HP VPN Firewall Appliances Network Management Configuration Guide

551
Ste
p
Command
Remarks
2. Enter policy node view.
policy-based-route policy-name [ deny |
permit ] node node-number
N/A
3. Configure an ACL match
criterion.
if-match acl acl-number Optional.
4. Configure a packet length
match criterion.
if-match packet-length min-len max-len Optional.
Configuring actions for a node
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter policy node view.
policy-based-route policy-name [ deny |
permit ] node node-number
N/A
3. Set an IP precedence.
apply ip-precedence value Optional.
4. Set output interfaces.
apply output-interface interface-type
interface-number [ track
track-entry-number ] [ interface-type
interface-number [ track
track-entry-number ] ]
Optional.
You can specify up to two output
interfaces to achieve load sharing.
5. Set next hops.
apply ip-address next-hop ip-address
[ direct ] [ track track-entry-number ]
[ ip-address [ direct ] [ track
track-entry-number ] ]
Optional.
You can specify up to two next
hops to achieve load sharing.
6. Set default output
interfaces.
apply default output-interface
interface-type interface-number [ track
track-entry-number ] [ interface-type
interface-number [ track
track-entry-number ] ]
Optional.
You can specify up to two default
output interfaces to achieve load
sharing.
7. Set default next hops.
apply ip-address default next-hop
ip-address [ track track-entry-number ]
[ ip-address [ track track-entry-number ] ]
Optional.
You can specify up to two default
next hops to achieve load sharing.
Configuring PBR
Configuring local PBR
Configure PBR by applying a policy locally. PBR uses the policy to guide the forwarding of locally
generated packets.
You can apply only one policy locally. If you perform the ip local policy-based-route command multiple
times, only the last specified policy takes effect.
If the specified policy does not exist, the local PBR configuration succeeds, but it does not take effect until
the policy is created.
Do not configure local PBR unless required.
To configure local PBR: