Chapter 13: IP Policy-Based Forwarding Configuration Guide

The following is the IP policy configuration for the Policy Router in Figure 21:

interface create ip mls0 address-netmask 10.50.1.1/16 port et.1.1

acl contractors permit ip 10.50.1.0/24 any any any 0 acl full-timers permit ip 10.50.2.0/24 any any any 0

ip-policy access permit acl contractors next-hop-list 11.1.1.1 action policy-only

ip-policy access permit acl full-timers next-hop-list 12.1.1.1 action policy-first

ip-policy access apply interface mls0

Firewall Load Balancing

The next hop gateway can be selected by the following information in the IP packet: source IP, destination IP, or both the source and destination IP. Figure 22 illustrates this configuration.

Intranet

Internet

Firewalls

1.1.1.1 1 2.2.2.1

mls1

Policy

 

Router 1

 

1.1.1.5

 

 

 

 

1

 

 

 

e

 

 

 

 

 

 

 

 

 

t

 

 

 

 

 

.

 

 

 

 

 

 

.

 

 

 

 

1

 

 

 

 

 

 

1

 

 

 

.

 

1.1.1.2

 

2.2.2.2

 

 

 

.

 

t

 

 

2

 

 

 

 

1

 

e

.2

 

 

et.

1.2

 

 

 

 

 

 

t.1

 

 

 

 

 

 

 

 

 

 

e

 

 

 

 

 

 

 

 

 

 

 

e

t

 

 

 

 

 

 

 

.3

 

 

 

 

 

 

 

 

1

 

 

 

 

.

 

 

 

 

t.

 

 

 

 

 

 

1.

 

 

 

e

 

 

 

 

 

t

 

3

1.1.1.3

 

2.2.2.3

 

 

.4

 

e

 

 

 

 

 

 

.1

 

 

 

.

 

 

 

 

 

 

 

 

 

 

.

 

 

 

 

t

 

 

 

 

1

 

 

3

 

e

 

 

 

 

 

 

 

4

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Policy Router 2

2.2.2.5

mls2

1.1.1.44 2.2.2.4

Figure 22. Selecting Next Hop Gateway from IP Packet Information

One session should always go to a particular firewall for persistence.

218

SmartSwitch Router User Reference Manual

Page 218
Image 218
Cabletron Systems SmartSwitch manual Firewall Load Balancing, Selecting Next Hop Gateway from IP Packet Information