<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot apply a policy-map on interface because of Flowspec IOS XR in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748321#M1096412</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Review this thread :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/routing/got-error-when-applying-pbr-on-asr9010/td-p/4076635" target="_blank"&gt;https://community.cisco.com/t5/routing/got-error-when-applying-pbr-on-asr9010/td-p/4076635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2023 10:40:44 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-01-03T10:40:44Z</dc:date>
    <item>
      <title>Cannot apply a policy-map on interface because of Flowspec IOS XR</title>
      <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748255#M1096409</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to apply a policy on my router interface to change the next-hop for some packet source IPs so it could be redirected to a specific transit. I applied a Policy-map PBR on an ingress interface on Cisco XR ASR9000 but the commit does not work and here is the log :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;!! SEMANTIC ERRORS: This configuration was rejected by&lt;/DIV&gt;&lt;DIV&gt;!! the system due to semantic errors. The individual&lt;/DIV&gt;&lt;DIV&gt;!! errors with each failed configuration command can be&lt;/DIV&gt;&lt;DIV&gt;!! found below.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;interface Bundle-Ether2.10&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;service-policy type pbr input PM_IP_SFR_Sortie_NAT&lt;/DIV&gt;&lt;DIV&gt;!!% 'PBR' detected the 'warning' condition 'BGP FS policy already applied to an interface or traditional policy applied to an interface'&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;Flowspec is enabled on all interfaces for DDoS and we cannot disable it.&lt;/DIV&gt;&lt;DIV&gt;Someone can help with this please ?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Regards&lt;/DIV&gt;&lt;DIV&gt;Louey&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 03 Jan 2023 10:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748255#M1096409</guid>
      <dc:creator>Louey</dc:creator>
      <dc:date>2023-01-03T10:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot apply a policy-map on interface because of Flowspec IOS XR</title>
      <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748300#M1096410</link>
      <description>&lt;P&gt;That’s an useful feature because we can develop a program executed on the router itself to convert the flowspec rules received into configuration line. That’s exactly what the bgpfs2acl script is doing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.mygeorgiasouthern.net/" target="_self"&gt;MyGeorgiaSouthern.edu&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 04:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748300#M1096410</guid>
      <dc:creator>Stratforders</dc:creator>
      <dc:date>2023-01-04T04:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot apply a policy-map on interface because of Flowspec IOS XR</title>
      <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748320#M1096411</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/920275"&gt;@Louey&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please share the configuration of that interface .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sharanya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 10:40:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748320#M1096411</guid>
      <dc:creator>fssabati</dc:creator>
      <dc:date>2023-01-03T10:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot apply a policy-map on interface because of Flowspec IOS XR</title>
      <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748321#M1096412</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Review this thread :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/routing/got-error-when-applying-pbr-on-asr9010/td-p/4076635" target="_blank"&gt;https://community.cisco.com/t5/routing/got-error-when-applying-pbr-on-asr9010/td-p/4076635&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 10:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748321#M1096412</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-01-03T10:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot apply a policy-map on interface because of Flowspec IOS XR</title>
      <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748329#M1096413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the interface config :&lt;/P&gt;&lt;P&gt;interface Bundle-Ether2.10&lt;BR /&gt;description Server: VLAN10 - Interco Public_Network_and_Transit9&lt;BR /&gt;ipv4 mtu 1500&lt;/P&gt;&lt;P&gt;ipv4 address 10.10.10.1 255.255.255.192&lt;/P&gt;&lt;P&gt;encapsulation dot1q 10&lt;/P&gt;&lt;P&gt;ex&lt;/P&gt;&lt;P&gt;And here is the policy-map&lt;/P&gt;&lt;P&gt;policy-map type pbr PM_IP_SFR_Sortie_NAT&lt;BR /&gt;class type traffic CM_IP_SFR_Sortie_NAT&lt;BR /&gt;redirect ipv4 nexthop x.x.x.x&lt;/P&gt;&lt;P&gt;ex&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 10:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748329#M1096413</guid>
      <dc:creator>Louey</dc:creator>
      <dc:date>2023-01-03T10:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot apply a policy-map on interface because of Flowspec IOS XR</title>
      <link>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748332#M1096415</link>
      <description>&lt;P&gt;No solution on the post unfortunately.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 10:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-apply-a-policy-map-on-interface-because-of-flowspec-ios/m-p/4748332#M1096415</guid>
      <dc:creator>Louey</dc:creator>
      <dc:date>2023-01-03T10:53:46Z</dc:date>
    </item>
  </channel>
</rss>

