Showing results for 
Search instead for 
Did you mean: 

How to perform Policy Based Routing in ACI via L3OUT

Level 1
Level 1

Hi Folks,

I have a use case for Policy Based Routing to perform PBR based on specific Source and Destination IP via L3OUT in ACI. Below mentioned is the scenario.  There is an EPG-1 where I have a VM and we have a default route towards Firewall to access WAN and Internet. But we also have a Router connected to reach the specific remote site destinations. The requirement is that if any of my VM to need to access any network, traffic must be sent to Firewall which is currently working Fine but if the Source is particular VM and the destination IP in packet then the traffic must be sent to the Router via 2nd L3out. 

Please guide, how this requirement can be achieved.

PBR scenario.jpg

2 Replies 2

Cisco Employee
Cisco Employee

Hi @harpreetbatra,


You can have two separate L3outs for two different Purpose. Routing should take Precedence choosing longest-prefix match.

So If a default route is coming in L3Out-1 and you have more specifics prefixes in L3Out-2 then then routing will automatically choose second L3out to send the traffic towards external router as long as required contracts are in place.


Please follow the link for PBR related configurations.


If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.

You can also learn more about Cisco ACI through our live Ask the Experts (ATXs) session. Check out Cisco ACI ATXs Resources [] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.


I have the same use case scenario trying to solve...Wondering if you got your solution, even the post is 2-year old now...

Save 25% on Day-2 Operations Add-On License