Routing configuration overview

Routing configuration involves adding a default route, adding routes to networks that are not directly connected, and adding routes to networks that can be reached through route-based VPNs.

Follow these general steps to configure routing:

  1. Add the default route.
  2. Add routes to networks that are not directly connected, but require a next hop gateway.
  3. Add routes to networks that are reachable through the Tunnel Interfaces used in route-based VPNs.

Limitations

  • Routing and anti-spoofing can only be configured for interfaces that have IP addresses. It is not possible to define routing or anti-spoofing for the following types of interfaces because they do not have IP addresses:
    • Capture Interfaces and Inline Interfaces on Master Engines.
    • Capture Interfaces and Inline Layer 2 Engine Interfaces on Engines.
  • Layer 2 physical interfaces on Engines are not included in the routing and anti-spoofing configuration.
  • The basic routing configuration does not determine which traffic is routed through policy-based VPNs. Routing is checked after policy-based VPN traffic is encapsulated inside encrypted packets with different source and destination IP address information.

Multi-Link

For information on using NetLinks to configure routing for Multi-Link, see the section about defining Multi-Link routes.