<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Flex configuration for PBR in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274899#M1120270</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am looking to use flex configuration to push a subnet traffic down a 3 VTI tunnels in ECMP.&lt;/P&gt;&lt;P&gt;I am wanting the traffic to be load balanced or round robin. How is this achievable if each VTI has a different tunnel IP.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Mar 2025 11:48:43 GMT</pubDate>
    <dc:creator>NetworkMonkey101</dc:creator>
    <dc:date>2025-03-25T11:48:43Z</dc:date>
    <item>
      <title>Using Flex configuration for PBR</title>
      <link>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274899#M1120270</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am looking to use flex configuration to push a subnet traffic down a 3 VTI tunnels in ECMP.&lt;/P&gt;&lt;P&gt;I am wanting the traffic to be load balanced or round robin. How is this achievable if each VTI has a different tunnel IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 11:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274899#M1120270</guid>
      <dc:creator>NetworkMonkey101</dc:creator>
      <dc:date>2025-03-25T11:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Using Flex configuration for PBR</title>
      <link>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274906#M1120271</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1495947"&gt;@NetworkMonkey101&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By configuring dynamic routing you could achieve ECMP load balancing over the three VTI.&lt;/P&gt;
&lt;P class="" data-start="0" data-end="661"&gt;When using a dynamic routing protocole, the router learn multiple routes to the same destination via the three VTIs. If these routes have the same cost (ospf) or feasible distance (eigrp), the router installs all of them in the routing table, allowing CEF to distribute traffic across them.&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="663" data-end="1199"&gt;=&amp;gt; By default, CEF performs per-destination load balancing, meaning packets from the same flow always take the same path. However, CEF can also be configured for per-packet load balancing, ensuring a round-robin distribution across all tunnels.&lt;/P&gt;
&lt;P class="" data-start="663" data-end="1199"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios/12_4t/ip_switch/configuration/guide/tceflbs.html#wp1046328" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/ios/12_4t/ip_switch/configuration/guide/tceflbs.html#wp1046328&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 11:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274906#M1120271</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2025-03-25T11:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using Flex configuration for PBR</title>
      <link>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274945#M1120274</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1495947"&gt;@NetworkMonkey101&lt;/a&gt; FTD uses traffic zone for ECMP. You associate VTI interfaces with ECMP zones and configure ECMP static routes to achieve the following:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Load balancing (Active/Active VTIs)—Connection can flow over any of the parallel VTI tunnels.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/760/management-center-device-config-76/vpn-s2s.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/760/management-center-device-config-76/vpn-s2s.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 14:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/using-flex-configuration-for-pbr/m-p/5274945#M1120274</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-03-25T14:22:23Z</dc:date>
    </item>
  </channel>
</rss>

