[nsp] 3640 and PBR

From: Brian (signal@shreve.net)
Date: Fri Feb 23 2001 - 11:26:40 EST

I am seeing a strange problem with a 3640 running 12.0(7)XK1. It is the
border router for an ISP.

A user who is assigned an IP address, cannot get his VPN to work with the
remote destination, whenever I enable policy routing on the ingress
interface of this 3640. I will post a breif part of the config:

 interface FastEthernet0/0
 ip address
 no ip directed-broadcast
 ip ospf priority 4
 duplex auto
 speed auto
 ip policy route-map proxy-redirect

access-list 110 permit tcp any eq www

route-map proxy-redirect permit 10
 match ip address 110
 set ip next-hop
route-map proxy-redirect permit 20

This user is not on at all. Yet adding the route map to
f0/0 messes this users VPN up. My understanding is that the packets that
don't match list 110, should be unchanged. Can anyone speculate?


