Use FlexConfig to configure PBR on FTD

Scenario:

Request specified server to use backup Internet link Outside2 to access Internet

 

1. Create extended ACL to match source IP











2. Create a route-map, match the created ACL, but this route-map Set Clause doesn't have option to specify next hop, we will do it in FlexConfig Object.








3. Create FlexConfig Object, Insert Policy Object Route Map variable, select the created route map, 

































4. Edit the FlexConfig Object, make sure the Sequence No is one in step 2, here we can set next hop.




















5. Create FlexConfig Polily, refer the FlexConfig Object.














if delete this PBR FlexConfig Object from the list, deploy will fail and shows error, so it needs stay there.

FMC >> no route-map RouteMap-PBR permit 1
Local-FTD >> error : ERROR: route-map RouteMap-PBR is attached to routing protocols
(EIGRP/RIP/OSPF/BGP/ISIS) or used in policy based routing.
Please remove the relevant configuration before removing the route_map
Config Error -- no route-map RouteMap-PBR permit 1


Comments

Popular posts from this blog

Firepower FMC and FTD troubleshooting

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.