Creating Advanced Policy-Based Routing Rules
Use this page to configure rules for an advanced policy-based routing (APBR) profile (also known as an application profile). You can then associate the rules with one or more than one applications (example: for HTTP) or application groups.
To create a rule:
Fields |
Description |
---|---|
Source |
Click the add icon (+) to select a source zone from the list. You can select one or more zones for the application profile. |
Application |
Click the add icon (+) to select the application from the list. If the application matches any of the application or application groups of a rule in a profile, the application profile rule is considered as a match. You can select one or more applications. |
Routing Instance |
Click the + icon to select a routing instance from the list, that are configured on a device. The device sends the matched packet to the specified routing instance. The routing instances specify the routing table and the destination to which a packet is forwarded. When traffic arrives at the specified zone, it is matched by the advanced application profile. The application profile matches applications and application groups and if the matching rule is found, the packets are routed to the routing instance that sends the traffic to a different interface as specified in the next-hop IP address. |
Rule Name |
The rule name is automatically generated by Security Director. For example, Rule-incremental value. |
An APBR policy designed in Security Director is equal to one or more policies on a device, based on the unique security zones and rule set.