Course menu

Module 4: Routing and SD-WANLesson 4.2 (2 of 4 in this module)16 of 18 in the FortiGate Administrator course

Policy routes

Sending traffic by source, protocol or port instead of destination, the order of route lookups, and the stop-policy-routing action.

Intermediate · 9 min read

What you will learn

After this lesson, you can send selected traffic out of a different link with a policy route, explain where policy routes sit in the lookup order, and use stop policy routing to make exceptions.

  • Policy-based routing
  • Lookup order
  • Stop policy routing

A policy route (policy-based route) forwards traffic based on fields other than the destination alone: incoming interface, source address, protocol, ports or ToS/DSCP. FortiOS checks policy routes before SD-WAN rules and the routing table; the first match decides the outgoing interface and gateway, and a 'stop policy routing' entry sends matching traffic back to normal routing.

In simple terms: Normal routing asks 'where is it going?'. A policy route can also ask 'who sent it, and what is it?', and choose a different exit.

A real-life situation

FGT1 now has two ISPs: port1 (primary) and port4 (192.0.2.2/30, gateway 192.0.2.1). The mail server 10.0.1.50 must send mail only from ISP2, because the domain's SPF record lists ISP2's address. Everything else uses ISP1. The destination of outgoing mail is "anywhere", so a normal route can't express this. A policy route can.

Where policy routes sit

1. Policy routes
config router policy, top-down. Match → use its interface and gateway.
2. SD-WAN rules
If SD-WAN is enabled and a rule matches, use the member it selects.
3. Routing table
Longest prefix, distance and priority, as usual.
For a new session, FortiOS looks for a path in this order and stops at the first match.

Configure the policy route

config router policy edit 1 set input-device "port2" set src "10.0.1.50/255.255.255.255" set dst "0.0.0.0/0.0.0.0" set protocol 6 set start-port 25 set end-port 25 set gateway 192.0.2.1 set output-device "port4" next end

Matches SMTP (TCP 25) from the mail server arriving on port2 and sends it to ISP2. A firewall policy port2 → port4 with NAT must allow it.

Exceptions: stop policy routing

A broad policy route can catch traffic it shouldn't, for example traffic from 10.0.1.50 to the DMZ. Put an exception above it that hands that traffic back to the routing table:

config router policy edit 2 set input-device "port2" set src "10.0.1.0/255.255.255.0" set dst "10.0.0.0/255.0.0.0" set action deny next move 2 before 1 end

In the CLI the 'stop policy routing' action is action deny. It doesn't block anything: internal traffic simply skips the remaining policy routes and uses the routing table.

Verify

Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # diagnose firewall proute list
list route policy info(vf=root):

id=2 ... action(deny) iif=5(port2) ...
source(1): 10.0.1.0-10.0.1.255
destination(1): 10.0.0.0-10.255.255.255

id=1 ... protocol=6 sport=0-65535 iif=5(port2) dport=25 oif=7(port4) gwy=192.0.2.1
source(1): 10.0.1.50-10.0.1.50
destination(1): 0.0.0.0-255.255.255.255
hit_count=12 ...
Each policy route with its match fields, outgoing interface, gateway and hit count. (Example output, trimmed.) Debug flow also names the decision for a session, for example a line saying a policy route was matched.

Why it works this way

Destination routing can't tell two flows to the same destination apart. Checking policy routes first lets an administrator override the routing table for chosen traffic, and stop policy routing lets broad rules have precise exceptions without copying them.

Common mistakes

  • Adding the policy route but no firewall policy for the new interface pair.
  • Writing a broad policy route (source the whole LAN, any destination) that also catches internal and VPN traffic.
  • Forgetting that policy routes beat SD-WAN rules and the routing table, then wondering why a route change has no effect.

Key takeaways

✅ Key takeaways
  • Policy routes match on incoming interface, source, destination, protocol, ports and ToS.
  • Lookup order: policy routes, then SD-WAN rules, then the routing table.
  • action deny means stop policy routing: fall back to normal routing, not drop.
  • A firewall policy must still allow the traffic out of the chosen interface.

Check yourself

Predict · scenario 1

A policy route sends 10.0.1.50's traffic to port4, and the routing table's default route points to port1. Where does 10.0.1.50's matching traffic go?

Predict · scenario 2

What does a policy route with action deny (stop policy routing) do to matching traffic?

FAQ

Does a policy route replace the firewall policy?
No. The policy route picks the outgoing interface; a firewall policy for that interface pair must still allow the traffic, with NAT if it goes to the Internet.
Should I use policy routes or SD-WAN rules?
For steering traffic between Internet links, SD-WAN rules are usually better: they can follow link quality and application. Policy routes suit fixed exceptions, for example one server that must always use one link.