5.3 Policy-Based Routing (PBR) Architecture, Configuration, and Route-Maps
Key Takeaways
Policy-Based Routing (PBR) intercepts packets before the standard destination-based routing table lookup, directing traffic based on source IP, packet length, protocol, or application port.
Route-maps evaluate statements sequentially by sequence number; an implicit deny exists at the end of every route-map, returning unmatched traffic to normal destination routing.
The
set ip next-hopdirective overrides the standard routing table for reachable next-hops, whereasset ip default next-hopis evaluated only when no explicit, non-default destination route exists in the routing table.Interface PBR (
ip policy route-map) processes transit packets entering an interface, while Local PBR (ip local policy route-map) processes packets generated by the router itself.PBR operational verification relies on
show route-mapto inspect match counters,show ip policyto verify interface bindings, anddebug ip policyto trace real-time policy execution.
Policy-Based Routing (PBR) Architecture, Configuration, and Route-Maps
Traditional IP forwarding operates strictly on a destination-driven paradigm: a router evaluates incoming packets against its local routing table (RIB) and selects the best exit interface solely based on the destination IP address and Longest Prefix Match (LPM). However, enterprise networks frequently require customized traffic forwarding that overrides standard routing tables. Policy-Based Routing (PBR) provides network engineers with granular control, allowing packets to be steered based on source IP address, transport layer protocol, application port numbers, packet length, or Quality of Service (QoS) markings.
Enterprise PBR Architecture and Use Cases
PBR functions as a programmable bypass mechanism inserted directly into the router's packet forwarding path:
Incoming Packet on Interface
|
v
[Is PBR Enabled on Interface?]
/ \
YES NO
/ \
[Evaluate Route-Map] v
| | [Standard Destination Routing Table]
MATCH NO MATCH |
| | v
v +-----> [Normal Forwarding / Next-Hop]
[Apply 'Set' Action]
(e.g., Force ISP 2)
Primary Enterprise Use Cases
- Multi-Homed ISP Selection: Steering latency-sensitive voice and critical SaaS traffic through a premium primary ISP link while shunting bulk data or backup replication over an inexpensive secondary circuit.
- Security Inspection Steering: Forcing specific user subnets or suspicious traffic through dedicated out-of-path security appliances (such as web proxies, firewalls, or IDS sensors) without re-architecting physical cabling.
- QoS Policy Routing: Classifying traffic at the edge and assigning specific next-hop paths or IP Precedence/DSCP values to protect business-critical flows.
- Equal-Cost Multi-Path Override: Bypassing standard hashing algorithms to pin specific traffic streams to deterministic transit interfaces.
Route-Map Anatomy and Processing Semantics
PBR relies on route-maps to define match criteria and forwarding actions. A route-map consists of named statement blocks ordered by sequence numbers:
route-map PBR_POLICY permit 10
match ip address 101
set ip next-hop 198.51.100.1
!
route-map PBR_POLICY permit 20
match ip address 102
set ip next-hop 203.0.113.1
Route-Map Processing Rules
- Sequential Evaluation: Route-maps evaluate statements in ascending sequence number order (e.g., 10, then 20, then 30). As soon as a packet matches a statement, evaluation terminates and the corresponding
setaction executes. - Permit vs. Deny in Route-Maps:
permit: If the packet matches thematchclause, the router applies thesetaction.deny: If the packet matches thematchclause, the router ceases policy routing for this packet. The packet falls through to standard destination-based routing.
- Implicit Deny: Every route-map terminates with an unwritten implicit deny. Packets that fail to match any sequence number exit the route-map and undergo standard destination-based routing table lookups. Packets are never dropped by an implicit deny in PBR.
The Matrix of Route-Map and ACL Logic
When an Access Control List (ACL) is called within a match ip address statement, the combination of ACL action and route-map action dictates the forwarding outcome:
| Route-Map Clause | ACL Condition | Resulting Router Action |
|---|---|---|
permit 10 | permit | Match Successful: Execute the set actions configured in sequence 10. |
permit 10 | deny | No Match: Skip remaining statements in sequence 10; advance to sequence 20. |
deny 10 | permit | Policy Exemption: Cease PBR processing immediately. Route packet via normal routing table. |
deny 10 | deny | No Match: Skip remaining statements in sequence 10; advance to sequence 20. |
Next-Hop Forwarding Directives: set ip next-hop vs. set ip default next-hop
The most critical architectural distinction in PBR lies between set ip next-hop and set ip default next-hop:
Incoming Packet
|
+---------------------+---------------------+
| |
[set ip next-hop] [set ip default next-hop]
| |
Is next-hop reachable? Does an explicit route exist
/ \ in RIB (excluding 0.0.0.0/0)?
YES NO / \
/ \ YES NO
v v / \
Forward via PBR Fallback to standard Forward via Forward via PBR
next-hop routing table standard explicit default next-hop
RIB route
| Parameter | set ip next-hop | set ip default next-hop |
|---|---|---|
| Evaluation Timing | Evaluated BEFORE the standard destination routing table lookup. | Evaluated AFTER checking the standard routing table for explicit routes. |
| Override Behavior | Overrides all specific routes in the routing table (e.g., /32, /24), provided the target next hop is reachable. | Does NOT override explicit destination routes in the routing table. |
| Default Route Interaction | Completely ignores any default route (0.0.0.0/0) in the routing table. | Overrides the default route (0.0.0.0/0) in the routing table if no specific route matches. |
| Typical Use Case | Dedicated policy steering (e.g., force all marketing traffic out ISP 2 regardless of destination). | Backup path steering (e.g., route via primary WAN for corporate subnets, but send unknown Internet traffic to proxy). |
Interface Directives: PBR also supports
set interface <type/number>andset default interface <type/number>. These directives should only be used on point-to-point connections (such as serial links or GRE tunnels). Usingset interfaceon a multiaccess Ethernet segment causes excessive ARP lookups for every destination IP, exhausting router memory and CPU resources.
Interface PBR vs. Local PBR
Routers process transit packets passing through interfaces differently from packets generated locally by the router's own control plane:
1. Interface PBR (ip policy route-map)
Applied to an ingress physical interface, subinterface, or VLAN interface (SVI). It evaluates transit traffic entering the router from downstream devices:
interface GigabitEthernet0/0/1
description Ingress LAN from Campus
ip policy route-map LAN_STEERING
Packets originated by the router itself (e.g., ping commands executed on the CLI, SNMP traps, Syslog messages, or BGP update packets) completely bypass interface PBR.
2. Local PBR (ip local policy route-map)
Applied globally to inspect and redirect traffic originated locally by the router:
ip local policy route-map ROUTER_MANAGEMENT_POLICY
This command enables network administrators to direct management or monitoring traffic out a dedicated out-of-band management interface or secondary WAN link.
Step-by-Step Cisco IOS PBR Configuration
Consider an enterprise edge router dual-homed to two ISPs:
ISP_1Next-Hop:198.51.100.1(connected viaGigabitEthernet0/0/1)ISP_2Next-Hop:203.0.113.1(connected viaGigabitEthernet0/0/2)- Ingress LAN Interface:
GigabitEthernet0/0/0
Business Objective: Route Voice over IP (VoIP) and video traffic (marked DSCP EF or CS4) out ISP_1. Route Guest Wi-Fi subnet (172.16.50.0/24) out ISP_2. Allow all other enterprise data to follow standard routing.
! Step 1: Define classification ACLs
ip access-list extended ACL_REALTIME_TRAFFIC
permit ip any any dscp ef
permit ip any any dscp cs4
!
ip access-list extended ACL_GUEST_WIFI
permit ip 172.16.50.0 0.0.0.255 any
!
! Step 2: Build the route-map with sequence numbers and set clauses
route-map PBR_EDGE_POLICY permit 10
description Direct Voice and Video out ISP 1
match ip address ACL_REALTIME_TRAFFIC
set ip next-hop 198.51.100.1
!
route-map PBR_EDGE_POLICY permit 20
description Direct Guest Wi-Fi out ISP 2
match ip address ACL_GUEST_WIFI
set ip next-hop 203.0.113.1
!
! Step 3: Attach the route-map to the ingress interface
interface GigabitEthernet0/0/0
description Ingress User LAN
ip address 10.1.1.1 255.255.255.0
ip policy route-map PBR_EDGE_POLICY
PBR Verification and Troubleshooting
Network engineers verify and troubleshoot PBR deployments using dedicated operational commands:
show route-map [map-name]: Displays route-map configuration, sequence numbers, and vital match counters indicating how many packets and bytes have matched each sequence clause.show ip policy: Lists all interfaces whereip policy route-mapis actively applied along with the bound route-map name.show ip local policy: Displays the globally configured local policy route-map applied to self-generated router packets.debug ip policy: Generates real-time console messages for each packet evaluated by PBR, displaying the source/destination IP, matching sequence number, and designated next-hop, or indicating if the packet fell through to the normal routing table (routed normal).
An administrator configures a route-map with 'set ip default next-hop 192.0.2.1'. The router holds an explicit route for destination 10.10.10.0/24 via 198.51.100.1 and a default route (0.0.0.0/0) via 203.0.113.1. When a packet matching the route-map arrives for destination 10.10.10.50, how does the router forward it?
The router drops the packet due to conflicting next-hop directives between PBR and the routing table.
The router forwards the packet to 192.0.2.1 because PBR unconditionally overrides the routing table.
The router forwards the packet to 203.0.113.1 according to the default route.
The router forwards the packet to 198.51.100.1 because an explicit destination route exists in the routing table.
A network engineer must redirect SNMP traps and Syslog messages generated locally by a core router out a dedicated management gateway rather than the default WAN interface. Which configuration approach is required?
Attach 'ip policy route-map MGT-POLICY' to the loopback interface used as the management source IP.
Configure 'ip local policy route-map MGT-POLICY' in global configuration mode.
Enable 'ip route-cache policy' globally and apply the route-map to the console line.
Configure 'ip policy route-map MGT-POLICY' on all physical ingress interfaces.
In a route-map applied for interface Policy-Based Routing, sequence 10 is configured with a 'deny' statement matching subnet 10.1.1.0/24. What happens when a packet originating from 10.1.1.50 enters the interface and matches sequence 10?
The packet is dropped immediately and an ICMP Destination Unreachable message is returned.
The packet proceeds to sequence 20 of the route-map to check whether any later permit statement applies a policy override.
The packet exits the route-map without applying any 'set' actions and is forwarded using the normal routing table.
The packet is redirected to interface Null0 because of the explicit deny action.
Sections you finish are checked off in the contents.