PBR on vlan interface

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2015 10:22 PM - edited 03-08-2019 12:11 AM
hi all,
i have this diagram in attachment. the core sw is doing pbr for both users in vlan 100 and vlan 200 and set the ip next hop to firewalls' int 1.
is it normal for the laptop 1 with ip address in vlan 100 to ping interface vlan 200? if yes, then the pbr does not take precedence if the destination traffic is local on the core sw?
thanks
- Labels:
-
LAN Switching

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2015 10:55 PM
If your laptop default GW is core switch vlan 100 IP address, then its normal, provided you core switch is configred for "ip routing"
If you want to filter in-between vlan100 and vlan 200 via FW, then you need to create the SVI of vlan 100 and vlan 200 on FW and give its IP as the GW for laptops.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-02-2015 10:17 AM
Posts in this discussion have been modified due to possible misconduct. Please refer to the CSC terms of use for more details.
