Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Configure a PBR Policy for DNS and Web Traffic

Updated: February 5, 2026

Overview

Provides instructions to configure a policy-based routing policy in Firewall Management Center (FMC) to steer Threat Defense (FTD) DNS and web traffic to the Cisco Umbrella SIG tunnel.

You can configure the PBR policy in the Policy Based Routing page by specifying the ingress interfaces, match criteria (extended access control list), and egress interfaces to route DNS and web traffic.

Procedure

1.

Choose Devices > Device Management, and edit the threat defense device (NGFWBR1).

2.

Click the Routing tab on the interface view of NGFWBR1.

3.

Click Policy Based Routing.

4.

In the Add Policy Based Route dialog box, select the Ingress Interface from the drop-down list.

5.

To specify the match criteria and the forward action in the policy, click Add.

6.

In the Add Forwarding Actions dialog box, do the following:

  1. From the Match ACL drop-down, choose LAN_to_Internet.

  2. To select the configured interfaces, choose Egress Interfaces from the Send To drop-down list.

  3. From Available Interfaces, click the Add (add icon) icon adjacent to Outside_static_vti_1 interface to move it to Selected Egress Interfaces.

  4. Click Save to write the changes for the match criteria.

  5. Review the configuration and click Save to write all the configuration changes for policy based routing.

7.

Click Save.

The PBR policy is created as seen in the figure below.

Details of PBR policy