TAG AGGREGATE 15 VLAN 6"
vlan 7 802.1q 15 "TAG AGGREGATE 15 VLAN 7"
vlan 8 802.1q 15 "TAG AGGREGATE 15 VLAN 8"
vlan 9 802.1q 15 "TAG AGGREGATE 15 VLAN 9"
vlan 10 802.1q 15 "TAG AGGREGATE 15 VLAN 10"
vlan 2 802.1q 16 "TAG AGGREGATE 16 VLAN 2"
vlan 3 802.1q 16 "TAG AGGREGATE 16 VLAN 3"
vlan 4 802.1q 16 "TAG AGGREGATE 16 VLAN 4"
vlan 5 802.1q 16 "TAG AGGREGATE 16 VLAN 5"
vlan 6 802.1q 16 "TAG AGGREGATE 16 VLAN 6"
vlan 7 802.1q 16 "TAG AGGREGATE 16 VLAN 7"
vlan 8 802.1q 16 "TAG AGGREGATE 16 VLAN 8"
vlan 9 802.1q 16 "TAG AGGREGATE 16 VLAN 9"
vlan 10 802.1q 16 "TAG AGGREGATE 16 VLAN 10"
vlan 2 802.1q 17 "TAG AGGREGATE 17 VLAN 2"
vlan 3 802.1q 17 "TAG AGGREGATE 17 VLAN 3"
vlan 4 802.1q 17 "TAG AGGREGATE 17 VLAN 4"
vlan 5 802.1q 17 "TAG AGGREGATE 17 VLAN 5"
vlan 6 802.1q 17 "TAG AGGREGATE 17 VLAN 6"
vlan 7 802.1q 17 "TAG AGGREGATE 17 VLAN 7"
vlan 8 802.1q 17 "TAG AGGREGATE 17 VLAN 8"
vlan 9 802.1q 17 "TAG AGGREGATE 17 VLAN 9"
vlan 10 802.1q 17 "TAG AGGREGATE 17 VLAN 10"
vlan 3 802.1q 18 "TAG AGGREGATE 18 VLAN 3"
vlan 6 802.1q 18 "TAG AGGREGATE 18 VLAN 6"
vlan 7 802.1q 18 "TAG AGGREGATE 18 VLAN 7"
vlan 8 802.1q 18 "TAG AGGREGATE 18 VLAN 8"
vlan 10 802.1q 18 "TAG AGGREGATE 18 VLAN 10"
! Spanning tree :
bridge mode 1x1
! Bridging :
! Bridging :
! Port mirroring :
! UDP Relay :
ip helper address 192.168.8.12
! Server load balance :
! System service :
swlog console level info
! SSH :
! VRRP :
! Web :
! AMAP :
! LLDP :
! Lan Power :
! NTP :
! RDP :
! VLAN STACKING:
! Ethernet-OAM :
! EFM-OAM :
! ERP :
! SAA :
! DHCP Server :
Thank you very much for your assistance.