Enhancement for Policy Based Routing
With IPSO 4.2, you can exert detailed control over
traffic forwarding by using
policy based routing (PBR). When you use PBR, you
create routing tables of
static routes and you direct traffic to the
appropriate tables by using an access
control list (ACL). Using an ACL in this way lets you
direct traffic flow by
filtering on one or more of the following:
�� Source address
�� Source mask length
�� Destination address
�� Destination mask length
�� Source port
�� Destination port
�� Protocol type
Combining PBR with Other Routing
You can use policy based routing in combination with
routing protocols or
static routes configured in the normal way. To set
this up, make sure that the
action of the last rule in your ACL is Accept. This
causes all packets that are
not forwarded using a PBR table to be forwarded
according to the standard
routing configuration.
If you employ a routing protocol that uses multicast
addresses to form
adjacencies (OSPF or RIP, for example), configure a
rule in the ACL with the
following settings:
�� Action: Accept
�� Src IP Addr: 0.0.0.0
�� Dest IP Addr 224.0.0.0
�� Dest Mask Len: 4
This rule should be next to last in the ACL.
You cannot use PBR to route locally destined packets,
locally originated
packets, multicast packets, or broadcast packets. You
can configure an ACL
rule to match this traffic, but the traffic will not
be forwarded by a PBR table.

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to