A real-life situation
FGT1 now has two ISPs: port1 (primary) and port4 (192.0.2.2/30, gateway 192.0.2.1). The mail server 10.0.1.50 must send mail only from ISP2, because the domain's SPF record lists ISP2's address. Everything else uses ISP1. The destination of outgoing mail is "anywhere", so a normal route can't express this. A policy route can.
Where policy routes sit
Configure the policy route
config router policy
edit 1
set input-device "port2"
set src "10.0.1.50/255.255.255.255"
set dst "0.0.0.0/0.0.0.0"
set protocol 6
set start-port 25
set end-port 25
set gateway 192.0.2.1
set output-device "port4"
next
endMatches SMTP (TCP 25) from the mail server arriving on port2 and sends it to ISP2. A firewall policy port2 → port4 with NAT must allow it.
Exceptions: stop policy routing
A broad policy route can catch traffic it shouldn't, for example traffic from 10.0.1.50 to the DMZ. Put an exception above it that hands that traffic back to the routing table:
config router policy
edit 2
set input-device "port2"
set src "10.0.1.0/255.255.255.0"
set dst "10.0.0.0/255.0.0.0"
set action deny
next
move 2 before 1
endIn the CLI the 'stop policy routing' action is action deny. It doesn't block anything: internal traffic simply skips the remaining policy routes and uses the routing table.
Verify
FGT1 # diagnose firewall proute list list route policy info(vf=root): id=2 ... action(deny) iif=5(port2) ... source(1): 10.0.1.0-10.0.1.255 destination(1): 10.0.0.0-10.255.255.255 id=1 ... protocol=6 sport=0-65535 iif=5(port2) dport=25 oif=7(port4) gwy=192.0.2.1 source(1): 10.0.1.50-10.0.1.50 destination(1): 0.0.0.0-255.255.255.255 hit_count=12 ...
Why it works this way
Destination routing can't tell two flows to the same destination apart. Checking policy routes first lets an administrator override the routing table for chosen traffic, and stop policy routing lets broad rules have precise exceptions without copying them.
Common mistakes
- Adding the policy route but no firewall policy for the new interface pair.
- Writing a broad policy route (source the whole LAN, any destination) that also catches internal and VPN traffic.
- Forgetting that policy routes beat SD-WAN rules and the routing table, then wondering why a route change has no effect.
Key takeaways
- Policy routes match on incoming interface, source, destination, protocol, ports and ToS.
- Lookup order: policy routes, then SD-WAN rules, then the routing table.
- action deny means stop policy routing: fall back to normal routing, not drop.
- A firewall policy must still allow the traffic out of the chosen interface.
Check yourself
A policy route sends 10.0.1.50's traffic to port4, and the routing table's default route points to port1. Where does 10.0.1.50's matching traffic go?
What does a policy route with action deny (stop policy routing) do to matching traffic?