AWS announces general availability of Policy-Based Routing on AWS Transit Gateway
AWS Transit Gateway now offers Policy-Based Routing, enabling granular traffic control based on packet attributes without complex multi-VPC architectures
AWS Transit Gateway now supports Policy-Based Routing (PBR), providing network administrators with granular control over traffic forwarding. With PBR, forwarding decisions can be based on packet attributes such as source and destination IP addresses, ports, and protocol, rather than destination IP address alone. Previously, customers needed multi-VPC architectures with additional routing hops for traffic steering or workload isolation, adding complexity and operational overhead. PBR eliminates this by extending Transit Gateway's native routing capabilities, allowing security architects and enterprise network teams to classify and direct traffic inline without extra infrastructure. Customers associate a policy table with a Transit Gateway attachment and define an ordered set of rules. Each rule classifies traffic and directs matching packets to a specified route table using first-match-wins logic. This supports use cases such as steering sensitive workloads through AWS Network Firewall or third-party inspection appliances, routing application traffic over AWS Direct Connect or AWS VPN paths based on source, port, or protocol, and isolating production and development environments into separate routing domains. Policy-Based Routing for AWS Transit Gateway is available in all commercial AWS Regions where Transit Gateway is available. It can be configured using the AWS Management Console, AWS CLI, and AWS SDK. PBR incurs no additional charge beyond standard Transit Gateway fees