Hi team,
Still we are not able to capture the router chassis interface traffic and we are not able to view hit count of policy based routing & ACL. Please find the configuraion for your reference and do the needful.
Netflow server : 172.20.247.108 port: 9996
A2 & B2 Rack-6802Router]dis route-policy
Route-policy: AIRTEL
Permit : 1
if-match ip next-hop acl 2015
Route-policy: AIRTEL_DENY
Permit : 1
if-match as-path 3
if-match ip next-hop acl 2111
Route-policy: BSNL
Permit : 1
if-match ip next-hop acl 2020
Route-policy: DENY
Permit : 1
if-match ip next-hop acl 2111
Route-policy: JIO
Permit : 1
if-match ip next-hop acl 2004
Route-policy: RAILTEL
Permit : 1
---- More ----
if-match ip next-hop acl 2005
Route-policy: RELIANCE
Permit : 1
if-match ip next-hop acl 2012
Route-policy: SIFY
Permit : 1
if-match ip next-hop acl 2009
Route-policy: TATA
Permit : 1
if-match ip next-hop acl 2010
Route-policy: TATA_DENY
Permit : 1
if-match as-path 2
if-match ip next-hop acl 2112
Route-policy: VODAFONE
Permit : 1
if-match ip next-hop acl 2008
[A2 & B2 Rack-6802Router] dis ip pol
[A2 & B2 Rack-6802Router]dis ip policy-based-route
Policy name: PBR1
node 0 permit:
if-match acl 3004
apply next-hop 10.25.0.49
node 1 permit:
if-match acl 3005
apply next-hop 10.37.201.1
node 2 permit:
if-match acl 3007
apply next-hop 10.1.17.221
node 3 permit:
if-match acl 3008
apply next-hop 10.5.0.133
node 4 permit:
if-match acl 3006
apply next-hop 10.100.23.150
node 5 permit:
if-match acl 3009
apply next-hop 10.16.64.6
node 6 permit:
if-match acl 3999
apply next-hop 11.11.11.1
node 7 permit:
---- More ----
if-match acl 3003
apply next-hop 10.15.0.1
[A2 & B2 Rack-6802Router] dis cu | in nets
ip netstream export host 172.20.247.108 9996
ip netstream export source interface GigabitEthernet2/3/0/14
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
ip netstream inbound
ip netstream outbound
[A2 & B2 Rack-6802Router]
[A2 & B2 Rack-6802Router]
[A2 & B2 Rack-6802Router]dis cu
#
version 7.1.064, Release 7809P20
#
mdc Admin id 1
#
sysname A2 & B2 Rack-6802Router
#
clock protocol none
#
telnet server enable
#
irf mac-address persistent always
irf auto-update enable
irf auto-merge enable
undo irf link-delay
irf member 1 priority 1
irf member 2 priority 1
#
ip unreachables enable
ip ttl-expires enable
#
ip netstream export host 172.20.247.108 9996
ip netstream export source interface GigabitEthernet2/3/0/14
---- More ----
#
flow-interval 10
#
password-recovery enable
#
vlan 1
#
irf-port 1/1
port group interface Ten-GigabitEthernet1/2/0/22 mode enhanced
port group interface Ten-GigabitEthernet1/2/0/23 mode enhanced
#
irf-port 2/2
port group interface Ten-GigabitEthernet2/2/0/22 mode enhanced
port group interface Ten-GigabitEthernet2/2/0/23 mode enhanced
#
policy-based-route PBR1 permit node 0
if-match acl 3004
apply next-hop 10.25.0.49
#
policy-based-route PBR1 permit node 1
if-match acl 3005
apply next-hop 10.37.201.1
#
---- More ----
policy-based-route PBR1 permit node 2
if-match acl 3007
apply next-hop 10.1.17.221
#
policy-based-route PBR1 permit node 3
if-match acl 3008
apply next-hop 10.5.0.133
#
policy-based-route PBR1 permit node 4
if-match acl 3006
apply next-hop 10.100.23.150
#
policy-based-route PBR1 permit node 5
if-match acl 3009
apply next-hop 10.16.64.6
#
policy-based-route PBR1 permit node 6
if-match acl 3999
apply next-hop 11.11.11.1
#
policy-based-route PBR1 permit node 7
if-match acl 3003
apply next-hop 10.15.0.1
---- More ----
#
interface Bridge-Aggregation11
#
interface Route-Aggregation1
description *** DC & DR Replication ***
ip address 11.11.11.2 255.255.255.252
link-aggregation mode dynamic
link-aggregation load-sharing mode per-packet
#
interface Route-Aggregation10
description *** Uplink towards A1-Rack 5900 switch ***
ip address 172.17.55.9 255.255.255.192
link-aggregation mode dynamic
mad enable
ip policy-based-route PBR1
#
interface NULL0
#
interface GigabitEthernet1/2/0/0
port link-mode route
#
interface GigabitEthernet1/2/0/1
port link-mode route
---- More ----
#
interface GigabitEthernet1/2/0/2
port link-mode route
#
interface GigabitEthernet1/2/0/3
port link-mode route
#
interface GigabitEthernet1/2/0/4
port link-mode route
#
interface GigabitEthernet1/2/0/5
port link-mode route
#
interface GigabitEthernet1/2/0/6
port link-mode route
#
interface GigabitEthernet1/2/0/7
port link-mode route
#
interface GigabitEthernet1/2/0/8
port link-mode route
#
interface GigabitEthernet1/2/0/9
---- More ----
port link-mode route
#
interface GigabitEthernet1/2/0/10
port link-mode route
#
interface GigabitEthernet1/2/0/11
port link-mode route
#
interface GigabitEthernet1/2/0/12
port link-mode route
#
interface GigabitEthernet1/2/0/13
port link-mode route
#
interface GigabitEthernet1/2/0/14
port link-mode route
description <<AIRTEL 32 MBPS LINK >>
#
interface GigabitEthernet1/2/0/14.418
ip address 10.37.201.2 255.255.255.252
vlan-type dot1q vid 418
#
interface GigabitEthernet1/2/0/15
---- More ----
port link-mode route
description << RELIANCE 16 Mbps >>
ip address 10.16.64.5 255.255.255.252
ip netstream inbound
ip netstream outbound
#
interface GigabitEthernet1/2/0/16
port link-mode route
#
interface GigabitEthernet1/2/0/17
port link-mode route
#
interface GigabitEthernet1/2/0/18
port link-mode route
#
interface GigabitEthernet1/2/0/19
port link-mode route
#
interface GigabitEthernet1/2/0/20
port link-mode route
description *** Uplink towards A1-Rack 5900sw1 ***
port link-aggregation group 10
#
---- More ----
interface GigabitEthernet1/2/0/21
port link-mode route
description *** Uplonk towards A1-Rack 5900sw2 ***
port link-aggregation group 10
#
interface GigabitEthernet1/3/0/0
port link-mode route
#
interface GigabitEthernet1/3/0/1
port link-mode route
#
interface GigabitEthernet1/3/0/2
port link-mode route
#
interface GigabitEthernet1/3/0/3
port link-mode route
#
interface GigabitEthernet1/3/0/4
port link-mode route
#
interface GigabitEthernet1/3/0/5
port link-mode route
#
---- More ----
interface GigabitEthernet1/3/0/6
port link-mode route
#
interface GigabitEthernet1/3/0/7
port link-mode route
#
interface GigabitEthernet1/3/0/8
port link-mode route
#
interface GigabitEthernet1/3/0/9
port link-mode route
#
interface GigabitEthernet1/3/0/10
port link-mode route
#
interface GigabitEthernet1/3/0/11
port link-mode route
#
interface GigabitEthernet1/3/0/12
port link-mode route#
interface GigabitEthernet1/3/0/13
port link-mode route
---- More ----
#
interface GigabitEthernet1/3/0/14
port link-mode route
description <<< SIFY LINK 16M >>>
ip address 10.5.0.134 255.255.255.252
#
interface GigabitEthernet1/3/0/15
port link-mode route
description << VODAFONE MPLS 32Mbps >>
ip address 10.15.0.2 255.255.255.252
#
interface GigabitEthernet1/3/0/16
port link-mode route
#
interface GigabitEthernet1/3/0/17
port link-mode route
#
interface GigabitEthernet1/3/0/18
port link-mode route
description << P2P to ITPL 15 Mbps >>
ip address 10.10.10.2 255.255.255.252
ip netstream inbound
ip netstream outbound
---- More ----
#
interface GigabitEthernet1/3/0/19
port link-mode route
description *** Airtel DC & DR Replication ***
duplex full
speed 100
ip netstream inbound
ip netstream outbound
lacp period short
port link-aggregation group 1
#
interface GigabitEthernet1/3/0/20
port link-mode route
description *** Uplonk towards A1-Rack 5900sw1 ***
port link-aggregation group 10
#
interface GigabitEthernet1/3/0/21
port link-mode route
description *** Uplonk towards A1-Rack 5900sw2 ***
port link-aggregation group 10
#
interface GigabitEthernet2/2/0/0
port link-mode route
---- More ----
#
interface GigabitEthernet2/2/0/1
port link-mode route
#
interface GigabitEthernet2/2/0/2
port link-mode route
#
interface GigabitEthernet2/2/0/3
port link-mode route
#
interface GigabitEthernet2/2/0/4
port link-mode route
#
interface GigabitEthernet2/2/0/5
port link-mode route
#
interface GigabitEthernet2/2/0/6
port link-mode route
#
interface GigabitEthernet2/2/0/7
port link-mode route
#
interface GigabitEthernet2/2/0/8
---- More ----
port link-mode route
#
interface GigabitEthernet2/2/0/9
port link-mode route
#
interface GigabitEthernet2/2/0/10
port link-mode route
#
interface GigabitEthernet2/2/0/11
port link-mode route
#
interface GigabitEthernet2/2/0/12
port link-mode route
#
interface GigabitEthernet2/2/0/13
port link-mode route
#
interface GigabitEthernet2/2/0/14
port link-mode route
description << BSNL 16Mbps >>
ip address 10.100.23.149 255.255.255.252
#
interface GigabitEthernet2/2/0/15
---- More ----
port link-mode route
description << RAILTEL MPLS 10Mbps >>
speed 100
ip address 10.25.0.50 255.255.255.252
ip netstream inbound
ip netstream outbound
#
interface GigabitEthernet2/2/0/16
port link-mode route
#
interface GigabitEthernet2/2/0/17
port link-mode route
#
interface GigabitEthernet2/2/0/18
port link-mode route
#
interface GigabitEthernet2/2/0/19
port link-mode route
#
interface GigabitEthernet2/2/0/20
port link-mode route
description *** Uplonk towards A1-Rack 5900sw1 ***
port link-aggregation group 10
---- More ----
#
interface GigabitEthernet2/2/0/21
port link-mode route
description *** Uplonk towards A1-Rack 5900sw2 ***
port link-aggregation group 10
#
interface GigabitEthernet2/3/0/0
port link-mode route
#
interface GigabitEthernet2/3/0/1
port link-mode route
#
interface GigabitEthernet2/3/0/2
port link-mode route
#
interface GigabitEthernet2/3/0/3
port link-mode route
#
interface GigabitEthernet2/3/0/4
port link-mode route
#
interface GigabitEthernet2/3/0/5
port link-mode route
---- More ----
#
interface GigabitEthernet2/3/0/6
port link-mode route
#
interface GigabitEthernet2/3/0/7
port link-mode route
#
interface GigabitEthernet2/3/0/8
port link-mode route
#
interface GigabitEthernet2/3/0/9
port link-mode route
#
interface GigabitEthernet2/3/0/10
port link-mode route
#
interface GigabitEthernet2/3/0/11
port link-mode route
#
interface GigabitEthernet2/3/0/12
port link-mode route
#
interface GigabitEthernet2/3/0/13
---- More ----
port link-mode route
#
interface GigabitEthernet2/3/0/14
port link-mode route
description << TATA 40Mbps >>
duplex full
speed 100
ip address 10.1.17.222 255.255.255.252
ip netstream inbound
ip netstream outbound
#
interface GigabitEthernet2/3/0/15
port link-mode route
description << JIO 20Mbps >>
speed 100
ip address 10.22.0.5 255.255.255.252
ip netstream inbound
ip netstream outbound
#
interface GigabitEthernet2/3/0/16
port link-mode route
#
interface GigabitEthernet2/3/0/17
---- More ----
port link-mode route
#
interface GigabitEthernet2/3/0/18
port link-mode route
description << P2P to ITPL Tata 4 Mbps Bkp >>
duplex full
speed 100
ip address 10.10.10.6 255.255.255.252
ip netstream inbound
ip netstream outbound
#
interface GigabitEthernet2/3/0/19
port link-mode route
description *** Tata DC & DR Replication ***
duplex full
speed 100
ip netstream inbound
ip netstream outbound
lacp period short
port link-aggregation group 1
#
interface GigabitEthernet2/3/0/20
port link-mode route
---- More ----
description *** Uplonk towards A1-Rack 5900sw1 ***
port link-aggregation group 10
#
interface GigabitEthernet2/3/0/21
port link-mode route
description *** Uplonk towards A1-Rack 5900sw2 ***
port link-aggregation group 10
#
interface M-GigabitEthernet1/0/0/0
#
interface Ten-GigabitEthernet1/3/0/23
port link-mode route
#
interface Ten-GigabitEthernet2/3/0/22
port link-mode route
#
interface Ten-GigabitEthernet2/3/0/23
port link-mode route
#
interface Ten-GigabitEthernet1/3/0/22
port link-mode bridge
#
interface Ten-GigabitEthernet1/2/0/22
---- More ----
description *** HA ***
#
interface Ten-GigabitEthernet1/2/0/23
description *** HA ***
#
interface Ten-GigabitEthernet2/2/0/22
description *** HA ***
#
interface Ten-GigabitEthernet2/2/0/23
description *** HA ***
#
bgp 64520
peer 10.1.17.221 as-number 4755
peer 10.5.0.133 as-number 9583
peer 10.15.0.1 as-number 55410
peer 10.16.64.6 as-number 18101
peer 10.22.0.5 as-number 55836
peer 10.22.0.6 as-number 55836
peer 10.22.0.6 password cipher $c$3$HxF1eNc9jFwT3l7fTgpY3kQyBNWGsSfaq2E1NEI=
peer 10.25.0.49 as-number 24186
peer 10.37.201.1 as-number 9730
peer 10.100.23.150 as-number 9829
#
---- More ----
address-family ipv4 unicast
default-route imported
import-route direct
import-route static
network 172.17.50.0 255.255.255.0
network 172.17.51.0 255.255.255.0
network 172.17.52.0 255.255.255.0
network 172.17.53.0 255.255.255.0
network 172.17.54.0 255.255.255.0
network 172.17.55.0 255.255.255.192
network 172.17.55.64 255.255.255.192
network 172.17.55.128 255.255.255.128
network 172.17.56.0 255.255.255.0
network 172.17.57.0 255.255.255.0
network 172.17.58.0 255.255.255.0
network 172.17.59.0 255.255.255.0
network 172.17.60.0 255.255.255.0
peer 10.1.17.221 enable
peer 10.1.17.221 route-policy TATA_DENY import
peer 10.1.17.221 route-policy TATA export
peer 10.5.0.133 enable
peer 10.5.0.133 route-policy DENY import
peer 10.5.0.133 route-policy SIFY export
---- More ----
peer 10.5.0.133 route-limit 1000
peer 10.15.0.1 enable
peer 10.15.0.1 route-policy DENY import
peer 10.15.0.1 route-policy VODAFONE export
peer 10.16.64.6 enable
peer 10.16.64.6 route-policy DENY import
peer 10.16.64.6 route-policy RELIANCE export
peer 10.22.0.6 enable
peer 10.22.0.6 route-policy DENY import
peer 10.22.0.6 route-policy JIO export
peer 10.25.0.49 enable
peer 10.25.0.49 route-policy DENY import
peer 10.25.0.49 route-policy RAILTEL export
peer 10.37.201.1 enable
peer 10.37.201.1 route-policy AIRTEL_DENY import
peer 10.37.201.1 route-policy AIRTEL export
peer 10.37.201.1 allow-as-loop 6
peer 10.37.201.1 preferred-value 8
peer 10.100.23.150 enable
peer 10.100.23.150 route-policy DENY import
peer 10.100.23.150 route-policy BSNL export
#
route-policy AIRTEL permit node 1
---- More ----
if-match ip next-hop acl 2015
#
route-policy AIRTEL_DENY permit node 1
if-match as-path 3
if-match ip next-hop acl 2111
#
route-policy BSNL permit node 1
if-match ip next-hop acl 2020
#
route-policy DENY permit node 1
if-match ip next-hop acl 2111
#
route-policy JIO permit node 1
if-match ip next-hop acl 2004
#
route-policy RAILTEL permit node 1
if-match ip next-hop acl 2005
#
route-policy RELIANCE permit node 1
if-match ip next-hop acl 2012
#
route-policy SIFY permit node 1
if-match ip next-hop acl 2009
---- More ----
#
route-policy TATA permit node 1
if-match ip next-hop acl 2010
#
route-policy TATA_DENY permit node 1
if-match as-path 2
if-match ip next-hop acl 2112
#
route-policy VODAFONE permit node 1
if-match ip next-hop acl 2008
#
ip as-path 3 permit _9730$
#
scheduler logfile size 1024
#
line class aux
authentication-mode scheme
user-role network-admin
#
line class console
user-role network-admin
#
line class vty
---- More ----
user-role network-operator
#
line aux 1/0
user-role network-admin
#
line aux 2/0
user-role network-admin
#
line con 1/0
authentication-mode scheme
user-role network-admin
user-role network-operator
#
line con 2/0
authentication-mode scheme
user-role network-admin
user-role network-operator
#
line vty 0 4
authentication-mode scheme
user-role network-operator
protocol inbound ssh
#
---- More ----
line vty 5 63
user-role network-operator
#
ip route-static 0.0.0.0 0 172.17.55.1
ip route-static 10.0.67.0 24 172.17.55.1 description << RBI LDAP >>
ip route-static 10.1.72.60 30 172.17.55.1 description *NPCI TATA WAN*
ip route-static 10.1.74.68 30 172.17.55.1 description *NPCI AIRTEL WAN*
ip route-static 10.13.135.0 24 172.17.55.1 description << Euronet SDMS ATM >>
ip route-static 10.24.1.0 24 172.17.55.1 description << RBI >>
ip route-static 10.29.1.0 24 172.17.55.1 description << RTGS >>
ip route-static 10.31.84.65 32 172.17.55.1 description << CCIL new >>
ip route-static 10.88.55.65 32 172.17.55.1 description << Euronet SDMS ATM >>
ip route-static 10.150.187.0 24 172.17.55.1 description << AGIES >>
ip route-static 10.150.189.0 24 172.17.55.1 description << AGIES >>
ip route-static 115.117.58.0 24 172.17.55.1 description <<TATA INTERNET>>
ip route-static 125.22.102.0 24 172.17.55.1 description <<AIRTEL INTERNET>>
ip route-static 130.1.1.0 24 172.17.55.1 description < NSDL >
ip route-static 130.1.3.0 24 172.17.55.1 description << NSDL >>
ip route-static 156.55.159.0 24 172.17.55.1 description <FIS Server >
ip route-static 172.17.50.0 24 172.17.55.1
ip route-static 172.17.51.0 24 172.17.55.1
ip route-static 172.17.52.0 24 172.17.55.1
ip route-static 172.17.53.0 24 172.17.55.1
---- More ----
ip route-static 172.17.54.0 24 172.17.55.1
ip route-static 172.17.55.64 26 172.17.55.1
ip route-static 172.17.55.128 25 172.17.55.1
ip route-static 172.17.56.0 24 172.17.55.1
ip route-static 172.17.57.0 24 172.17.55.1
ip route-static 172.17.58.0 24 172.17.55.1
ip route-static 172.17.59.0 24 172.17.55.1
ip route-static 172.17.60.0 24 172.17.55.1
ip route-static 192.168.1.0 24 10.10.10.1 description << ITPL AIRTEL 15Mbps >>
ip route-static 192.168.1.0 24 10.10.10.5 preference 80 description << ITPL TATA 5 >>
ip route-static 192.168.95.0 24 172.17.55.1 description < AGS >
ip route-static 192.168.239.61 32 172.17.55.1 description << NPCI EFRM >>
ip route-static 202.46.201.54 32 172.17.55.1 description << PAMACONLINE >>
ip route-static 202.138.123.64 27 172.17.55.1 description << Euronet ATM >>
ip route-static 202.138.123.68 32 172.17.55.1 description << Euronet ATM >>
ip route-static 209.62.85.88 32 172.17.55.1 description Ags ftp
#
info-center loghost 172.17.57.20 port 2519 facility local6
info-center loghost 192.168.1.195
info-center source BGP console level warning
#
snmp-agent
snmp-agent local-engineid 800063A2804CAEA386B9E000000001
---- More ----
snmp-agent community read dlbnoc
snmp-agent community write nocdlb
snmp-agent log all
snmp-agent sys-info version all
snmp-agent trap if-mib link extended
#
ssh server enable
#
ntp-service unicast-server 172.30.1.41
ntp-service refclock-master
#