<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5 in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56681#M16629</link>
    <description>Create Date: Sep 12 2012  2:27PM&lt;BR /&gt;
&lt;BR /&gt;
Hi Prusso,&lt;BR /&gt;
&lt;BR /&gt;
I am testing it with ICMP, but I want all traffic to be redirected.&lt;BR /&gt;
&lt;BR /&gt;
And none of my traffic is getting redirected. I have tried the count  as well but the counter is not incrementing&lt;BR /&gt;
implying that the policy never gets hit.&lt;BR /&gt;
&lt;BR /&gt;
Br,&lt;BR /&gt;
./emuzkhn  (from Muhammad_Khan)</description>
    <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
    <dc:creator>EtherNation_Use</dc:creator>
    <dc:date>2014-01-08T05:55:00Z</dc:date>
    <item>
      <title>Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56676#M16624</link>
      <description>Create Date: Sep 12 2012  8:53AM&lt;BR /&gt;
&lt;BR /&gt;
Hi all,&lt;BR /&gt;
&lt;BR /&gt;
I am facing a very simple redirection problem while using my Policy based redirect on the Switch.&lt;BR /&gt;
&lt;BR /&gt;
I have a dynamic policy defined for redirection as below on my Switch. And I apply it as ANY on the switch.&lt;BR /&gt;
&lt;BR /&gt;
###########################################################################################################################&lt;BR /&gt;
(vr VR-SIG) CH-SW1.11 # show configuration acl&lt;BR /&gt;
#&lt;BR /&gt;
# Module acl configuration.&lt;BR /&gt;
#&lt;BR /&gt;
create access-list sctp_int_1_flow " source-address 10.91.0.48/28 ;" " redirect 10.91.0.234 ;" application "Cli"&lt;BR /&gt;
&lt;BR /&gt;
configure access-list add sctp_int_1_flow last priority 0 zone SYSTEM any ingress&lt;BR /&gt;
&lt;BR /&gt;
(vr VR-SIG) CH-SW1.15 # show access-list any detail&lt;BR /&gt;
#Dynamic Entries ((*)- Rule is non-permanent )&lt;BR /&gt;
# RuleNo Application Zone Sub-Zone&lt;BR /&gt;
# 9 Cli SYSTEM 0&lt;BR /&gt;
entry sctp_int_1_flow { if match all {&lt;BR /&gt;
source-address 10.91.0.48/28 ;&lt;BR /&gt;
} then {&lt;BR /&gt;
redirect 10.91.0.234 ;&lt;BR /&gt;
} }&lt;BR /&gt;
&lt;BR /&gt;
#########################################################################################&lt;BR /&gt;
&lt;BR /&gt;
But My redirection is not working. &lt;BR /&gt;
&lt;BR /&gt;
(vr VR-SIG) CH-SW1.13 # ping 10.91.0.100 from 10.91.0.62 with record-route&lt;BR /&gt;
Ping(ICMP) 10.91.0.100: 4 packets, 8 data bytes, interval 1 second(s).&lt;BR /&gt;
16 bytes from 10.91.0.100: icmp_seq=1 ttl=255 time=7.668 ms&lt;BR /&gt;
RR: 10.91.0.62&lt;BR /&gt;
10.91.0.101&lt;BR /&gt;
10.91.0.62&lt;BR /&gt;
&lt;BR /&gt;
I would expect the ICMP packet coming with source-address 10.91.0.62 to hit the Policy and redirect the traffic to 10.91.0.234 instead as the route-record shows that the traffic is redirected to 10.91.0.101 - where I do not want my traffic to flow.&lt;BR /&gt;
&lt;BR /&gt;
It looks to me that for some reason my policy is not active. &lt;BR /&gt;
&lt;BR /&gt;
Any help will be appreciated.&lt;BR /&gt;
&lt;BR /&gt;
Thank you,&lt;BR /&gt;
&lt;BR /&gt;
./emuzkhn   (from Muhammad_Khan)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56676#M16624</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56677#M16625</link>
      <description>Create Date: Sep 12 2012 12:19PM&lt;BR /&gt;
&lt;BR /&gt;
Hi emuzkhn, &lt;BR /&gt;
&lt;BR /&gt;
maybe you can try something like in:&lt;BR /&gt;
Concept Guide -&amp;gt;Policy-Based Redirection Redundancy -&amp;gt; Packet Forward/Drop&lt;BR /&gt;
(http://www.extremenetworks.com/services/software-userguide-archives.aspx)&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek  (from Jaroslaw_Kasjaniuk)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56677#M16625</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56678#M16626</link>
      <description>Create Date: Sep 12 2012  1:27PM&lt;BR /&gt;
&lt;BR /&gt;
Hi Jarek,&lt;BR /&gt;
&lt;BR /&gt;
We are not looking in to next hop redundancy. I want a simple redirection of one plain traffic. I would be looking forward to solution with plain L3 - Policy based redirect.&lt;BR /&gt;
&lt;BR /&gt;
Any help in this regards will be highly appreciable.&lt;BR /&gt;
&lt;BR /&gt;
Thank you,&lt;BR /&gt;
&lt;BR /&gt;
./emuzkhn  (from Muhammad_Khan)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56678#M16626</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56679#M16627</link>
      <description>Create Date: Sep 12 2012  1:32PM&lt;BR /&gt;
&lt;BR /&gt;
Also one more thing to add - My policy is not even getting a hit..   (from Muhammad_Khan)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56679#M16627</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56680#M16628</link>
      <description>Create Date: Sep 12 2012  1:57PM&lt;BR /&gt;
&lt;BR /&gt;
Hello emuzkhnIs this not working for ICMP traffic only or are you noticing that all IP traffic is not being redirected?  Do you have any static policies configured?I would add a count statement to the ACL and also try it with a protocol statement for ICMP traffic in addition to the IP subnet that you have and see if that gets any hits using the count option as well.Let me know what you find out.P  (from Paul_Russo)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56680#M16628</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56681#M16629</link>
      <description>Create Date: Sep 12 2012  2:27PM&lt;BR /&gt;
&lt;BR /&gt;
Hi Prusso,&lt;BR /&gt;
&lt;BR /&gt;
I am testing it with ICMP, but I want all traffic to be redirected.&lt;BR /&gt;
&lt;BR /&gt;
And none of my traffic is getting redirected. I have tried the count  as well but the counter is not incrementing&lt;BR /&gt;
implying that the policy never gets hit.&lt;BR /&gt;
&lt;BR /&gt;
Br,&lt;BR /&gt;
./emuzkhn  (from Muhammad_Khan)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56681#M16629</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56682#M16630</link>
      <description>Create Date: Sep 12 2012  2:28PM&lt;BR /&gt;
&lt;BR /&gt;
Hi Prusso,&lt;BR /&gt;
&lt;BR /&gt;
I am testing it with ICMP, but I want all traffic to be redirected for the subnet.&lt;BR /&gt;
&lt;BR /&gt;
And none of my traffic is getting redirected for this subnet. I have tried the count  as well but the counter is not incrementing&lt;BR /&gt;
implying that the policy never gets hit.&lt;BR /&gt;
&lt;BR /&gt;
Br,&lt;BR /&gt;
./emuzkhn  (from Muhammad_Khan)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56682#M16630</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56683#M16631</link>
      <description>Create Date: Sep 13 2012 11:12AM&lt;BR /&gt;
&lt;BR /&gt;
Hi, &lt;BR /&gt;
&lt;BR /&gt;
ok that was an example how can you do this.&lt;BR /&gt;
&lt;BR /&gt;
An example.&lt;BR /&gt;
 We want to redirect all traffic from 10.91.0.48/28 to address 10.91.0.234&lt;BR /&gt;
&lt;BR /&gt;
create flow-redirect redir1&lt;BR /&gt;
configure flow-redirect redir1 add nexthop 10.91.0.234 priority 100&lt;BR /&gt;
configure flow-redirect redir1 nexthop 10.91.0.234 ping health-check interval 60 miss 3&lt;BR /&gt;
&lt;BR /&gt;
Create an ACL:&lt;BR /&gt;
entry subnet1 {&lt;BR /&gt;
if match all {&lt;BR /&gt;
 source-address 10.91.0.48/28 ;&lt;BR /&gt;
} then {&lt;BR /&gt;
 permit;&lt;BR /&gt;
 redirect-name redir1;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
&lt;BR /&gt;
configure access-list redir1 vlan "vlan_name" ingress&lt;BR /&gt;
&lt;BR /&gt;
That will redirect traffic in this vlan only from subnet 10.91.0.48/28 to 10.91.0.234.&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek  (from Jaroslaw_Kasjaniuk)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56683#M16631</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Help required for L3 - Policy Based Redirect. Summit x460-24t, ExOS 12.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56684#M16632</link>
      <description>Create Date: Sep 13 2012  1:34PM&lt;BR /&gt;
&lt;BR /&gt;
Hi Jarek,&lt;BR /&gt;
&lt;BR /&gt;
I tried the suggested but it did not work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
(vr VR-SIG) CH-SW1.69 # show vlan "SCTP_INT_1"&lt;BR /&gt;
VLAN Interface with name SCTP_INT_1 created by user&lt;BR /&gt;
        Admin State:    Enabled         Tagging:        802.1Q Tag 844&lt;BR /&gt;
        Virtual router: VR-SIG&lt;BR /&gt;
        IPv4 Forwarding: Enabled&lt;BR /&gt;
        Primary IP    : 10.91.0.62/28&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
(vr VR-SIG) CH-SW1.65 # show configuration acl&lt;BR /&gt;
#&lt;BR /&gt;
# Module acl configuration.&lt;BR /&gt;
#&lt;BR /&gt;
create flow-redirect redir1&lt;BR /&gt;
configure flow-redirect redir1 vr VR-SIG&lt;BR /&gt;
configure flow-redirect redir1 health-check ping&lt;BR /&gt;
configure flow-redirect redir1 no-active forward&lt;BR /&gt;
configure flow-redirect redir1 add nexthop 10.91.0.234 priority 200&lt;BR /&gt;
configure flow-redirect redir1 nexthop 10.91.0.234 ping health-check interval 60 miss 3&lt;BR /&gt;
configure access-list redir1 vlan "SCTP_INT_1" ingress&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
(vr VR-SIG) CH-SW1.67 # edit policy redir1&lt;BR /&gt;
entry subnet1 {&lt;BR /&gt;
if match all {&lt;BR /&gt;
source-address 10.91.0.48/28 ;&lt;BR /&gt;
} then {&lt;BR /&gt;
permit;&lt;BR /&gt;
redirect-name redir1;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
&lt;BR /&gt;
Now I am trying to generate traffic from another machine connected directly to the switch on an untagged port from an IP address of subnet 10.91.0.48/28 and VLAN SCTP_INT_1&lt;BR /&gt;
&lt;BR /&gt;
[emuzkhn@radius1 ~]$ traceroute -s 10.91.0.54 10.91.0.100&lt;BR /&gt;
traceroute to 10.91.0.100 (10.91.0.100) from 10.91.0.54, 64 hops max, 40 byte packets&lt;BR /&gt;
 1  10.91.0.62 (10.91.0.62)  1.1 ms  0.653 ms  0.599 ms&lt;BR /&gt;
 2  10.91.0.101 (10.91.0.101)  0.622 ms *  0.621 ms&lt;BR /&gt;
[emuzkhn@radius1 ~]$&lt;BR /&gt;
[emuzkhn@radius1 ~]$&lt;BR /&gt;
[emuzkhn@radius1 ~]$&lt;BR /&gt;
[emuzkhn@radius1 ~]$&lt;BR /&gt;
[emuzkhn@radius1 ~]$ ping 10.91.0.100&lt;BR /&gt;
PING 10.91.0.100 (10.91.0.100): 56 data bytes&lt;BR /&gt;
64 bytes from 10.91.0.100: icmp_seq=0 ttl=254 time=0.599 ms&lt;BR /&gt;
64 bytes from 10.91.0.100: icmp_seq=1 ttl=254 time=0.462 ms&lt;BR /&gt;
64 bytes from 10.91.0.100: icmp_seq=2 ttl=254 time=0.885 ms&lt;BR /&gt;
64 bytes from 10.91.0.100: icmp_seq=3 ttl=254 time=0.489 ms&lt;BR /&gt;
--- 10.91.0.100 ping statistics ---&lt;BR /&gt;
4 packets transmitted, 4 packets received, 0.0% packet loss&lt;BR /&gt;
round-trip min/avg/max/std-dev = 0.462/0.608/0.885/0.170 ms&lt;BR /&gt;
[emuzkhn@radius1 ~]$&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Switch does not redirect the traffic and instead uses the standard routing table on the swtich to route the traffic.&lt;BR /&gt;
&lt;BR /&gt;
Any more suggestions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
./rameez  (from Muhammad_Khan)</description>
      <pubDate>Wed, 08 Jan 2014 05:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/help-required-for-l3-policy-based-redirect-summit-x460-24t-exos/m-p/56684#M16632</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:55:00Z</dc:date>
    </item>
  </channel>
</rss>

