Policy Based Routing on Cisco L3 Switch 3550 with IOS 12.1(22)

Discussion in 'Cisco' started by Al, Apr 30, 2008.

  1. Al

    Al Guest

    Hi all,

    I have a 3550 L3 switch and I am trying to implement policy based
    routing. My setup is as follows:

    PC1
    |
    |
    |
    Switch 3550------- Appliance 1
    | \
    | \
    | \
    Firewall1 Firewall 2
    | |
    | |
    VPN 1 VPN 2
    | |
    | |
    |__Firewall 3__|
    |
    |
    |
    PC3


    Currently, the switch sends all traffic bound for PC2 through Firewall
    1

    I want traffic from Appliance 1 going to PC2 to pass through Firewall
    2 instead.

    To do this, I went into the Switch config and added the following:

    access-list 123 permit ip y.y.y.y 0.0.0.255 x.x.x.x 0.0.0.255
    route-map test_map permit 10
    match ip address 123
    set ip next-hop 192.168.0.1 (IP of inside interface of Firewall 2)
    int vlan1
    ip policy route-map test_map

    As far as I can tell, It's set up according to examples in Cisco
    documentation, but doesn't work. Can anyone see something I missed?

    Thanks.

    Al
     
    Al, Apr 30, 2008
    #1
    1. Advertisements

  2. Al

    Bod43 Guest

    http://www.cisco.com/en/US/tech/tk364/technologies_configuration_example09186a00802135d3.shtml
    Policy Routing with Catalyst 3550 Series Switch Configuration Example

    "You must modify the SDM template, such that it supports the 144-bit
    Layer 3 TCAM"

    Get that bit?
     
    Bod43, Apr 30, 2008
    #2
    1. Advertisements

  3. Al

    Al Guest

    I performed this step at the very beginning... After logging into the
    switch I entered the command:

    sdm prefered routing

    I then rebooted the switch. Once the switch reloaded, I entered the
    Access-list, route-maps, etc. When I do a show sdm prefered, the IOS
    confirms the current template is the Routing Template.

    Al.
     
    Al, May 1, 2008
    #3
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.