03-02-2022 10:21 AM
filter acl ace 1 1 name "No-PBR-for-IPMC"
filter acl ace action 1 1 permit count
filter acl ace ethernet 1 1 ether-type eq ip
filter acl ace ip 1 1 dst-ip mask 224.0.0.0 31.255.255.255
filter acl ace 1 1 enable
filter acl ace 1 999 name "Rest-force-PBR-to-FW"
filter acl ace action 1 999 permit redirect-next-hop 172.16.0.250 vrf red unreachable deny count
filter acl ace ethernet 1 999 ether-type eq ip
filter acl ace 1 999 enable
However, I'm running 8.4.1 and up on my VSP's and I'm wondering if this will work instead with the new routed-only option? Is ace 1 still needed? I'm primarily concerned about VRRP and other IP multicast applications.
filter acl ace 1 999 name "Rest-force-PBR-to-FW"
filter acl ace action 1 999 permit redirect-next-hop 172.16.0.250 vrf red unreachable deny count
filter acl ace ethernet 1 999 ether-type eq ip
filter acl ace ip 1 999 routed-only
filter acl ace 1 999 enable
Solved! Go to Solution.
03-03-2022 02:57 AM
03-03-2022 08:41 AM
03-03-2022 02:57 AM