cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
887
Views
5
Helpful
6
Replies

FPR PBR for inbound traffic

Vishnu_RR
Level 1
Level 1

Hi team,

 

we have a plan to migrate some of the subnets from FPR to the next hop(from Radware to F5). I have doubt that if I create PBR that will work nicely for outbound traffic but I am not sure for inbound traffic. Please let me know any solution or any info on this.

6 Replies 6

Hi

  Which devices we are talking about and version?  A simple topology also helps.

balaji.bandi
Hall of Fame
Hall of Fame

PBR should work as expected for inbound,  make sure outbound also taken care.

 

Most cases we do static NAT right, can you should some example of your setup ? and goal ?

 

This required some testings, make sure the flows works as expected.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Vishnu_RR
Level 1
Level 1

Hi,

 

We are using FMC 2600 in HA with version 6.6.5, and FTD 4125 in HA. version 6.6.4. We configured the Flexconfig for outbound traffic towards F5.

we have a default route towards Radware 10.10.10.4.

The outbound traffic is working fine for some of the  LAN subnets towards F5 10.10.10.9 using Flexconfig.

we do not use NAT at Firewall. we will configure NAT at F5 itself. we have some servers which require inbound traffic also. If i configure flexconfig for outbound traffic to DMZ servers, does inbound work or not that I am not sure.PBR inbound traffic cisco community.png

Hello

With PBR you will usually incur asymmetric traffic paths if the PBR'd traffic next hop device has a different default egress path other then the ingress path it is receiving from the policy routed traffic.

 

 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

In your case PBR must be applied in LAN interface for LAN Server A to force route traffic to Nexthop A for outbound internet access, In this scenario if a fresh inbound connection received at FPR through WAN interface the traffic will be forwarded LAN server A and when the return traffic hits the FPR in LAN interface it will not match in the PBR but take the default route and forwarded to Nexthop B.

 

I have experienced the same issue in past and understood from team that PBR meant for initiated traffic. 

Vishnu_RR
Level 1
Level 1

Hi team,

 

Any confirmation on this ? @balaji.bandi could you confirm this, please.

Review Cisco Networking for a $25 gift card