15-90
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 15 Configuring Access Control
Configuring Policy-Based Forwarding
Configuring Policy-Based Forwarding
Policy-based forwarding (PBF) is an extension of VACL redirection that is supported by the PFC2 and
PFC3A/PFC3B/PFC3BXL. PBF is particularly beneficial in any flat Layer 2 network that is used for
transparent bridging where a limited amount of inter-VLAN communication is required and in server
farms or demilitarized zones (DMZs) where bridging devices (like server load-balancing appliances) are
involved or where firewall load balancing is performed.
Note
Software release 7.5(1) and later releases have PBF enhancements that simplify the process of setting
and committing
the security ACLs and adjacency information. For more information, see the
“Enhancements
to PBF Configuration (Software Releases 7.5(1) and Later)” section on page 15-102
.
Note
Software release 8.3(1) and later releases have further PBF enhancements that simplify the process of
setting and committing
the security ACLs and adjacency information. For more information, see the
“Enhancements to the PBF Configuration (Software Releases 8.3(1) and Later)” section on page 15-105
.
Note
PBF does not support IPX and multicast traffic.
Note
PBF does not work with 802.1Q tunnel traffic. PBF is supported on the Layer 3 IP unicast traffic; it is
not applicable to the Layer 2 traffic. At the intermediate (PBF) switch, all 802.1Q tunnel traffic appears
as Layer 2 traffic.
Note
PBF may require some configuration on the attached hosts. When a router is not present in the network,
the ARP table entries have to be statically added on each host participating in PBF.
PBF is described in these sections:
•
Understanding How PBF Works, page 15-91
•
PBF Hardware and Software Requirements, page 15-91
•
Configuring PBF from the CLI, page 15-92
•
PBF Configuration Example, page 15-100
•
Enhancements to PBF Configuration (Software Releases 7.5(1) and Later), page 15-102
•
Enhancements to the PBF Configuration (Software Releases 8.3(1) and Later), page 15-105
•
Enhancements to PBF Configuration (Software Releases 8.6(1) and Later), page 15-110