data:image/s3,"s3://crabby-images/0c4b9/0c4b90890db0bb8d7a37aee44f957521efe1a842" alt="routing_orchestration"
The goal of the article
- This article will show you how to create a policy routes to route user traffic by user, user group, server, or service.
- We will create these policy routes using firewall rules and it will not affect routing rules in Routing> Policy Routing.
Configuration instruction
We will have the diagram as shown below
data:image/s3,"s3://crabby-images/285f7/285f7b2ad9f42f459153b487444fb7db81550c4c" alt=""
- This article contains 3 examples of configuring policy-based routes:
- User-based or Group-based Routing.
- Service-based Routing.
- Server-based Routing.
User-based or Group-based Routing
- In this example we will configure all users’ internet traffic from the LAN area (all people in the LAN located in Group Marketing) routing through Gateway 1.
- To configure, click Firewall> + Add Firewall Rule and enter the following parameters.
data:image/s3,"s3://crabby-images/d4818/d4818467acc9804a13c4ec93d30d89eb0889335b" alt=""
data:image/s3,"s3://crabby-images/29dd0/29dd0f34232427f5a9ba2576cc657147ba60af49" alt=""
data:image/s3,"s3://crabby-images/c2f5e/c2f5e773d07d230c6d60a56a3095fb5e084f9306" alt=""
data:image/s3,"s3://crabby-images/5deca/5decae4ee4d76b9bfd60d1e2cd049eb399fc26f4" alt=""
data:image/s3,"s3://crabby-images/f41ab/f41ab522133d09695b6f04c21430af36b5c40608" alt=""
- Name: Enter a rule name
- Action: Accept
- Source Zone: LAN
- Source Networks and Devices: Any
- Destination Zones: WAN
- Destination Networks: Any
- Services: Any
- Match known users: Check
- User or Groups: Marketing
- Rewrite source address (Masquerading): Check
- Primary Gateway: Select the gateway you wish this traffic to go out
- Note: To view the Gateway name, go to Network> Interface> Click on Port Wan that we want to see the name.
- Click Save.
data:image/s3,"s3://crabby-images/655e0/655e02c8fa6ffb9d1bf178b0d04ef32fcec01b58" alt=""
Service-based routing
- In this example we will create policy routes that route all traffic of the SMTP (email) service through the Gateway 1 port.
- To configure, click Firewall> + Add Firewall Rule and enter the following parameters.
data:image/s3,"s3://crabby-images/77df7/77df7111fcb3cabfa1a541571ba3e821065730e2" alt=""
data:image/s3,"s3://crabby-images/2b785/2b7853051b68677c2dd4cf664b66bdd8775ae8f1" alt=""
data:image/s3,"s3://crabby-images/2579a/2579a0df21be2452f3bee337c841fcb074151a91" alt=""
- Name: Enter a rule name
- Action: Accept
- Source Zone: Lan
- Source Networks and Devices: Any
- Destination Zones: WAN
- Destination Networks: Any
- Services: SMTP
- Match known users: Unchecked
- Rewrite source address (Masquerading): Checked
- Primary Gateway: Select the gateway you wish this traffic to go out
Server-based routing
- In this example, we will configure all traffic from the Web Server routing through Gateway 2.
- To configure, click Firewall> + Add Firewall Rule and enter the following parameters.
data:image/s3,"s3://crabby-images/37ded/37ded123e96d702da5cedeac0524697c6c23982e" alt=""
data:image/s3,"s3://crabby-images/59aff/59aff955e9b6bfe78f654e5cc9dd39b7a0c76db7" alt=""
data:image/s3,"s3://crabby-images/83ad2/83ad2c9c01a6d867ce220e2ec52d4b4a95f6328c" alt=""
- Name: Enter a rule name
- Action: Accept
- Source Zone: Lan
- Source Networks and Devices: Web Server
- Destination Zones: WAN
- Destination Networks: Any
- Services: Any
- Match known users: Unchecked
- Rewrite source address (Masquerading): Checked
- Primary Gateway: Select the gateway you wish this traffic to go out
Leave a Reply