- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hi Guys,
I'm using MHO solution: 2 MHO 140 + 2 6800 CP GW. I have configure PBR for management interface but it doesn't work. Anyone has encountered this problem yet ?
My configuration:
set pbr table Mgmt static-route default nexthop gateway address 172.17.10.1 priority 1
set pbr rule priority 10 match from 172.17.10.216/32 to 172.16.0.68/32
set pbr rule priority 10 action table Mgmt
Best regards.
Hi,
It looks like you're creating pbr on orchestrator itself.
I guess you should do it on Security Group from its Global Clish. Mgmt interface of the orchestrator is not related to the policy.
Management interfaces of Security Group are eth1-Mgmt1, eth1-Mgmt2, etc...
Hi,
I created pbr on Security group
Output when i show configuration pbr on security group, it pushed to 2 GW 6800.
[Global] FW-SRV-MC-ch01-01 > show configuration pbr
1_01:
set pbr table Mgmt static-route 172.16.0.68/32 nexthop gateway logical eth1-Mgmt 1 on
set pbr rule priority 10 match from 172.17.10.0/24 to 172.16.0.68/32
set pbr rule priority 10 action table Mgmt
1_02:
set pbr table Mgmt static-route 172.16.0.68/32 nexthop gateway logical eth1-Mgmt 1 on
set pbr rule priority 10 match from 172.17.10.0/24 to 172.16.0.68/32
set pbr rule priority 10 action table Mgmt
Best regards.
So, that is what it should be. Does it work for you?
Correct, there's only one routing table here.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
21 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY