Enhancement for Policy Based Routing With IPSO 4.2, you can exert detailed control over traffic forwarding by using policy based routing (PBR). When you use PBR, you create routing tables of static routes and you direct traffic to the appropriate tables by using an access control list (ACL). Using an ACL in this way lets you direct traffic flow by filtering on one or more of the following: �� Source address �� Source mask length �� Destination address �� Destination mask length �� Source port �� Destination port �� Protocol type Combining PBR with Other Routing You can use policy based routing in combination with routing protocols or static routes configured in the normal way. To set this up, make sure that the action of the last rule in your ACL is Accept. This causes all packets that are not forwarded using a PBR table to be forwarded according to the standard routing configuration. If you employ a routing protocol that uses multicast addresses to form adjacencies (OSPF or RIP, for example), configure a rule in the ACL with the following settings: �� Action: Accept �� Src IP Addr: 0.0.0.0 �� Dest IP Addr 224.0.0.0 �� Dest Mask Len: 4 This rule should be next to last in the ACL. You cannot use PBR to route locally destined packets, locally originated packets, multicast packets, or broadcast packets. You can configure an ACL rule to match this traffic, but the traffic will not be forwarded by a PBR table.
Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
