Notes: This feature requires Firewalla App 1.44 or higher, and the ability to route traffic to VPN connection is only available on Firewalla Box early access release v1.972.
What is Policy-based Routing?
In networking, network traffic is usually managed by the system's routing table; This routing table can either be static, or dynamic based on your network topology. Policy-Based Routing (PBR) is a technique used to make routing decisions based on policies set by the network admin.
The traditional Policy Based Routing is based on the IP layer, and also the services the network is running. Firewalla on the other hand, the Policy Based Routing is much more flexible, and also can be mapped to the destination category (gaming, video) or even specific applications (Zoom, Webex).
- The Firewalla PBR is content-based
- The PBR feature will primarily work if you have multiple WAN or VPN connection
- The PBR feature will be available on the Gold first
Benefits:
- You can specify any type of traffic and route them to your VPN servers, as long as the VPN is connected. (Available on early access Box v1.972)
- If you have a dual-WAN setup, you can route any traffic to any WAN connection no matter the WANs are set to failover or load balancing.
Use Cases:
- Routing all video traffic to a 3rd party VPN server (Available on early access Box v1.972)
- Routing all traffic on PC to the standby WAN
- Running Zoom or Gaming from a low latency WAN interface
How to use it?
On Firewalla Box main page, tap on Routes -> Add Route, specify any type of traffic, matching a device/group/network, and route it to any VPN connection or WAN connection.
Following Targets are supported in Routes:
- Domain
- IP Address
- IP Address Range
- Remote Port
- Region
- Internet
- All Gaming Sites
- All Social Sites
- All Video Sites
Comments
6 comments
It would be great if we could redirect specific apps using PBR. Ex: Netflix via VPN1, and Amazon via VPN2, etc
I’m looking at a policy that routes based on what wan is less latent, is that possible? Peplink has this but everything else has me convinced firewalla is the better choice
@sukumar, the VPN redirection can be done on 1.972.
@John, latency based routing is possible; Is the problem you are facing the ISP is getting congested?
I have two LTE connections, one has much more throughput, but worse latency, I’d like to have gaming/remote work go through the less latent path, and video to go over the other connection, and fail over still functional, I see some vendors have “lowest latency” which tracks on the 2nd/3rd hop, and the other, (and preferable) is “fastest response time” this would be ideal, because it could choose the connection based quickest path, which may end up being the other link, I know persistence can be a issue, and would also consider using this for web browsing.
@firewalla, I am on 1.972 early access and 1.44 beta, how do I enable app based VPN routing for Netflix etc?
@Sukumar, Hulu doesn't like Dual WAN so I used PBR to channel andy traffic to hulo.com to my WAN1. You should be able to do the same with Netflix.
Please sign in to leave a comment.