目录
一、实验需求:
- 流量如图所示:
- AR2->AR1(150.1.1.1/32)的流量路径:AR2->S1->AR2,AR1(150.1.1.1/32)->AR2的流量路径:AR1->S1->FW1->S1->AR2;其中经过防火墙的ping和ssh流量关闭状态检测,其余流量不关闭状态检测。
二、关键配置:
-
交换机MQC配置如下:
acl number 3000
rule 5 permit ip source 150.1.1.1 0
#
traffic classifier PBR operator and
if-match acl 3000
#
traffic behavior PBR
redirect ip-nexthop 10.1.3.12
#
traffic policy PBR
classifier PBR behavior PBR
#
interface GigabitEthernet0/0/