<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR verify availability track object on FMC 7.4 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5114306#M1112897</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based route lookup called for 10.0.0.11/62195 to 18.64.243.21/443 proto 17 sub_proto 0 received on interface inf_inside,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: First matching rule from ACL(3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: route map FMC_GENERATED_PBR_1715304385898, sequence 5, permit; proceed with policy routing&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based routing applied; egress_ifc = inf_ISP2 : next_hop = gw_ISP2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based route lookup called for 10.0.0.11/56704 to 3.211.227.81/443 proto 6 sub_proto 0 received on interface inf_inside,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: First matching rule from ACL(3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: route map FMC_GENERATED_PBR_1715304385898, sequence 5, permit; proceed with policy routing&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based routing applied; egress_ifc = inf_IPS2 : next_hop = gw_ISP2&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;fpr# show path-monitoring&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Interface: inf_ISP2 (Ethernet1/1)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer: 33.44.55.66&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Version: 7546&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer reachable: No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;RTT average: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Jitter: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Packet loss: 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;MOS: 0.0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Last updated: 7 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;Interface: inf_IPS1 (Ethernet1/3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer: 8.8.8.8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Version: 7546&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer reachable: Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;RTT average: 5029 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Jitter: 751 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Packet loss: 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Last updated: 7 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Last updated: 7 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 12:06:49 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2024-05-23T12:06:49Z</dc:date>
    <item>
      <title>PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5112335#M1112841</link>
      <description>&lt;P&gt;I am setting up PBR under device management on FMC 7.4.&amp;nbsp; (in the past I had done this with FlexConfig but it seems that starting with 7.1 that **nctionality has been disabled from FlexConfig and moved to device management).&amp;nbsp; Under dev mgmnt/PBR/verify availability there is an option to enter a track but it's not clear if this should be an existing track object or the PBR screen will create a new object.&amp;nbsp; I started by just entering a random number with the thinking it will create the track but it appears it does not?&amp;nbsp; When I connect to the LINA and issue a "show track" command I only see the track objects that I added previously using SLA monitor in the object management screen.&amp;nbsp; Is it possible that this new track object lives somewhere else and I need to use a different command to see its status?&amp;nbsp; Or am I overthinking this and I need to create a track object separately and reference this object in my PBR config?&amp;nbsp; &amp;nbsp;See attached example were PBR created track is 222 but does not appear in LINA config.&amp;nbsp; Track 3 and 4 were created using object management screen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;route-map FMC_GENERATED_PBR_1715304385871 permit 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;match ip **bleep** acl_PBR&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;set ip next-hop verify-availability 1.1.1.1 1 &lt;STRONG&gt;&lt;FONT size="4"&gt;track 222&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sla monitor 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;type echo protocol ipIcmpEcho 8.8.4.4 interface interface3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;timeout 6000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sla monitor schedule 2 life forever start-time now&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sla monitor 4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;type echo protocol ipIcmpEcho 8.8.8.8 interface interface4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;timeout 6000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sla monitor schedule 1 life forever start-time now&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;track 3 rtr 3 reachability&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;track 4 rtr 4 reachability&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2024 18:36:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5112335#M1112841</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-21T18:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113172#M1112854</link>
      <description>&lt;P&gt;update: I was not able to get PBR with verify-availability working using only the PBR config screen in dev management. Two issues I had were that it would add two "set ip next-hop" lines in the PBR and that it does not create an SLA tracking object.&amp;nbsp; I used FlexConfig to remove the extra line and create the SLA and this seems to work as I need.&amp;nbsp; Below is summary:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;** device management generated PBR **&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;route-map FMC_GENERATED_PBR_1715304385885 permit 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;match ip **bleep** acl_PBR-ISP1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;set ip next-hop verify-availability ISP1_gatewayIP 1 track 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;set ip next-hop ISP1_gatewayIP&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;** "fixup" FlexConfig fpr dev mgmt generated PBR **&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;route-map FMC_GENERATED_PBR_1715304385885 permit 5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;no set ip next-hop ISP1_gatewayIP&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;no sla monitor 30&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sla monitor 30&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;type echo protocol ipIcmpEcho 8.8.4.4 interface inf_ISP1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;timeout 6000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;sla monitor schedule 30 life forever start-time now&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;track 3 rtr 30 reachability&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 12:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113172#M1112854</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-22T12:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113185#M1112855</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317180"&gt;@tato386&lt;/a&gt; you could use the interface priority instead of using Flexconfig&lt;/P&gt;
&lt;P&gt;"&lt;SPAN class="ph uicontrol"&gt;Interface Priority&lt;/SPAN&gt;—The traffic is forwarded based on the priority of the interfaces. Traffic is routed to the interface with the least priority value first. When the interface is not available, the traffic is then forwarded to the interface with the next lowest priority value."&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-policy-based.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-policy-based.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 12:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113185#M1112855</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-22T12:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113202#M1112856</link>
      <description>&lt;P&gt;yes, but what is the definition of "interface not available"?&amp;nbsp; The FTD interfaces are connected to the ISP's on-prem router so as long as there is power the FTD interface will show as up even if no path to internet.&amp;nbsp; I guess path monitoring might help here?&amp;nbsp; If path&amp;nbsp; shows down does that create an interface not available event?&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 13:23:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113202#M1112856</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-22T13:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113207#M1112857</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317180"&gt;@tato386&lt;/a&gt; yes use path monitoring. Here is a better guide:- &lt;A href="https://secure.cisco.com/secure-firewall/docs/policy-based-routing-with-path-monitoring" target="_blank"&gt;https://secure.cisco.com/secure-firewall/docs/policy-based-routing-with-path-monitoring&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 13:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113207#M1112857</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-22T13:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113243#M1112859</link>
      <description>&lt;P&gt;looks pretty good.&amp;nbsp; I'll give that a shot and post back.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 13:46:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113243#M1112859</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-22T13:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113871#M1112883</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I tried to use path monitoring and the device management PBR config but was not able to achieve the desired results.&amp;nbsp; When both interfaces are in a normal state the PBR functions as expected.&amp;nbsp; However, I then tried to simulate a failed circuit by using a bogus IP address in the IPv4 peer target of the primary interface path monitoring config.&amp;nbsp; I can see from the health monitor that the MOS for that circuit dropped to 0 and the packet loss jumped to 100% but yet the FTD continued to router traffic out that "failed" interface.&amp;nbsp; &amp;nbsp;Maybe there is some other step I need to take?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 04:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5113871#M1112883</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-23T04:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5114306#M1112897</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based route lookup called for 10.0.0.11/62195 to 18.64.243.21/443 proto 17 sub_proto 0 received on interface inf_inside,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: First matching rule from ACL(3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: route map FMC_GENERATED_PBR_1715304385898, sequence 5, permit; proceed with policy routing&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based routing applied; egress_ifc = inf_ISP2 : next_hop = gw_ISP2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based route lookup called for 10.0.0.11/56704 to 3.211.227.81/443 proto 6 sub_proto 0 received on interface inf_inside,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: First matching rule from ACL(3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: route map FMC_GENERATED_PBR_1715304385898, sequence 5, permit; proceed with policy routing&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;pbr: policy based routing applied; egress_ifc = inf_IPS2 : next_hop = gw_ISP2&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;fpr# show path-monitoring&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Interface: inf_ISP2 (Ethernet1/1)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer: 33.44.55.66&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Version: 7546&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer reachable: No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;RTT average: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Jitter: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Packet loss: 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;MOS: 0.0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Last updated: 7 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;Interface: inf_IPS1 (Ethernet1/3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer: 8.8.8.8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Version: 7546&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Remote peer reachable: Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;RTT average: 5029 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Jitter: 751 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Packet loss: 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Last updated: 7 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;Last updated: 7 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 12:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5114306#M1112897</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-23T12:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115731#M1112966</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;After experimenting a bit on my own and discussing it with the TAC team, it seems PBR (w/o FlexConfig) will not be able to do what I need. What I am looking to do is to send low priority traffic (defined by ACL) out of a low performance interface as long as that interface has working L3/IP connectivity to a peer on the Internet.&lt;/P&gt;&lt;P&gt;In my case I would need PBR to recognize the "Remote peer reachable" path monitoring metric which it does not. None of the other metrics work for me because priority and order only fail over when L2 is down. MOS, jitter, RTT and packet loss are better on higher performance interfaces so those won't work either.&lt;/P&gt;&lt;P&gt;The TAC guys are still mulling it over but most likely I'll have to wait/hope the developers add this capability in the future.&amp;nbsp; I will have to stick with FlexConfig for now.&lt;/P&gt;&lt;P&gt;Below is sample output from path monitoring which shows the PM metrics for ISP2 in up state and no L3/IP state.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;gt; show path-monitoring&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Interface: inf_ISP1 (Ethernet1/1)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer: 8.8.8.8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Version: 10600&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer reachable: Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;RTT average: 3454 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Jitter: 92 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Packet loss: 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Last updated: 0 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Interface: inf_ISP2 (Ethernet1/3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer: 8.8.4.4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Version: 10600&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer reachable: Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;RTT average: 5079 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Jitter: 829 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Packet loss: 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Last updated: 0 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;gt; show path-monitoring&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Interface: inf_ISP1 (Ethernet1/1)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer: 8.8.8.8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Version: 10762&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer reachable: Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;RTT average: 3283 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Jitter: 89 microsecond(s)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Packet loss: 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;MOS: 4.40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Last updated: 5 second(s) ago&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Interface: inf_ISP2 (Ethernet1/3)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer: 33.44.55.66&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Version: 10762&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;Remote peer reachable: No&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;RTT average: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Jitter: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Packet loss: 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;MOS: 0.0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Last updated: 5 second(s) ago&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 16:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115731#M1112966</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-24T16:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115750#M1112967</link>
      <description>&lt;P&gt;From your previous output I notice peer reachability is NO and hence I think pbr not work'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We use usually in IOS use something solve this issue' by&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add new next-hop like 8.8.4.4&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add static route for this next-hop via same egress interface we use in set of pbr&lt;/P&gt;
&lt;P&gt;That solve issue make next-hop UP and path work.&lt;/P&gt;
&lt;P&gt;Try it&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;""Remote peer reachable: No""&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;MHM&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 16:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115750#M1112967</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-24T16:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115864#M1112968</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;peer reachability in my example is there by design.&amp;nbsp; I purposely used a bogus IP (33.44.55.66) in the path monitoring of the interface in order to simulate a L3/IP loss to the Internet.&amp;nbsp; That's how I tested and confirmed PBR on FMC (w/o FlexConfig) currently has no option for my use case.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 17:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115864#M1112968</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-24T17:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115890#M1112969</link>
      <description>&lt;P&gt;You use next-hop 8.8.8.8/8.8.4.4 or direct connect IP?&lt;/P&gt;
&lt;P&gt;Use direct connect IP not far multihops IP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 18:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5115890#M1112969</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-24T18:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5116592#M1113005</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;Thanks for the tip but I am not looking to fix the Remote Peer Reachable issue.&amp;nbsp; It will work fine if I use a valid IP.&amp;nbsp; I only did this to try to test if the PBR will recognize this and failover but unfortunately it does not recognize when remote peer reachable is no.&lt;/P&gt;</description>
      <pubDate>Sat, 25 May 2024 17:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5116592#M1113005</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2024-05-25T17:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: PBR verify availability track object on FMC 7.4</title>
      <link>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5116628#M1113006</link>
      <description>&lt;P&gt;But without next-hop reachability and using verify then pbr not work.&lt;/P&gt;
&lt;P&gt;Pbr is divide into&lt;/P&gt;
&lt;P&gt;Match acl or app&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The part of set is not correct or next-hop not reachable then all pbr will not work.&lt;/P&gt;
&lt;P&gt;Anyway' wait TAC answer and then compare them answer with my note.&lt;/P&gt;
&lt;P&gt;Goodluck in your task&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 25 May 2024 18:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-verify-availability-track-object-on-fmc-7-4/m-p/5116628#M1113006</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-25T18:44:20Z</dc:date>
    </item>
  </channel>
</rss>

