Home > Policy Based Routing Sim

Policy Based Routing Sim

May 8th, 2014 in Lab Sim, LabSim Go to comments

Question

Company TUT has two links to the Internet. The company policy requires that web traffic must be forwarded only to Frame Relay link if available and other traffic can go through any links. No static or default routing is allowed.

BGP_Policy_Based_Routing_Sim.jpg

 

Answer and Explanation:

Notice: The answer and explanation below are from PeterPan and Helper.Please say thank to them!

All the HTTP traffic from the EIGRP Network should go through Frame Relay link if available and all the other traffic should go through either link.
The only router you are able to administrate is the Border Router, from the EIGRP Network you may only send HTTP traffic. As the other people mentioned, actually it is not a BGP lab. You are not able to execute the command “router bgp 65001”

1) Access list that catches the HTTP traffic:
BorderRouter(config)#access-list 101 permit tcp any any eq www

Note that the server was not directly connected to the Border Router. There were a lot of EIGRP routes on it. In the real exam you do not know the exact IP address of the server in the EIGRP network so we have to use the source as “any” to catch all the source addresses.

2) Route map that sets the next hop address to be ISP1 and permits the rest of the traffic:
BorderRouter(config)#route-map pbr permit 10
BorderRouter(config-route-map)#match ip address 101
BorderRouter(config-route-map)#set ip next-hop 10.1.101.1
BorderRouter(config-route-map)#exit

(Update: We don’t need the last command route-map pbr permit 20 to permit other traffic according to Cisco:

“If the packets do not meet any of the defined match criteria (that is, if the packets fall off the end of a route map), then those packets are routed through the normal destination-based routing process. If it is desired not to revert to normal forwarding and to drop the packets that do not match the specified criteria, then interface Null 0 should be specified as the last interface in the list by using the set clause.”

Reference: http://www.cisco.com/en/US/products/ps6599/products_white_paper09186a00800a4409.shtml)

3) Apply the route-map on the interface to the server in the EIGRP Network:
BorderRouter(config-route-map)#exit
BorderRouter(config)#int fa0/0
BorderRouter(config-if)#ip policy route-map pbr
BorderRouter(config-if)#exit
BorderRouter(config)#exit

4) There is a “Host for Testing”, click on this host to open a box in which there is a button named “Generate HTTP traffic”. Click on this button to generate some packets for HTTP traffic. Jump back to the BorderRouter and type the command “show route-map”.

BorderRouter#show route-map

In the output you will see the line “Policy routing matches: 9 packets…”. It means that the route-map we configured is working properly.

Note: We have posted a Policy Based Routing lab on GNS3 similar to this sim with detailed explanation, you can read it here.

Other lab-sims on this site:

EIGRP Stub Sim

OSPF Sim

EIGRP OSPF Redistribution Sim

IPv6 OSPF Virtual Link Sim

EIGRP Simlet

Comments
Comment pages
1 14 15 16 28
  1. Exam collection
    October 24th, 2016

    Which site can we get Cisco dumps as they were removed from exam collection

  2. DA
    October 24th, 2016

    @ OR….Ok, looking forward for the update

  3. Mick
    October 25th, 2016

    OR, waiting for your feedback :)

  4. OR
    October 25th, 2016

    I will share it in “share your ROUTE experience” section

  5. youssef
    October 26th, 2016

    Please could anyone send valid October 2016 300 -101 dumps to youssemerroun33(at)gmail(dot)com Thanks a lot.

  6. ashraf4y
    October 27th, 2016

    Hey all people please what is five simulations to the current Route exam

  7. LAURA
    October 27th, 2016

    Passed my 300-101 Exam with the help of pass4sure dumps, thanks to http://pass4surekey.com/exam/300-101.html they have most updated dumps.

  8. ayoshinin
    October 27th, 2016

    Laura, please can u send the dumps you use to my email {email not allowed}. please help me out.

  9. IQ
    October 27th, 2016

    Why is switch/T-Shoot website down anyone?

  10. DA
    October 28th, 2016

    @OR, How was the exam?

  11. ashraf4y
    October 29th, 2016

    Hey all people please what is five simulations to the current Route exam please
    and what EIGRP SIMLET

  12. ashraf4y
    October 29th, 2016

    IS EIGRP SIMLET EIGRP EVU

  13. OR
    October 29th, 2016

    @DA I passed it 8xx!!!

  14. DA
    October 30th, 2016

    @OR…..Congrats OR

  15. DR.IP
    November 1st, 2016

    Dear friends,

    Do you have any information regarding ccnp-routing dump?????

  16. Jane
    November 4th, 2016

    Please Please Please, could somebody email me the latest dumps pdf + Labs (Packet Tracer) for CCNP route exam on jane_woken52 @ yahoo.com . I will be very thankful of you guys. Pleaseeeeeee

  17. Muhammad Afzal
    November 6th, 2016

    Dear OR & DA.

    congratulation.

    Please share dumps
    M_afzal345 @ yahoo . com

  18. Routehelp
    November 6th, 2016

    I have tried PBR lab in GNS3 with echo instead of www for testing , but policy doesn’t work ( don’t match ), any suggest ?
    BorderRouter(config)#access-list 101 permit tcp any any eq echo
    BorderRouter(config)#route-map PBR permit 10
    BorderRouter(config-route-map)#match ip address 101
    BorderRouter(config-route-map)#set ip next-hop 10.1.101.1
    BorderRouter(config)#interface fastEthernet 0/0
    BorderRouter(config-if)#ip policy route-map PBR
    debug ip policy ( status rejected )
    *Mar 1 00:12:22.503: IP: s=192.168.2.254 (FastEthernet0/0), d=10.1.101.255 (Serial0/0), len 100, policy rejected — normal forwarding ted — normal forwarding
    Please help me …
    THX

  19. Anonymous
    November 8th, 2016

    passed recently, 4 labs (exepc eigrp stub), 1 simlet ospf
    Tagwas info valid, most q-s from new

  20. ledz
    November 9th, 2016

    Hey Anonymous. What materials did u refer

  21. Papa
    November 9th, 2016

    Echo doesnt come under tcp use icmp acl

  22. Learning
    November 9th, 2016

    @ Routehelp

    Isn’t the next-hop 10.1.100.2?

    What diagram are you using?

  23. ronc
    November 16th, 2016

    guys is 183q is latest dump i got it i want confirmation

  24. Akpofure
    November 17th, 2016

    I have passed the Route exam using the ebay link mentioned below. Contained all the new questions from the recent update. There’s a totaol of 206 with the new update (149 + 57). Many thanks to allah and this helpful community.

    The following is information to the Exam:

    44 Questions (This includes Multiple Choice,Drag and Drop, and Simlets)
    EIGRP Stub Simulation
    Redistribution Simulation
    IPv6 OSPF Simulation

    Information here is good as well, as mentioned by others. But here is the ebay link if you want to use the materials:

    http://www.ebay.com/itm/322309862094?

    Good Luck to you all. Many Blessings

  25. Muhammad Afzal
    November 20th, 2016

    Dear AKpofure,

    Please send me PDF dumps

    m_afzal345 @ yahoo . com

  26. Anonymous
    November 20th, 2016

    Hi guys:

    Can you please let me know how you generate the http traffic on the host. It is written that there is a button on the host to test but I dont see anything. Can you please let me know how should work it out or how ping should be configured to generate http traffic?

  27. Anonymous
    November 20th, 2016

    Ok you just have to telnet with the dest. IP and port 80 and then check the PBR on the Border router. :)

  28. Gerasknd
    November 23rd, 2016

    Hi,
    Just came back from the test (passed). Explanation/Answer on this page cannot be correct as part of the requirements are as follows:
    1. All other traffic may use either link
    2. No static or default routing is allowed
    Boarder Router HAS NO 0.0.0.0 route defined or learned via BGP. With configuration offered here, HTTP traffic will take frame-relay link, but all other traffic will be dropped without 0.0.0.0 route. What I have done is this:

    BorderRouter(config)#route-map pbr permit 10
    BorderRouter(config-route-map)#match ip address 101
    BorderRouter(config-route-map)#set ip next-hop 10.1.101.1

    BorderRouter(config)#route-map pbr permit 20
    BorderRouter(config-route-map)#set ip next-hop 10.1.102.1

    Not sure if it was what Cisco had expected though…

  29. Gerasknd
    November 23rd, 2016

    One more thing, none of the commands “show route-map”, “show route-map pbr”, “show route-map all”, “show access-list 101” worked on the test. Simulation just did not accept any of the commands listed so I am not sure how we are supposed to verify operation.

  30. metastabil
    November 25th, 2016

    Hi,
    this SIM is missing the IP SLA commands, because “The company policy requires that web traffic must be forwarded only to Frame Relay link if !!AVAILIBLE!! and other traffic can go through any links”

    Commands:
    ip sla monitor 1
    type echo protocol ipIcmpEcho 10.1.101.1 source-interface Serial0/0
    frequency 10
    ip sla monitor schedule 1 life forever start-time now

    route-map PBR permit 10
    match ip address WWW
    set ip next-hop verify-availability 10.1.101.1 1 track 1

  31. Quale Martins the thrids
    November 26th, 2016

    Anonymous @salman there is no need for the of ip sla because you are using pbr with the next hop so if the next hop (10.1.101.1) goes down there will be no route for that route in your routing table and will take the normal path define by the routing table.
    Here is a reference for this:
    http://www.cisco.com/c/en/us/support/docs/ip/ip-routed-protocols/47121-pbr-cmds-ce.html
    Nam September 6th, 2016

  32. ja mor
    November 28th, 2016

    i passed the exam 300-101 With Score of 934 Dump TAGWA-TAGELSIR is valid

  33. saw
    November 28th, 2016

    Hi all,
    Today i pass 300 101
    149+40 still valid. Lab Sim not change.

    Thanks to all.

  34. Muhammad Afzal
    November 30th, 2016

    Hi, All,

    Passed yesterday, 149+40 Still valid, thanks to Tagwa.

    m _ afzal345 @ yahoo.com

  35. Muhammad Afzal
    November 30th, 2016

    Hi, All,

    Passed yesterday, 149+40 Still valid, thanks to Tagwa. this lab came with changed IP address

    m _ afzal345 @ yahoo.com

  36. Jjonathan
    December 2nd, 2016

    “Generate HTTP traffic”

    How to generate http traffic on host in the lab simulation gns3?

  37. BrunoDiaz
    December 3rd, 2016

    Jjonathan
    Telnet X.X.X.X 80

  38. RectificationAgain
    December 3rd, 2016

    @Gerasknd & @Routehelp practice in GNS3

    Combining your input and question in GNS3, I have the following working. Substituting ICMP for WWW. It will not work substituting TCP ECHO for WWW.

    access-list 101 permit icmp any any echo
    !
    route-map PBR permit 10
    match ip address 101
    set ip next-hop 10.1.101.1
    !
    route-map PBR permit 20
    set ip next-hop 10.1.102.1
    !
    interface FastEthernet0/0
    ip policy route-map PBR

  39. Jia
    December 6th, 2016

    HI ,could anyone tell please where I can get TAGWA 40 questions?… thanks

  40. Muhammad Afzal
    December 6th, 2016

    send me email, i will give you 40 questions.

  41. Jia
    December 7th, 2016

    Jia_elle@hotmail dot com

    Thanks,

  42. Kubuntu
    December 7th, 2016

    ip access-list extended WWW-TRAFFIC
    permit tcp any any eq 80
    permit tcp any any eq 443
    exit

    This access-list is more suitable, because it says “web traffic”, not just HTTP traffic. TCP port 80 for HTTP and TCP port 443 for HTTPS traffic. A similar example is in the Foundation Learning Guide book.

  43. Kubuntu
    December 8th, 2016

    I stand corrected. Took the exam today. The question says “web HTTP traffic” so there is no need to capture HTTPS traffic. Passed with 9xx. Labs OSPF, Redistribution, PBR, Virtual Link. OSPF evaluation sim, timers have changed as mentioned by others. Drag and Drop was Chap 3way handshake.

  44. Garrison
    December 11th, 2016

    @metastabil
    I agree with metastabil the question clearly states a CONDITION for the PBR which requires IP SLA

  45. Anonymous
    December 13th, 2016

    Dear friends Need 40 questions routing kindly sent it on mahmoudhamid101@gmail

  46. Salman
    December 15th, 2016

    Hi all Kindly send me the latest dumps of CCNP Route i have to give paper in next week, Thanks
    email add is “salman underscore saeed 1992 at yahoo dot com”

  47. ETHIO
    December 15th, 2016

    HI ALL
    I THINK WE NEED IP LSA FOR THIS ONE

  48. ETHIO
    December 15th, 2016

    ip sla monitor 1
    type echo protocol ipIcmpEcho 10.1.101.1 source-interface Serial0/0
    ip sla monitor schedule 1 life forever start-time now
    !

    track 1 rtr 1 reachability // MAY BE its different based on your IOS version i think

    route-map rm1 permit 10
    match ip address acl1
    set ip next-hop verify-availability 10.1.101.1 1 track 1

    ip policy route-map rm1 // ON INTERFACE FA0/0

  49. Anonymous
    December 15th, 2016

    Thanks PeterPan and Helper!

  50. BrunoDiaz
    December 16th, 2016

    Passed today.
    This PBR Sim dont accept neither IP SLA or Track commands

  51. Alice
    December 16th, 2016

    Folks iğ sla not necesray in this exam
    Just needed in real life :)

  52. Hiko
    December 20th, 2016

    if possible, send me valid dumps.
    hikoheydar @ gmail.com

  53. Nancy
    December 21st, 2016

    Trying to take CCNP Routing next week, please confirm which Sim were in the exam

  54. Yamin
    December 21st, 2016

    Guys, need to verify availability for this lab with IP Sla?

  55. grappler
    December 25th, 2016

    this lab soes’t work with me even i set same config … thoughts ?

  56. Hitham
    December 25th, 2016

    Is there any change in real exam ??

  57. Anonymous
    December 27th, 2016

    Dear All,
    Dumps is changed, I exam @ 25 Dec

  58. Anonymous
    December 27th, 2016

    Dear All,
    Most of MCQs of Dumps is changed
    Labs are not change
    I exam @ 25 Dec

  59. BRE
    December 30th, 2016

    Hello everyone. Does this sim require any additional commands? Please let me know.

  60. Leo-Decap
    January 1st, 2017

    @Anonymous Are you telling Dumps with 183q is no more valid..??

  61. zee
    January 3rd, 2017

    any one can tell me about the exact number of route maps
    because in 141 dumps he made two route maps 10 and 20
    but on digital tut he made just one route map

  62. Konan
    January 5th, 2017

    I think no need for route-map 20 clause:
    because if PBR fails,router will route as normal.Or,of course,we can add route-map 20 clause just to configuration without any match/set command.
    If you do set next-hop command for other traffic ,maybe it will be mistake.Bacause it is written that other traffic can use ANY interface.

  63. Konan
    January 5th, 2017

    Not to be risky,I think we can use permit clause 20 without any set/match command.

  64. wkk
    January 8th, 2017

    please if possible, send me valid dumps.
    chothandar79 @ gmail.com

  65. CoolGuy
    January 11th, 2017

    Cleared Exam Today … !!!!
    149Q +Tagwa 41 Qs are still valid.
    Got the followng Labs+Sim in exam
    OSPF Evaluation
    EIGRP OSPF Redistribution
    Policy Based Routing
    OSPFv3 Virtual Link
    Thanks DigitalTut and all those who shares their knowledge and useful stuff.
    Others who are preparing or ready to take exam — Best Of Luck —

  66. Waleed are you serious?
    January 14th, 2017

    Lots of new question on the exam good luck to everyone. Labs are slightly different. I can’t remember what, but they were easy

  67. NetScapper
    January 14th, 2017

    Labs were almost the same as 9tut. Wording has change. PBR still the same. New questions on the exam, if you read through CCNP Cisco Press you can eliminate the answers and go with the best one.

  68. Thankfulguy
    January 15th, 2017

    149Q +Tagwa 41 Qs PLEASE HELP taking the exam on the 21th THANK YOU southern.kick16 @ gmail.com

  69. Anonymous
    January 17th, 2017

    please send dumps (149Q +Tagwa 41 Qs)

    telgin1980 -at- gmail -dot- com

  70. malik
    January 17th, 2017

    I pass my exam today with 947 marks. 149 + 41 are 100% valid. All questions from these two dumps nothing else.
    OSPF V3
    OSPF Evaluation
    Redistribution
    PBR
    OSPF V2

    CHAP Drag and Drop

  71. HK
    January 19th, 2017

    Hello everyone, I have a question that is below.

    1) have a two internet connection in one router.
    2) Router configuration for LAN, may be create two VLANs (eg:Manager and Staff). So ManagerVlan use only one internet connection and StaffVlan also use other.
    *How to configure policy-based routing.
    If u have the same design, plz send me{ heinkyaw.phk add gmail. com }
    Plz, Let me know any suggestions…

  72. Hiko
    January 19th, 2017

    Who passed exam? Please share your practice and about dumps.

Comment pages
1 14 15 16 28
  1. No trackbacks yet.