I am trying to do policy based routing with route-map, it is working fine on the way of the packet except at the end when the vasi interface pair comes into.
The packet lands on vasileft interface which is in a vrf and the packet should go to a subinterface which is in the same vrf. This works just fine when normal routing is in place, but if I would like to route with route-map it is not working. The packet turns back to vasiright.
Could you please advise why?
I have the following configuration
vrf forwarding ***
ip address X.X.X.5 255.255.255.252
ip policy route-map DMVPN-INTERNET3
vrf forwarding ***INSIDE
ip address X.X.X.6 255.255.255.252
route-map DMVPN-INTERNET3 permit 10
match ip address ROUTE-INTERNET
set ip vrf **** next-hop X.X.20.249
ip access-list extended ROUTE-INTERNET
deny ip X.X.21.0 0.0.0.255 10.0.0.0 0.255.255.255
deny ip X.X.21.0 0.0.0.255 192.0.0.0 0.255.255.255
deny ip X.X.21.0 0.0.0.255 22.214.171.124 0.255.255.255
permit ip X.X.21.0 0.0.0.255 any
Basicly what I would like to achieve is that all the traffic has to go to X.X.20.249.
Is there a limitation for policy based routing on vasi interface?
(Pdf copy at the bottom)
Segmentation within SD-Access is enabled through the combined use of both Virtual Networks (VN), which are analogous to VRFs, and Cisco Scalable Group Tags (SGTs). VNs, like VRFs, provide comp...
The 2020 IT Blog Awards, hosted by Cisco, is now open for submissions through October 16. Submit your blog, vlog or podcast today. For more information, including category details, the process, past winners and FAQs, check out: https://www.cisco...
Hello,We have a pair of N3K-3064PQ-10GX and one of them acting as backup and we want to migrate from VyOS to it, we want to add 500x interface vlan and each interface vlan has its own ip/prefixes (for example /30 /29 ...) and we ahve 6-8x BGP session with...
We live in an age that is both thrilling and evolving substantially. A new trend/technology is always on rise even before the preceding has been used to its fullest potential. Although the concepts of digital transformation may seem over discussed, ...
Show CommandPurposeCiscoICX-RuckusShow Spanning tree infoShow spanning-treeshow 802-1wVerify Port-Channel / Link aggregation infosh lag briefsh etherchannel summaryShow CDC/LDP neighbor infoshow cdp neighbors detailsh lldp neighbors de sh mac a...