Chapter 15: IP Policy-Based Forwarding Configuration Guide

ISPs. You can also create IP policies to select service providers based on various traffic types.

Configuring IP Policies

To implement an IP policy, you first create a profile for the packets to be forwarded using an IP policy. For example, you can create a profile defined as “all telnet packets going from network 9.1.0.0/16 to network 15.1.0.0/16”. You then associate the profile with an IP policy. The IP policy specifies what to do with the packets that match the profile. For example, you can create an IP policy that sends packets matching a given profile to next- hop gateway 100.1.1.1.

Configuring an IP policy consists of the following tasks:

Defining a profile

Associating the profile with a policy

Applying the IP policy to an interface

Defining an ACL Profile

An ACL profile specifies the criteria packets must meet to be eligible for IP policy routing. You define profiles with the acl command. For IP policy routing, the SSR uses the packet- related information from the acl command and ignores the other fields.

For example, the following acl command creates a profile called “prof1” for telnet packets going from network 9.1.1.5 to network 15.1.1.2:

ssr(config)# acl prof1 permit ip 9.1.0.0/16 15.1.0.0/16 any any telnet 0

See the SmartSwitch Router Command Line Interface Reference Manual for complete syntax information for the acl command.

Note: ACLs for non-IP protocols cannot be used for IP policy routing.

Associating the Profile with an IP Policy

Once you have defined a profile with the acl command, you associate the profile with an IP policy by entering one or more ip-policystatements. An ip-policystatement specifies the next-hop gateway (or gateways) where packets matching a profile are forwarded. (See the SmartSwitch Router Command Line Interface Reference Manual for complete syntax information for the ip-policycommand.)

208

SmartSwitch Router User Reference Manual

Page 234
Image 234
Cabletron Systems 9032578-05 Configuring IP Policies, Defining an ACL Profile, Associating the Profile with an IP Policy