Skip to main content

Layer 7 Application Policy-base Route (PBR)

Last updated: October 24, 2024

s
Written by shuochun su
Updated over 11 months ago

Using EnGenius' advanced layer 7 traffic analysis technology, you can create policy-based routing rules to direct specific applications to different WAN interfaces without specifying IP addresses or port ranges.

Traditional Layer 3 PBR often struggles with applications that frequently change IP addresses or use multiple IPs, making it hard to maintain effective rules. EnGenius' Layer 7 PBR solves this by:

  • Routing Specific Applications and Categories: Identify and route traffic based on application signatures

  • Adapting to Changes: Automatically adjust to changes in application behavior and infrastructure

  • Simplifying Management: Focus on applications and categories instead of constantly changing network parameters

Benefits

  • Optimized Traffic Management: Direct critical applications to a primary WAN while routing less important traffic to a secondary WAN

  • Enhanced Network Performance: Improve network efficiency by balancing load between WAN interfaces based on application

  • Simplified Rule Management: No need to update routing rules for changing IP addresses or port ranges

Application Example

Enterprises are increasingly relying on SaaS services such as Gmail, Windows 365, and CRM tools like Salesforce.com, making these services more critical than other internet traffic that it is better to separate the traffic from others. In this scenario, users can strategize as follows:

  1. Designate WAN1 as the primary WAN and WAN2 as the failover WAN, with most traffic routed through WAN1

  2. Route business-critical SaaS traffic, such as Gmail, Windows 365, and Salesforce.com, through WAN2

This approach allows users to segregate traffic based on application type, ensuring a dedicated WAN bandwidth for business-critical SaaS traffic.

Configuration Steps

The figure below illustrates layer 7 policy-based routing rules for directing entire categories and specific applications within a category to different WAN interfaces

  1. Go to Configure > Gateway > Interfaces > Policy Routes > Layer 7 to add rule

  2. Input Src. IP if you need to block a specific source IP address

  3. Select an Applications to be blocked, using the second drop-down to be more specific if necessary.

Note:

  • PBR preference uplink can be WAN1 and WAN2 only

  • Failover order options are as follows:

    • Option WAN1: WAN1 is the preferred uplink, followed by WAN2 and then WWAN.

    • Option WAN2: WAN2 is the preferred uplink, followed by WAN1 and then WWAN.

  • PRB fail-over will NOT refer to the "Fail-over preference" order set in WWAN (Configure > WWAN > Failover Preference).

  • Refer to Layer 7 Application Firewall Rule for detailed L7 categories and applications.

Did this answer your question?