Assigning PBR Policies to User Role or VLAN

To assign a PBR Policy-based Routing. PBR provides a flexible mechanism for forwarding data packets based on polices configured by a network administrator. policy to a user role or a VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN., complete the following steps:

  1. To assign a policy to a user role, see Configuring User Roles for Clients.
  2. To assign a policy to a VLAN, complete the following steps:
    1. To configure a gateway group or a gateway device, complete either one of these steps:
      • To select a gateway group:

        1. In the Classic Central app, set the filter to a group that contains at least one Branch Gateway.

          The dashboard context for a group is displayed.

        2. Under Manage, click Devices > Gateways.

          A list of gateways is displayed in the List view.

        3. Click Config.

          The configuration page is displayed for the selected group.

      • To select a gateway:

        1. In the Classic Central app, set the filter to Global or a group that contains at least one Branch Gateway.

        2. Under Manage, click Devices > Gateways.

          A list of gateways is displayed in the List view.

        3. Click a gateway under Device Name.

          The dashboard context for the gateway is displayed.

        4. Under Manage, click Device.

          The gateway device configuration page is displayed.

  3. If you are in the Basic Mode, click Advanced Mode to access the advanced configuration options.
  4. Click Security> Apply Policy tab.
  5. Select a VLAN from the VLANs table.
  6. Select a routing policy from the Route ACL drop-down list.
  7. Click Save Settings.

The following animation shows you how to assign a PBR policy to a user role or a VLAN.