Announcing general availability of Policy-Based Routing on Amazon Transit Gateway
Amazon Transit Gateway now supports Policy-Based Routing (PBR), giving network administrators granular control over how traffic is forwarded across their Amazon Web Services China network. With PBR, forwarding decisions can be based on a combination of packet attributes including source and destination IP addresses, ports, and protocol rather than destination IP address alone.
Previously, customers needing traffic steering or workload isolation had to build multi-VPC architectures with additional routing hops, adding complexity and operational overhead. PBR eliminates this by extending Transit Gateway's native routing capabilities, enabling security architects and enterprise network teams to classify and direct traffic inline without extra infrastructure. Customers associate a policy table with a Transit Gateway attachment and define an ordered set of rules. Each rule classifies traffic and directs matching packets to a specified route table using first-match-wins logic. This supports use cases such as steering sensitive workloads through Amazon Network Firewall or third-party inspection appliances, routing application traffic over Direct Connect paths based on source, port, or protocol, and isolating production and development environments into separate routing domains to limit lateral movement.
You can configure this feature using the Amazon Web Services Management Console, Amazon Command Line Interface (Amazon CLI), and the Amazon Software Development Kit (SDK). PBR incurs no additional charge beyond standard Transit Gateway fees. To learn more about Policy-Based Routing for Amazon Transit Gateway, visit the Amazon Transit Gateway product page .