The redirect vpn-group command redirects packets to a specific VPN group. In addition, you can also apply the action to a specific interface according to a traffic behavior, and redirect the traffic with a matching class.
The undo redirect vpn-group command deletes the configuration.
By default, redirecting packets to a specific VPN group is not configured in traffic behavior view.
Usage Scenario
To redirect the packets involved in the complex traffic classification to a specified VPN group, you can configure a VPN group, and then run the redirect vpn-group command to redirect the packets to the VPN group. Last, you must configure the traffic policy and apply the policy to interfaces.
Configuration Impact
Run the command vpn-group to add the VPN instance configured in the device to a VPN group. The traffic can be redirected to a specified VPN instance by binding the VPN group into a traffic behavior. Currently, a VPN group can bind eight VPN instance.
After the redirect vpn-group command is run, the device searches for the existing VPN instance that is earliest added to the VPN group:Follow-up Procedure
Configure a traffic classifier and traffic policy and apply the traffic policy to interfaces.
Precautions
One traffic behavior can have only one redirect configuration. To create a redirect configuration, you must delete the existing one.