12-21-2009 02:09 PM - edited 03-04-2019 07:02 AM
Hi everybody,
I was brought in last minute on a migration project where I discovered the first phase of the project is to move a subset of servers to a new location. The new location will eventually receive all of the servers currently in this subnet, 10.80.3.X/24, but for a short time there will be servers in two locations with the same subnet address. Fortunately, the servers that are moving are only accessed by a handful of other machines. I was wondering if PBR will solve my problem here, and if so, if my hardware can support it. I have two 6509's w/Sup720 with PFC3A.
My first idea is to create an access-list for servers that will be accessing the devices that are moving, then use a route-map to set the next hop for these devices to be the firewall (WAN connectivity is still being built out, so I'm using an IPsec tunnel between two ASA's for now).
Will this work?
Thanks in advance,
Brandon
Solved! Go to Solution.
12-22-2009 05:26 PM
branfarm1 wrote:
I hear ya -- I spend 99% of my time changing firewall configs -- not writing acl's for switches.
I can't remember -- do switches/router always use wildcard masks, or only sometimes?
For acls they always use wildcard masks.
One other thing. Don't be surprised if you don't see hits against the acls in your route-maps because PBR is done in hardware on the 6500 and acls are not incremented when processed in hardware.
Jon
12-22-2009 05:28 PM
Thanks for that -- I need to write myself a reminder about wildcard vs standard masks.
Thanks for all your help -- you're a lifesaver.
Happy holidays!
Brandon
12-22-2009 05:33 PM
branfarm1 wrote:
Thanks for that -- I need to write myself a reminder about wildcard vs standard masks.
Thanks for all your help -- you're a lifesaver.
Happy holidays!
Brandon
Brandon
No problem, glad to have helped.
Happy holidays to you as well.
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide