Configuring Policy-Based Forwarding For Deep Packet Inspection In Vpls - Alcatel-Lucent 7750 SR OS Service Manual

Service router - mobile gateway
Hide thumbs Also See for 7750 SR OS:
Table of Contents

Advertisement

Configuring a VPLS Service with CLI
Configuring Policy-Based Forwarding for Deep Packet Inspection
in VPLS
The purpose policy-based forwarding is to capture traffic from a customer and perform a deep
packet inspection (DPI) and forward traffic, if allowed, by the DPI.
In the following example, the split horizon groups are used to prevent flooding of traffic. Traffic
from customers enter at SAP 1/1/5:5. Due to the mac-filter 100 that is applied on ingress, all traffic
with dot1p 07 marking will be forwarded to SAP 1/1/22:1, which is the DPI.
DPI performs packet inspection/modifcation and either drops the traffic or forwards the traffic
back into the box through SAP 1/1/21:1. Traffic will then be sent to spoke-sdp 3:5.
SAP 1/1/23:5 is configured to see if the VPLS service is flooding all the traffic. If flooding is
peformed by the router then traffic would also be sent to SAP 1/1/23:5 (which it should not).
Figure 48
VPLS service. For information about configuring filter policies, refer to the 7750 SR OS Router
Configuration Guide.
Residential Split
IngressPBF Filter
on Incoming Traffic
Page 432
shows an example to configure policy-based forwarding for deep packet inspection on a
DPI BOX
Disable Learning
Split Horizon SAPs
Figure 6: Policy-Based Forwarding For Deep Packet Inspection
VPLS 10
VPLS 10
7750 SR OS Services Guide
Normal Stream
PBF Dirverted Stream

Advertisement

Table of Contents
loading

Table of Contents