Policy Based Route (PBR) is designed to select a router and forward data based on the source IP address, destination IP address and service type of a packet.
To create a policy-based route and PBR rule, take the following steps:
Option | Description |
---|---|
PBR name | Specifies a name for the policy-based route. |
Bind to | Binds the policy-based route to a zone or interface. Select a zone or interface from the drop-down list. |
Schedule |
Specifies a schedule for the policy-based route. |
Description | Type information about the PBR rule. |
Option | Description |
---|---|
Type | IP address: To specify a source address type of "IP address", click this option button and type the IP address and netmask into the IP address and Netmask box respectively. |
Host name: To specify a source address type of "host name", click this option button and type the host name into the Host name box. | |
IP range: To specify a source address type of "IP range", click this option button and type the start IP and end IP into the Start IP and End IP box respectively. | |
Address entry: To specify a source address type of "address entry", click this option button and select an address entry from the Address entry drop-down list. | |
Add | Click Add add the source address entry to the system. All the entries that have been added will be displayed in the list below. |
Delete | Select the entry you want to delete from the list, and click Delete. |
Option | Description |
---|---|
User type | Role: To specify a source user type of "Role", click this option button and select a role from the Role drop-down list. |
User: To specify a source user type of "User", click this option button and select an AAA server and username from the AAA server and Username drop-down list respectively. | |
User group: To specify a source user type of "User group", click this option button and select an AAA server and user group name from the AAA server and User group name drop-down list respectively. | |
Add | Click Add to add the source user entry to the system. All the entries that have been added will be displayed in the list below. |
Delete | Select the entry you want to delete from the list, and click Delete. |
Option | Description |
---|---|
Type | IP address: To specify a destination address type of "IP address", click this option button and type the IP address and netmask into the IP address and Netmask box respectively. |
Host name: To specify a destination address type of "host name", click this option button and type the host name into the Host name box. | |
IP range: To specify a destination address type of "IP range", click this option button and type the start IP and end IP into the Start IP and End IP box respectively. | |
Address entry: To specify a destination address type of "address entry", click this option button and select an address entry from the Address entry drop-down list. | |
Add | Click Add to add the destination address entry to the system. All the entries that have been added will be displayed in the list below. |
Delete | Select the entry you want to delete from the list, and click Delete. |
Option | Description |
---|---|
Next hop | IP address: Check the radio button to specify an IP address as the next hop. Type IP address into the IP address text box and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. |
Interface: Check the radio button to specify an interface as the next hop. Select an interface from the Interface drop-down list and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. | |
Virtual Router in current VSYS: Check the radio button to specify a virtual router in the current VSYS as the next hop. Select a virtual router from the Virtual Router drop-down list and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. | |
Virtual Router in other VSYS: Check the radio button to specify a virtual router out of the current VSYS as the next hop. Select a virtual router from the Virtual Router drop-down list and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. | |
Add | Click to add the specified next hop. |
Delete | Select next-hop entries from the next hop table and click this button to delete. |
To add a rule for an existing policy-based route, take the following steps:
Option | Description |
---|---|
PBR name | Select an existing policy-based route from the drop-down list. |
Schedule | Specifies a schedule for the PBR rule. |
Description | Type information about the PBR rule. |
Option | Description |
---|---|
PBR name | Specifies a name for the policy-based route. |
Set next hop |
Specifies a next hop for the PBR rule. Select the Set next hop check box, and then specify the type of the next hop in the box below, including:
|
Description | Type information about the PBR rule. |
Bind to | Binds the policy-base rule to an interface or zone. Select an interface or zone from the drop-down list. |
Option | Description |
---|---|
Type | IP address: To specify a source address type of "IP address", click this option button and type the IP address and netmask into the IP and Netmask box respectively. |
Host name: To specify a source address type of "host name", click this option button and type the host name into the Host name box. | |
IP range: To specify a source address type of "IP range", click this option button and type the start IP and end IP into the Start IP and End IP box respectively. | |
Address entry: To specify a source address type of "address entry", click this option button and select an address entry from the Address entry drop-down list. | |
Add | Click Add to add the source address entry to the system. All the entries that have been added will be displayed in the list below. |
Delete | Select the entry you want to delete from the list, and click Delete. |
Option | Description |
---|---|
User type | Role: To specify a source user type of "Role", click this option button and select a role from the Role drop-down list. |
User: To specify a source user type of "User", click this option button and select an AAA server and username from the AAA server and Username drop-down list respectively. | |
User group: To specify a source user type of "User group", click this option button and select an AAA server and user group name from the AAA server and User group name drop-down list respectively. | |
Add | Click Add to add the source user entry to the system. All the entries that have been added will be displayed in the list below. |
Delete | Select the entry you want to delete from the list, and click Delete. |
Option | Description |
---|---|
Type | IP address: To specify a destination address type of "IP address", click this option button and type the IP address and netmask into the IP address and Netmask box respectively. |
Host name: To specify a destination address type of "host name", click this option button and type the host name in the Host name box. | |
IP range: To specify a destination address type of "IP range", click this option button and type the start IP and end IP into the Start IP and End IP box respectively. | |
Address entry: To specify a destination address type of "address entry", click this option button and select an address entry from the Address entry drop-down list. | |
Add | Click Add to add the destination address entry to the system. All the entries that have been added will be displayed in the list below. |
Delete | Select the entry you want to delete from the list, and click Delete. |
Option | Description |
---|---|
Next hop | IP address: Check the radio button to specify an IP address as the next hop. Type IP address into the IP address text box and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. |
Interface: Check the radio button to specify an interface as the next hop. Select an interface from the Interface drop-down list and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. | |
Virtual Router in current VSYS: Check the radio button to specify a virtual router in the current VSYS as the next hop. Select a virtual router from the Virtual Router drop-down list and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. | |
Virtual Router in other VSYS: Check the radio button to specify a virtual router out of the current VSYS as the next hop. Select a virtual router from the Virtual Router drop-down list and specify the weight into the Weight text box. When more than one next hops are available, the traffic will be allocated to the different next hops according to the weight value. | |
Add | Click to add the specified next hop. |
Delete | Select next-hop entries from the next hop table and click this button to delete. |
To edit/delete/move a policy-based route, take the following steps:
Option | Description |
---|---|
Top | Click this option button to move the PBR rule to the top. |
Bottom | Click this option button to move the PBR rule to the bottom. |
Before ID | Click this option button and type the ID into the box behind to move the PBR rule to the position before the ID. |
After ID | Click this option button and type the ID into the box behind to move the PBR rule to the position after the ID. |
Note: Each PBR rule is labeled with a unique ID. When traffic flows into a Hillstone device, the device will query for PBR rules by turn, and processes the traffic according to the first matched rule. However, the PBR rule ID is not related to the matching sequence during the query. You can move a PBR rule's location up or down at your own choice to adjust the matching sequence accordingly.
By default the configured PBR rules will take effect immediately. You can disable a rule to end its control over traffic.
To enable or disable a PBR rule, take the following steps:
To delete a policy-based route, take the following steps:
You can apply a policy-based route by binding it to an interface or zone. To apply a policy-based route, take the following steps:
To search the policy-based routes, take the following steps:
When searching the policy-based routes by an IP address, the system follows these principles:
The system supports the DNS redirect funtion, which redirects the DNS requests to a specified DNS server. For more informaiton about specifying IP addresses of the DNS server, see Configuring a DNS Server. Currently, the DNS redirect function is mainly used to redirect the video traffic for load balancing. With the policy based route working together, the system can redirect the Web video traffic to different links, improving the user experience.
To enable the DNS redirect function, take the following steps: