Wanguard 6.2 User Guide
Appendix 4 – Network Integration Guideline for Wanguard Filter
2. Using
PBR
(Policy Base Routing) to override the normal routing decision from
Divert-from/Inject-to
router:
Figure-5.
Logical Diagram Layer 3 Forwarding using PBR (
*same steps as per Fig.1
)
Warning
: PBR may impact router performance – depending on platform type, some optimizations may exist.
However, by default PBR relays on packet-by-packet processing (process-switching) which have a significant impact
on router’s CPU.
In case multiple
Next-hop
routers exist, then the following have to be considered too:
•
multiple GRE tunnels have to be deployed and static routes at
Filter
level have to be considered, or
•
multiple entries on PBR matching each zone, depending on which option is chosen
When using GRE, you must run on
Filter
the standard Linux tool
ip
in order
to create and route GRE / IP over
IP tunnels that will be used to inject the cleaned traffic back into the network. You must then configure
Filter
(see
Packet Filter Configuration) with the Outbound Interface set to the virtual network interface created by the tunnel.
Please refer to the below router configuration samples for both GRE and PBR options:
1. The GRE method (using Cisco CLI) – configuration from
Next-hop
router:
- 122 -
Summary of Contents for wanguard 6.2
Page 1: ......