A device configured with the redirection action redirects the packets matching traffic classification rules to the CPU, an interface, or a VPN instance.
A traffic policy that contains redirection can only be applied in the inbound direction of the system, interface or VLAN.
Only the S5720-EI, S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-S, S5731S-H, S5732-H, S5735-L, S5735S-L, S5735S-L-M, S5735-S, S5735S-S, S5735-S-I, S6720-EI, S6720S-EI, S6720-HI, S6730-H, S6730S-H, S6730-S, and S6730S-S support redirection to the CPU.
If redirect interface is configured in a traffic behavior, you are advised to apply the traffic policy containing the traffic behavior only to Layer 2 data traffic.
The system view is displayed.
A traffic classifier is created and the traffic classifier view is displayed, or the view of an existing traffic classifier is displayed.
By default, the relationship between rules in a traffic classifier is or.
Only the S5720-EI, S6720-EI, and S6720S-EI support traffic classifiers with advanced ACLs containing the ttl-expired field.
When a traffic classifier contains if-match ipv6 acl { acl-number | acl-name }, the S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S6720-HI, S6730-H, S6730S-H, S6730-S, and S6730S-S do not support remark 8021p [ 8021p-value | inner-8021p ], remark cvlan-id cvlan-id, remark vlan-id vlan-id, or mac-address learning disable.
Exit from the traffic classifier view.
Run traffic behavior behavior-name
A traffic behavior is created and the traffic behavior view is displayed, or the view of an existing traffic behavior is displayed.
Run redirect interface interface-type interface-number [ forced ]
The device is configured to redirect packets matching the traffic classifier to a specified interface.
After traffic is redirected to an interface in Down state, if forced is specified, traffic is dropped on the interface and is not switched to the original forwarding path. If forced is not configured, traffic is switched to the original forwarding path.
The packets that are redirected to an interface will be discarded if the VLAN of the packets on the interface is not allowed.
After the traffic policy containing redirect cpu is applied, the device redirects traffic matching traffic classification rules to the CPU, affecting system performance. Exercise caution when you run the redirect cpu command.
Run redirect vpn-instance vpn-instance-name
The device is configured to redirect packets matching the traffic classifier to a VPN instance.
The S5735-L, S5735-S, S5735-S-I, S5735S-L, S5735S-L-M, and S5735S-L-M do not support this command.
Run quit
Exit from the traffic behavior view.
Run quit
Exit from the system view.
The system view is displayed.
On the S2720-EI, S5720I-SI, S5720-LI, S5720S-LI, S5720S-SI, S5720-SI, S5730S-EI, S5730-SI, S6720-LI, S6720S-LI, S6720S-SI, and S6720-SI, run traffic policy policy-name
A traffic policy is created and the traffic policy view is displayed, or the view of an existing traffic policy is displayed.
On the S5720-EI, S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S5735-L, S5735S-L, S5735S-L-M, S5735-S, S5735S-S, S5735-S-I, S6720-EI, S6720-HI, S6720S-EI, S6730-H, S6730S-H, S6730-S, and S6730S-S, run traffic policy policy-name [ match-order { auto | config } ]
A traffic policy is created and the traffic policy view is displayed, or the view of an existing traffic policy is displayed. If you do not specify the matching order of traffic classifiers when creating a traffic policy, the default matching order is config.
After a traffic policy is applied, you cannot use the traffic policy command to modify the matching order of traffic classifiers in the traffic policy. To modify the matching order, delete the traffic policy, create a traffic policy, and then specify the matching order.
If more than 128 ACL rules defining CAR are configured, a traffic policy must be applied to an interface, a VLAN, and the system in sequence in the outbound direction. In the preceding situation, if ACL rules need to be updated, delete the traffic policy from the interface, VLAN, and system and re-configure a traffic policy in sequence.
Run classifier classifier-name behavior behavior-name
A traffic behavior is bound to a traffic classifier in the traffic policy.
Exit from the traffic policy view.
Exit from the system view.
The traffic policy containing redirection cannot be applied in the outbound direction.
Applying traffic policies consumes ACL resources. If there are no sufficient ACL resources, some traffic policies will fail to be applied. For example, if an if-match rule in a traffic policy occupies one ACL, M ACL resources will be used to apply the traffic policy to M interfaces. When a traffic policy is applied to L VLANs, L ACLs are occupied. When a traffic policy is applied to the system, one ACL is occupied. For details about ACLs occupied by if-match rules, see Table 3 in "Licensing Requirements and Limitations for MQC" of MQC Configuration.
Run system-view
The system view is displayed.
Run interface interface-type interface-number[.subinterface-number ]
The interface view or sub-interface view is displayed.
Only the S5720-EI, S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S6720-EI, S6720-HI, S6720S-EI, S6730-H, S6730S-H, S6730-S, and S6730S-S support Ethernet sub-interfaces.
After you run the undo portswitch command to switch Layer 2 interfaces on the preceding series of switches into Layer 3 interfaces, you can configure Ethernet sub-interfaces on the interfaces.
After an interface is added to an Eth-Trunk, sub-interfaces cannot be configured on the interface.
Run traffic-policy policy-name inbound
A traffic policy is applied to the interface or sub-interface.
Run system-view
The system view is displayed.
Run vlan vlan-id
The VLAN view is displayed.
Run traffic-policy policy-name inbound
A traffic policy is applied to the VLAN.
Run system-view
The system view is displayed.
Run interface vlanif vlan-id
The VLANIF interface view is displayed.
Run traffic-policy policy-name inbound
A traffic policy is applied to the VLANIF interface.
Only one traffic policy can be applied to the inbound direction on a VLANIF interface, but a traffic policy can be applied to the inbound direction on different VLANIF interfaces.
A traffic policy cannot be applied to a VLANIF interface corresponding to the super-VLAN or MUX VLAN.
A traffic policy that is applied to a VLANIF interface is valid only for unicast packets and Layer 3 multicast packets on the VLANIF interface.
A traffic policy can be applied to a VLANIF interface only on the S5720-EI, S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S6720-EI, S6720-HI, S6720S-EI, S6730-H, S6730S-H, S6730-S, and S6730S-S.
Run system-view
The system view is displayed.
Run traffic-policy policy-name global inbound [ slot slot-id ]
A traffic policy is applied to the system.
Each direction can be configured with only one traffic policy globally or in a slot. A traffic policy cannot be applied to the same direction in both the system and slot. For example, if a traffic policy is applied to the inbound direction globally, it cannot be applied to the inbound direction in a slot.
Run the display traffic policy user-defined [ policy-name [ classifier classifier-name ] ] command to check the configuration of a specified user-defined traffic policy.
Run the display traffic-applied [ interface [ interface-type interface-number ] | vlan [ vlan-id ] ] { inbound | outbound } [ verbose ] command to check information about ACL-based simplified and MQC-based traffic policies applied to the system, a VLAN, or an interface.
The display traffic-applied command cannot be used to check information about ACL-based simplified and MQC-based traffic policies applied to a sub-interface. However, traffic policies can be applied to a sub-interface.
Run the display traffic policy { interface [ interface-type interface-number [.subinterface-number ] ] | vlan [ vlan-id ] | ssid-profile [ ssid-profile-name ] | global } [ inbound | outbound ] command to check the traffic policy configuration.
Only the S5720-EI, S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S6720-EI, S6720-HI, S6720S-EI, S6730-H, S6730S-H, S6730-S, and S6730S-S support sub-interfaces.
Only the S5720-HI, S5730-HI, S5731-H, S5731S-H, S5732-H, S6720-HI, S6730S-H, and S6730-H support ssid-profile [ ssid-profile-name ].
Run the display traffic-policy applied-record [ policy-name ] command to check the application records of a specified traffic policy.