Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi all I am trying to resolve an issue with some PBR on a Cisco 3850. Basically, i want to route internet traffic for one specific vlan to a new firewallI have created a test SVI (vlan 888 - 10.77.88.254/24) and i am matching traffic with a souce IP ...
HiI am about to undertake a project to migrate our core switches to new hardware and am keen to find out the best way of doing this.Currently we have 3 sites. A, B and C Site A, contains two Cisco 4506 switches that are end of life and are the ones s...
Hi all,I have set up a Cisco 887 router with ADSL and it trunked into a PoE switch so it can run 3 x cisco 321 AP's. I have 3 vlans set up..1 - IP 192.168.1.1151 IP 192.168.7.254152 IP 10.5.8.253I have vlan 152 set up on the PoE switch with an IP ad...
HiI have two WAP 321 devices set up in our building they are on the same subnet with the same SSID and are using the WDS bridge mode. My question is, if i enable mac-address filtering on one of these devices will this infomation be passed to the othe...
Hi Peter Managed to get to the bottom of this in the end. So the PBR was working (ip next-hop) but the ASA was dropping TCP packets as there was some asymmetric routing created by the PBR. I fixed this by using TCP state bypass for local addresses. T...
Thanks Peter. Yes, looks like it should. I think now that there is some kind of asymetric routing going on with the new firewall. There appears to me some messages in the syslog on there..
Ah - thats a pain. Ok, so i need to route internet traffic for one specific PC to our new firewall, 10.77.7.249. The reason for this is because theres 300 or so PCs in production using a different gateway for their internet traffic, if i change the l...
Understood, thanks Peter.I know its matching everything because i have a ping running from my PC to the test PC in vlan 888 and as soon as i apply the policy the ping drops. My PC is in another subnet. 10.20.1.0/24. If i do show ip route 10.20.1.0 on...
.. some additional info.I now have a ping running from a PC in vlan 888 to another PC in our subnet and i can see the policy routing matches increasing on every ping. Looks like everything is being policy routed - even traffic that the switch has a r...