Configuration guidelines – H3C Technologies H3C SecPath F1000-E User Manual
Page 355
Configuration Guidelines
When configuring a policy, note the following:
1.
The outbound interface and default outbound interface must be P2P interfaces. For non-P2P
interfaces (broadcast interfaces and NBMA interfaces), such as Ethernet interfaces and
Virtual-Template interfaces, multiple next hops are available, and thus packets may not be
forwarded successfully.
2.
The Web supports only one outbound interface, nexthop, default outbound interface, and default
nexthop. For example, if two outbound interfaces are configured at the command line, the Web
interface displays only one of them; it displays the other one after the currently displayed one is
deleted.
3.
To implement source address based PBR on a firewall device, you need to specify the default
filtering action as denying packets to pass the firewall.