Routing IP routing
Digi Connect IT® 4 User Guide
263
6. Type exit to exit the Admin CLI.
Depending on your device configuration, you may be presented with an Access selection
menu. Type quit to disconnect from the device.
Policy-based routing
Normally, a routing device determines how to route a network packet based on its destination
address. However, you can use policy-based routing to forward the packet based on other criteria,
such as the source of the packet. For example, you can configure the Connect IT 4 device so that high-
priority traffic is routed through the cellular connection, while all other traffic is routed through an
Ethernet (WAN) connection.
Policy-based routing for the Connect IT 4 device uses the following criteria to determine how to route
traffic:
n Firewall zone (for example, internal/outbound traffic, external/inbound traffic, or IPSec tunnel
traffic).
n Network interface (for example, the cellular connection, the WAN, or the LAN).
n IPv4 address.
n IPv6 address.
n MAC address.
n Domain.
n Protocol type (TCP, UDP, ICMP, or all).
The order of the policies is important. Routing policies are processed sequentially; as a result, if a
packet matches an earlier policy, it will be routed using that policy’s rules. It will not be processed by
any subsequent rules.
Configure a routing policy
Required configuration items
n The packet matching parameters. It can any combination of the following:
l Source interface.
l Source address. This can be a firewall zone, an interface, a single IPv4/IPv6 address or
network, or a MACaddress.
l Destination address. This can be a firewall zone, an interface, a single IPv4/IPv6 address or
network, or a domain.
l Protocol. This can be any, tcp, udp or icmp.
l Source port. This is only used if the protocol is set to tcp or udp.
l Destination port. This is only used if protocol is set to tcp or udp.
n The network interface used to reach the destination.
Additional configuration items
n A label for the routing policy.
n Whether packets that match this policy should be dropped when the gateway interface is
disconnected, rather than forwarded through other interfaces.
To configure a routing policy: