Policy-Based Routing (PBR) provides a mechanism to override traditional destination-based routing lookup decisions. Instead of inspecting only the destination IP address in the Routing Information Base (RIB), PBR allows network administrators to classify traffic based on criteria such as Source IP address, Protocol type, L4 Port numbers, or QoS Precedence/DSCP markings, and force traffic onto designated next-hop paths.
Key Architecture & Components
Access Control Lists (ACLs): Used to match specific traffic criteria (e.g., Extended ACL matching Voice subnet 10.1.10.0/24 or HTTP port 80).
Route-Maps: Programmatic logic structures with `match` and `set` statements that enforce routing actions:
match ip address [ACL]: Identifies candidate traffic.
set ip next-hop [IP]: Forces packets out an explicit adjacent IPv4 gateway.
set interface [Interface]: Directs packets out a specific egress interface.
set default ip next-hop: Evaluates policy first; falls back to destination lookup if next-hop unreachable.
Inbound Interface Binding: PBR policies are applied to ingress interfaces using the ip policy route-map [NAME] command.
Local PBR: Policy routing for traffic originated by the router itself using ip local policy route-map [NAME].
PBR Processing Workflow
Match Hit: Packet matching a `permit` route-map clause is redirected to the configured next-hop regardless of RIB entry.
Match Miss / Fallthrough: Unmatched traffic falls through the route-map and defaults to traditional destination-based RIB routing.