R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
536
Reply from 1.1.3.2: bytes=56 Sequence=3 ttl=255 time=1 ms
Reply from 1.1.3.2: bytes=56 Sequence=4 ttl=255 time=1 ms
Reply from 1.1.3.2: bytes=56 Sequence=5 ttl=255 time=1 ms
--- 1.1.3.2 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/1/2 ms
Telnet uses TCP, and ping uses ICMP. The preceding results show that all TCP packets of Firewall
are forwarded via GigabitEthernet 0/1, and other packets are forwarded via GigabitEthernet
0/2. The PBR configuration is effective.
Configuring interface PBR based on packet type at the CLI
Network requirements
As shown in Figure 311, configure PBR on Firewall, so that TCP packets arriving on GigabitEthernet 0/1
are forwarded via GigabitEthernet 0/2 and other packets are forwarded according to the routing table.
Figure 311 Network diagram
Configuration procedure
NOTE:
In this example, static routes are configured to ensure the reachability among devices.
1. Configure Firewall.
# Define ACL 3101 to match TCP packets.
Firewall
GE0/1
10.110.0.10/24
GE0/2
1.1.2.1/24
GE0/3
1.1.3.1/24
Subnet
10.110.0.0/24
GE0/1
1.1.2.2/24
GE0/1
1.1.3.2/24
Router B Router A
Host A Host B
10.110.0.20/24
Gateway: 10.110.0.10