Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure a Policy Based Routing Policy for YouTube

Updated: February 5, 2026

Overview

Provides instructions to configure a policy-based routing policy to steer YouTube traffic across selected internet interfaces in Firewall Management Center (FMC).

You can configure the PBR policy in the Policy Based Routing page by specifying the ingress interfaces, match criteria (Extended Access Control List), and egress interfaces to route YouTube traffic.

The YouTube traffic is load balanced between the outside and outside2 interfaces and falls back to the outside3 if both the links fail.

Procedure

1.

Select Devices > Device Management, and edit the threat defense device (NGFWBR1).

2.

Click the Routing tab on the interface view of NGFWBR1.

3.

Click Policy Based Routing.

The Policy Based Routing page displays the configured policy. The grid displays the list of ingress interfaces and a combination of the policy-based route access list, and egress interfaces.

4.

To configure the policy, click Add.

5.

In the Add Policy Based Route dialog box, select inside from the Ingress Interface drop-down list.

Note

Only interfaces that have logical names and that belong to a global virtual router are listed in the drop-down.

6.

To specify the match criteria and the forward action in the policy, click Add.

7.

In the Add Forwarding Actions dialog box, do the following:

  1. From the Match ACL drop-down, choose DIA_SocialMedia.

  2. To select the configured interfaces, choose Egress Interfaces from the Send To drop-down list.

  3. Choose By Priority from the Interface Ordering drop-down list.

    Traffic is routed to the interface with the least priority value first. When the interface is not available, the traffic is then forwarded to the interface with the next lowest priority value. For example, let us assume that outside2 and outside3 are configured withpriority values 10 and 20 respectively. The traffic is forwarded to outside2. If outside2 becomes unavailable, the traffic is then forwarded to outside3.

  4. In the Available Interfaces box, all the interfaces with their priority values are listed. Click the Add (add icon) icon to add the selected egress interface.

    For our scenario:

    1. From Available Interfaces, click the Add (add icon) icon adjacent to outside and outside2 interfaces to move it to Selected Egress Interfaces.

    2. Then click the Add (add icon) icon adjacent to outside3 interface to move it to Selected Egress Interfaces.

  5. Click Save to write the changes for the match criteria.

  6. Review the configuration and click Save to write all the configuration changes for policy based routing.

8.

Click Save.