cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
2
Replies

PBR on vlan interface

SirEna
Level 1
Level 1

hi all,

 

i have this diagram in attachment. the core sw is doing pbr for both users in vlan 100 and vlan 200 and set the ip next hop to firewalls' int 1.

is it normal for the laptop 1 with ip address in vlan 100 to ping interface vlan 200? if yes, then the pbr does not  take precedence if the destination traffic is local on the core sw? 

 

thanks

 

                                                            

2 Replies 2

If your laptop default GW is core switch vlan 100 IP address, then its normal, provided you core switch is configred for "ip routing"

If you want to filter in-between vlan100 and vlan 200 via FW, then you need to create the SVI of vlan 100 and vlan 200 on FW and give its IP as the GW for laptops.

rosaho
Level 3
Level 3

Posts in this discussion have been modified due to possible misconduct. Please refer to the CSC terms of use for more details. 

Review Cisco Networking for a $25 gift card