AWS announces general availability of Policy-Based Routing on AWS Transit Gateway

AWS Transit Gateway Policy-Based Routing (PBR) Now Available
AWS Transit Gateway now supports Policy-Based Routing (PBR), providing network administrators with fine-grained control over traffic forwarding across their AWS network. PBR allows forwarding decisions based on packet attributes such as source and destination IP addresses, ports, and protocol.
Previously, customers requiring traffic steering or workload isolation had to build complex multi-VPC architectures, adding complexity and operational overhead. PBR simplifies this by extending Transit Gateway's native routing capabilities, enabling security architects and enterprise network teams to classify and direct traffic inline without additional infrastructure.
Customers can associate a policy table with a Transit Gateway attachment and define an ordered set of rules. Each rule classifies traffic and directs matching packets to a specified route table using first-match-wins logic. This supports use cases such as steering sensitive workloads through AWS Network Firewall or third-party inspection appliances, routing application traffic over AWS Direct Connect or AWS VPN paths based on source, port, or protocol, and isolating production and development environments into separate routing domains to limit lateral movement.
What to do
- Configure PBR using the AWS Management Console, AWS CLI, or AWS SDK.
- No additional charge beyond standard Transit Gateway fees.
PBR is available in all commercial AWS Regions where Transit Gateway is available. To learn more, visit the AWS Transit Gateway product page.
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



