Routing configuration overview
Routing configuration involves adding a default route, adding routes to networks that are not directly connected, and adding routes to networks that can be reached through route-based VPNs.
Follow these general steps to configure routing:
- Add the default route.
- Add routes to networks that are not directly connected, but require a next hop gateway.
- Add routes to networks that are reachable through the Tunnel Interfaces used in route-based VPNs.
Limitations
- Routing and anti-spoofing can only be configured for interfaces that have IP addresses. It is not possible to define routing or anti-spoofing for the following types of interfaces because they
do not have IP addresses:
- Capture Interfaces and Inline Interfaces on Master Engines.
- Capture Interfaces and Inline Layer 2 Engine Interfaces on Engines.
- Layer 2 physical interfaces on Engines are not included in the routing and anti-spoofing configuration.
- The basic routing configuration does not determine which traffic is routed through policy-based VPNs. Routing is checked after policy-based VPN traffic is encapsulated inside encrypted packets with different source and destination IP address information.
Multi-Link
For information on using NetLinks to configure routing for Multi-Link, see the section about defining Multi-Link routes.