Enterprise Campus Solution

Policy-Based Routing Guide

Steer selected traffic with explicit policy while preserving normal routing behavior.

Back to Enterprise Campus Solutions

Overview

Policy-Based Routing (PBR) lets the network steer selected traffic according to policy rather than destination routing alone. It is useful for campus security, WAN edge selection, service insertion, migration, and special application paths.

PBR should be narrow and intentional. The default routing table should still carry normal traffic, while policy rules handle traffic that truly needs a different path.

When To Use PBR

ScenarioPBR Use
Firewall or inspection insertionSend selected VLANs or applications through security services.
WAN edge selectionSteer traffic from a branch, building, or application toward a chosen uplink.
MigrationRedirect legacy services while new routing is introduced.
Guest or IoT segmentationSend edge segments through controlled service paths.
TroubleshootingTemporarily steer a narrow class of traffic for validation.

Policy Components

ComponentPurposeDesign Note
Match criteriaDefines which traffic is selected.Keep selectors specific and documented.
Next hopDefines where selected traffic goes.Use reachable and monitored next hops.
FallbackDefines behavior when policy path fails.Avoid silent blackholing.
Application pointInterface or routing boundary where policy is applied.Apply close to the source when practical.

Traffic Flow

Packet enters xSONiC switch
        |
        v
Does it match PBR policy?
        | yes
        v
Forward to configured next hop
        |
        v
If no match or fallback applies, use normal routing table

Design Warnings

RiskMitigation
Policy sprawlKeep PBR limited to documented use cases.
Hidden asymmetric routingValidate return path and firewall state.
Next-hop failureDefine fallback and monitoring behavior.
Operational confusionLabel policies by business purpose, not only ACL number.
Overlapping match rulesOrder and test policy behavior carefully.

Deployment Checklist

  1. Document the business reason for each policy.
  2. Define exact source, destination, protocol, or segment matches.
  3. Confirm the intended next hop and return path.
  4. Decide fallback behavior for next-hop failure.
  5. Apply policy at a controlled boundary and test with representative traffic.
  6. Monitor counters to confirm policy hit rate and path behavior.

xSONiC Platform Fit

XS-AA access and aggregation switches fit PBR use cases at campus routing boundaries. They can steer guest, IoT, branch, or selected application traffic toward firewall, WAN, inspection, or migration paths while preserving normal routing for the rest of the network.

Related Products

Products commonly paired with this solution.

Use these related platforms as a starting point for sizing, comparison, and follow-up discussion.

XS-AA-24X1-4X25-ACC front panel product image

XS-AA-24X1-4X25-ACC

Access & Aggregation

24x 1G RJ45 campus access switch with 4x 25G SFP28 for enterprise access and aggregation networks.

124Gbps class
Campus switching class
XS-AA-48X1-4X25-ACC front panel product image

XS-AA-48X1-4X25-ACC

Access & Aggregation

48x1G RJ45 access switch with 4x25G uplinks for campus edge, SMB, and enterprise access deployments.

210Gbps
510Mpps
XS-AA-48X1-6X25-ACC front panel product image

XS-AA-48X1-6X25-ACC

Access & Aggregation

48x 1G RJ45 campus access switch with 6x 25G SFP28 for enterprise access and aggregation networks.

198Gbps class
Campus switching class
XS-AA-24X10-6X100-AGG front panel product image

XS-AA-24X10-6X100-AGG

Access & Aggregation

24x10G aggregation switch with 6x100G uplinks for campus distribution, private cloud leaf, and enterprise core roles.

1.2Tbps
890Mpps
XS-AA-48X10-6X100-AGG front panel product image

XS-AA-48X10-6X100-AGG

Access & Aggregation

48x 10G SFP+ aggregation/core switch with 6x 100G QSFP28 for enterprise access and aggregation networks.

1.1Tbps class
Campus switching class
XS-AA-48X25-8X100-AGG front panel product image

XS-AA-48X25-8X100-AGG

Access & Aggregation

48x 25G SFP28 aggregation/core switch with 8x 100G QSFP28 for enterprise access and aggregation networks.

2Tbps class
Campus switching class
XS-AA-32X100-CORE front panel product image

XS-AA-32X100-CORE

Access & Aggregation

32x 100G QSFP28 aggregation/core switch with 2x 10G SFP+ auxiliary for enterprise access and aggregation networks.

3.2Tbps class
Campus switching class
Next Step

Move from Policy-Based Routing Guide into implementation.

Use the related products below to continue comparing platforms, or open a conversation if you need help mapping the solution to your environment.