GRE support with other features
This section describes how GRE tunnels may affect other features on FSX, FCX, and ICX6610 devices.
Support for ECMP for routes through a GRE tunnel
Equal-Cost Multi-Path (ECMP) load sharing allows for load distribution of traffic among available routes. When GRE is enabled, a mix of
GRE tunnels and normal IP routes is supported. If multiple routes are using GRE tunnels to a destination, packets are automatically load-
balanced between tunnels, or between tunnels and normal IP routes.
ACL, QoS, and PBR support for traffic through a GRE tunnel
NOTE
PBR and ACL filtering for packets terminating on a GRE tunnel is not supported on FCX devices. However, PBR can be used to
map IP traffic into a GRE tunnel, but it cannot be used to route GRE traffic. On FCX devices, QoS support for GRE
encapsulated packets is limited to copying DSCP values from the inner header onto the outer header.
For FastIron SX devices only, traffic coming from a tunnel can be filtered by an ACL both before and after the tunnel is terminated and
also redirected by PBR after tunnel is terminated. An ACL classifies and sets QoS for GRE traffic. If the ACL or PBR is applied to the
tunnel loopback port, it would apply to the inner IP packet header (the payload packet) after the tunnel is terminated. If the ACL is applied
to the tunnel ingress port, then the delivery header (outer header) would be classified or filtered before the tunnel is terminated.
NOTE
Restrictions for using ACLs in conjunction with GRE are noted in the section
Configuration considerations for GRE IP tunnels
on page 106. PBR can be configured on tunnel loopback ports for tunnel interfaces with no restrictions. PBR with GRE tunnel
is not supported on FSX 800 and FSX 1600 with the SX-FI48GPP module.
Syslog messages related to GRE IP tunnels
Syslog messages provide management applications with information related to GRE IP tunnels. The following Syslog message is
supported.
Tunnel: TUN-RECURSIVE-DOWN tnnl 1, Tnl disabled due to recursive routing
Configuration considerations for GRE IP tunnels
Before configuring GRE tunnels and tunnel options, consider the configuration notes in this section.
•
When GRE is enabled on a Layer 3 switch, the following features are not supported on Virtual Ethernet (VE) ports, VE member
ports (ports that have IP addresses), and GRE tunnel loopback ports:
–
ACL logging
–
ACL statistics (also called ACL counting)
–
MAC address filters
–
IPv6 filters
NOTE
The above features are supported on VLANs that do not have VE ports.
•
Whenever multiple IP addresses are configured on a tunnel source, the primary address of the tunnel is always used for forming
the tunnel connections. Therefore, carefully check the configurations when configuring the tunnel destination.
IPv4 point-to-point GRE tunnels
FastIron Ethernet Switch Layer 3 Routing
106
53-1003627-04
Summary of Contents for FastIron SX 1600
Page 2: ...FastIron Ethernet Switch Layer 3 Routing 2 53 1003627 04 ...
Page 16: ...FastIron Ethernet Switch Layer 3 Routing 16 53 1003627 04 ...
Page 20: ...FastIron Ethernet Switch Layer 3 Routing 20 53 1003627 04 ...
Page 142: ...FastIron Ethernet Switch Layer 3 Routing 142 53 1003627 04 ...
Page 150: ...FastIron Ethernet Switch Layer 3 Routing 150 53 1003627 04 ...
Page 200: ...FastIron Ethernet Switch Layer 3 Routing 200 53 1003627 04 ...
Page 214: ...FastIron Ethernet Switch Layer 3 Routing 214 53 1003627 04 ...
Page 350: ...FastIron Ethernet Switch Layer 3 Routing 350 53 1003627 04 ...
Page 476: ...FastIron Ethernet Switch Layer 3 Routing 476 53 1003627 04 ...
Page 588: ...FastIron Ethernet Switch Layer 3 Routing 588 53 1003627 04 ...