D-Link DFL-2500 User Guide - Page 107

Policy Based RoutingPBR

Page 107 highlights

88 Chapter 10. Routing Note As a result of this setup the return traffic from the router will be routed directly upon the local network with a standard "Allow" rule set. For this scenario to work the IP rule set must either dictate that the traffic for this network is to be NATed or forwarded without state tracking (FwdFast). 10.7 Policy Based Routing(PBR) 10.7.1 Overview Policy Based Routing(PBR) is an extension to normal routing described previously, which offers network administrators significant flexibility to implement their own defined policies on making routing decisions. By PBR, packets can go through a user desired route other than the routing algorithms decided one. Normal routing forwards packets according to destination IP address information derived from static routes or dynamic routing protocol. For example, by OSPF, the router will only take the least-cost(shortest) path that obtained from SPF calculation to transport packets. Complementing to this destination-address-solely concern, PBR gives more control over routing by enabling the router to use specific path for certain traffic flow based on various criterion, such as source addresses and service types. Moreover, D-Link firewalls extend the benefits of PBR further by not just looking at the packets one by one, but also at state information, so that the policy can provide control on both forward and return directions. PBR can be applied to applications including: • Source sensitive routing - When more than one ISP is used to provide Internet services, PBR can route traffic originating from different sets of users through different paths across the firewall. • Service based routing - PBR can route certain protocols through transparent proxies, such as Web caches and anti-virus scanners. D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

88
Chapter 10. Routing
Note
As a result of this setup the return traffic from the router will be routed
directly upon the local network with a standard ”Allow” rule set. For this
scenario to work the IP rule set must either dictate that the traffic for this
network is to be NATed or forwarded without state tracking (FwdFast).
10.7
Policy Based Routing(PBR)
10.7.1
Overview
Policy Based Routing(PBR)
is an extension to normal routing described
previously, which offers network administrators significant flexibility to
implement their own defined policies on making routing decisions. By PBR,
packets can go through a user desired route other than the routing
algorithms decided one.
Normal routing forwards packets according to destination IP address
information derived from static routes or dynamic routing protocol. For
example, by OSPF, the router will only take the least-cost(shortest) path
that obtained from SPF calculation to transport packets. Complementing
to this destination-address-solely concern, PBR gives more control over
routing by enabling the router to use specific path for certain traffic flow
based on various criterion, such as
source addresses
and
service types
.
Moreover, D-Link firewalls extend the benefits of PBR further by not just
looking at the packets one by one, but also at state information, so that the
policy can provide control on both forward and return directions.
PBR can be applied to applications including:
Source sensitive routing
– When more than one ISP is used to provide Internet services, PBR
can route traffic originating from different sets of users through
different paths across the firewall.
Service based routing
– PBR can route certain protocols through transparent proxies, such
as Web caches and anti-virus scanners.
D-Link Firewalls User’s Guide