<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NOS VDX-6740 - PBR construct - how to? in Data Center (VDX)</title>
    <link>https://community.extremenetworks.com/t5/data-center-vdx/nos-vdx-6740-pbr-construct-how-to/m-p/81928#M523</link>
    <description>hi there,&lt;BR /&gt;
I cannot quite suss out the logic behind ACLs + PBR and am asking here hoping that someone can help.&lt;BR /&gt;
I have an ACL:&lt;BR /&gt;
&lt;BR /&gt;
ip access-list extended protect-VLANs&lt;BR /&gt;
 seq 10 permit ip host 192.168.2.144 any&lt;BR /&gt;
 seq 50 deny ip any 10.5.8.0 255.255.255.0&lt;BR /&gt;
 seq 51 deny ip any 10.5.7.0 255.255.255.0&lt;BR /&gt;
 seq 90 permit ip any any&lt;BR /&gt;
&lt;BR /&gt;
Now I go to PBR:&lt;BR /&gt;
&lt;BR /&gt;
Interface Ve VlanZ &lt;BR /&gt;
 ip policy route-map protect-vlans permit 10 (Active)&lt;BR /&gt;
 match ip address acl protect-VLANs &lt;BR /&gt;
 set ip vrf protect-vlans next-hop 192.168.2.199&lt;BR /&gt;
 set ip vrf protect-vlans next-hop 10.5.8.254&lt;BR /&gt;
 set interface null0 (selected)&lt;BR /&gt;
 Policy routing matches: 0 packets Note: No counters available&lt;BR /&gt;
&lt;BR /&gt;
VE's ip is 192.168.2.199 onto which protect-vlans PBR is applied.&lt;BR /&gt;
&lt;BR /&gt;
What I'm hoping to achieve is that only 192.168.2.144 could get to VLANs "behind" 192.168.2.199.&lt;BR /&gt;
But with above no node, not 192.168.2.144 can ping 10.5.8.0/24&lt;BR /&gt;
&lt;BR /&gt;
I'm failing to understand the logic here, obviously.</description>
    <pubDate>Thu, 21 Feb 2019 01:51:06 GMT</pubDate>
    <dc:creator>Pawel_Eljasz</dc:creator>
    <dc:date>2019-02-21T01:51:06Z</dc:date>
    <item>
      <title>NOS VDX-6740 - PBR construct - how to?</title>
      <link>https://community.extremenetworks.com/t5/data-center-vdx/nos-vdx-6740-pbr-construct-how-to/m-p/81928#M523</link>
      <description>hi there,&lt;BR /&gt;
I cannot quite suss out the logic behind ACLs + PBR and am asking here hoping that someone can help.&lt;BR /&gt;
I have an ACL:&lt;BR /&gt;
&lt;BR /&gt;
ip access-list extended protect-VLANs&lt;BR /&gt;
 seq 10 permit ip host 192.168.2.144 any&lt;BR /&gt;
 seq 50 deny ip any 10.5.8.0 255.255.255.0&lt;BR /&gt;
 seq 51 deny ip any 10.5.7.0 255.255.255.0&lt;BR /&gt;
 seq 90 permit ip any any&lt;BR /&gt;
&lt;BR /&gt;
Now I go to PBR:&lt;BR /&gt;
&lt;BR /&gt;
Interface Ve VlanZ &lt;BR /&gt;
 ip policy route-map protect-vlans permit 10 (Active)&lt;BR /&gt;
 match ip address acl protect-VLANs &lt;BR /&gt;
 set ip vrf protect-vlans next-hop 192.168.2.199&lt;BR /&gt;
 set ip vrf protect-vlans next-hop 10.5.8.254&lt;BR /&gt;
 set interface null0 (selected)&lt;BR /&gt;
 Policy routing matches: 0 packets Note: No counters available&lt;BR /&gt;
&lt;BR /&gt;
VE's ip is 192.168.2.199 onto which protect-vlans PBR is applied.&lt;BR /&gt;
&lt;BR /&gt;
What I'm hoping to achieve is that only 192.168.2.144 could get to VLANs "behind" 192.168.2.199.&lt;BR /&gt;
But with above no node, not 192.168.2.144 can ping 10.5.8.0/24&lt;BR /&gt;
&lt;BR /&gt;
I'm failing to understand the logic here, obviously.</description>
      <pubDate>Thu, 21 Feb 2019 01:51:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/data-center-vdx/nos-vdx-6740-pbr-construct-how-to/m-p/81928#M523</guid>
      <dc:creator>Pawel_Eljasz</dc:creator>
      <dc:date>2019-02-21T01:51:06Z</dc:date>
    </item>
  </channel>
</rss>

