Got it

PBR with MPLS-TE tunnel on AR2200

Created: Sep 11, 2017 06:51:04Latest reply: Oct 17, 2018 02:49:22 2148 2 0 0 0
  Rewarded HiCoins: 0 (problem resolved)
This post was last edited by user_2698869 at 2017-09-14 12:28. Hello!

I'm faced with the problem when redirecting traffic to MPLS TE tunnel. I have done all the instructions from the manual, but have no success.
My case is as follows.

Router AR2200 V200R007C00SPCb00 has name R2.

I take traffic from GigabitEthernet0/0/0 and try to redirect it to Tunnel0/0/1.

[R2]disp ip int bri
Interface                         IP Address/Mask      Physical   Protocol  
GigabitEthernet0/0/0              172.16.20.254/24     up         up        
GigabitEthernet0/0/1              1.0.12.2/24          up         up
LoopBack0                         2.2.2.2/32           up         up(s)     
Tunnel0/0/1                       1.1.12.2/24          up         up 


The tunnel is MPLS TE tunnel and it is fully functional:

interface Tunnel0/0/1
 ip address 1.1.12.2 255.255.255.0
 tunnel-protocol mpls te
 destination 1.1.1.1
 mpls te tunnel-id 1
 mpls te path explicit-path ->R1
 mpls te path explicit-path ->R3->R1 secondary
 mpls te backup hot-standby
 mpls te commit


[R2]ping lsp -c 1 te Tunnel 0/0/1
    Reply from 1.0.12.1: bytes=72 Sequence=1 time=1 ms


  --- FEC: TE TUNNEL IPV4 SESSION QUERY Tunnel0/0/1 ping statistics ---
    1 packet(s) transmitted
    1 packet(s) received
    0.00% packet loss


To perform redirection I use traffic policy on the interface GigabitEthernet0/0/0, where traffic is coming:

[R2]display traffic-policy applied-record     
-------------------------------------------------
  Policy Name:   take-tunnel 
  Policy Index:  0
     Classifier:satellite     Behavior:take-tunnel0/0/1 
-------------------------------------------------
 *interface GigabitEthernet0/0/0
    traffic-policy take-tunnel inbound  
      slot 0    :  success
-------------------------------------------------


[R2]disp traffic policy user-defined 
  User Defined Traffic Policy Information:
  Policy: take-tunnel
   Classifier: satellite
    Operator: OR
     Behavior: take-tunnel0/0/1
      Redirect: 
        Redirect ip-nexthop 1.1.12.2
      statistic: enable


[R2]disp traffic classifier user-defined 
  User Defined Classifier Information:
   Classifier: satellite
    Operator: OR
    Rule(s) : 
     if-match acl 3001


[R2]disp acl 3001
Advanced ACL 3001, 1 rule
Acl's step is 5
 rule 10 permit ip source 172.16.20.0 0.0.0.255 destination 172.16.10.0 0.0.0.255 logging (176 matches)


Despite of the fact that packets are matched and traffic policy is applied successfully to the incoming interface, there are no packets out from the tunnel.



[R2]display traffic policy statistics interface gi0/0/0 in

Interface: GigabitEthernet0/0/0
Traffic policy inbound: take-tunnel
 Rule number: 1
 Current status: OK!
 Item                    Sum(Packets/Bytes)               Rate(pps/bps)
 ------------------------------------------------------------------------------
 Matched                         176/21,472                      1/936          
 Passed                        176/21,472                      1/936          
 Dropped                         0/0                           0/0            
    Filter                        0/0                           0/0            
    CAR                           0/0                           0/0            
 Queue Matched                   0/0                           0/0            
     Enqueued                      0/0                           0/0            
     Discarded                     0/0                           0/0            
 CAR                             0/0                           0/0            
    Green packets                 0/0                           0/0            
    Yellow packets                0/0                           0/0            
    Red packets                   0/0                           0/0


[R2]disp int tu0/0/1
Tunnel0/0/1 current state : UP
Line protocol current state : UP
Last line protocol up time : 2017-09-14 12:28
Description:satellite
Route Port,The Maximum Transmit Unit is 1500
Internet Address is 1.1.12.2/30
Encapsulation is TUNNEL, loopback not set
Tunnel destination 1.1.1.1
Tunnel up/down statistics 1
Tunnel protocol/transport MPLS/MPLS, ILM is available,
primary tunnel id is 0x3, secondary tunnel id is 0x0
Current system time: 2017-09-14 12:28
    300 seconds output rate 0 bits/sec, 0 packets/sec
    19 seconds output rate 0 bits/sec, 0 packets/sec
    0 packets output,  0 bytes
    0 output error
    0 output drop


Can anybody shed some light on the situation?


UPD. I tried to direct the traffic to the mpls-te tunnel via static route and got success. I tried PBR on the traffic with redirection to an GRE tunnel and got success also. But
PBR with mpls-te tunnel is not working.
  • x
  • convention:

Featured Answers
Barret
Created Oct 17, 2018 02:49:22

please change the Redirect ip-nexthop to 1.1.1.1
View more
  • x
  • convention:

All Answers
WoodWood
WoodWood Created Sep 11, 2017 07:19:18

please help @kmyd
View more
  • x
  • convention:

Barret
Barret Created Oct 17, 2018 02:49:22

please change the Redirect ip-nexthop to 1.1.1.1
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.
Information Protection Guide
Thanks for using Huawei Enterprise Support Community! We will help you learn how we collect, use, store and share your personal information and the rights you have in accordance with Privacy Policy and User Agreement.