Provides instructions to configure a policy-based routing policy to steer WebEx traffic through preferred interfaces for optimal performance in Firewall Management Center (FMC).
You can configure the PBR policy with path monitoring in the Policy Based Routing page. In this example, WebEx application traffic is forwarded to the interface that has the least traffic loss.
Before you begin
To use the path monitoring metrics for configuring the traffic forwarding priority over egress interfaces, you must configure the path monitoring settings for the interfaces. See
Configure Path Monitoring Settings.
Procedure
|
1. |
Choose , and edit the threat defense device (NGFWBR1). |
|
2. |
Click the Routing tab on the interface view of NGFWBR1. |
|
3. |
Click Policy Based Routing.
The Policy Based Routing page displays the configured policy. The grid displays the list of ingress interfaces and a combination of the policy-based route access list, and egress interfaces.
|
|
4. |
To configure the policy, click Add. |
|
5. |
In the Add Policy Based Route dialog box, select inside from the Ingress Interface drop-down list.
Note
Only interfaces that have logical names and that belong to a global virtual router are listed in the drop-down.
|
|
6. |
To specify the match criteria and the forward action in the policy, click Add. |
|
7. |
In the Add Forwarding Actions dialog box, do the following:
-
From the Match ACL drop-down, choose DIA_Collaboration.
-
To select the configured interfaces, choose Egress Interfaces from the Send To drop-down list.
-
Choose Minimal Packet Loss from the Interface Ordering drop-down list.
The traffic is forwarded to the interface that has the minimal packet loss.
-
In the Available Interfaces box, all the interfaces are listed. From the list of interfaces, click the Add ( )icon to add the selected egress interface.
For our scenario:
-
From Available Interfaces, click the Add ( ) icon adjacent to outside3 interface to move it to Selected Egress Interfaces.
-
Then click the Add ( ) icon adjacent to outside2 interface to move it to Selected Egress Interfaces.
-
Click Save to write the changes for the match criteria.
-
Review the configuration and click Save to write all the configuration changes for policy based routing.
|
|
8. |
Click Save. |