---
title: "Configure application group routing"
canonical: "https://docs.aryaka.com/space/KNOW/1642650/Configure%20application%20group%20routing"
format: markdown
---
The Routing tab is the second of three configuration tabs accessed from the Add Application Group Policy page. This topic assumes you have completed the configuration on the first tab as described in  Configure application group policy information , then will complete the configuration on the VPN Path Aryaka tab. The Routing tab allows you to customize the routing behavior of your application group. This custom routing configuration is applied to VPN zones and DMZ zones. Note: Zone customization is optional. If you do not want to customize the routing of the application group, skip this step and continue the creation of you application group policy as described in   Customize VPN Path Aryaka . You can view the default routing behavior on the Config > Zones page as described in  Configure zones . You can customize one zone and use default routing for the other. If you customize one zone and route the traffic to a network other than VPN Path Aryaka, the icon for the VPN Path Aryaka customization  is not  displayed. The VPN Path Aryaka icon  does  appear under the following circumstances: No customizations have been made to zones. Any customizations that were made involve VPN Path Aryaka. To customize VPN zone routing Click  Add New  in the VPN Zone Customization pane. The Details pane appears. Enter a name for your custom routing configuration. (Optional) Enter a description of the customization. Click  Add  in the Source VPN Zones pane. The Add Source Zone dialog appears. Do one of the following: Click one or more zones in the Name column. The selected applications appear highlighted in a dark band. Click  Select All  to select  every  zone. This can result in a large, difficult-to-mange list of zones. Enter a text string in the Search field, then select one or more of the results or click  Select All  to select all of the matching search results. Click  Add Selected . The selected zones appear in the table in the Source VPN Zones pane. Click the  Permit Access  toggle in the Routing pane. The associated routing fields appear. Click the  Route To  drop-down list, then select one of the following options to determine where the application traffic is routed: Direct Internet—If you select this option, provide the following information:  Click  Default  or  Custom  in the Internet Interface field.  Default allows the ANAP to select the healthier link available at the site as measured by the  Internet Traffic Controller (ITC)  running on the ANAP Custom requires you to specify an interface from those listed that the ANAP must use. If the selected custom interface is unavailable, the traffic is dropped by the ANAP. This behavior can changed by contacting  Aryaka Customer Support . Cloud Transport Network—Currently, only the Azure vWAN Cloud Transport Network is supported. If the tunnels to this network are down or if there is no route learned from this network to route your application traffic, the traffic is dropped by the ANAP. This behavior can changed by contacting  Aryaka Customer Support . Cloud Security Connector—If you select this option, provide the following information: Click the  Vendor  drop-down list. This list is populated by the Cloud Security Vendors added as described in  View and add a Cloud Security Vendor network . Click the  When traffic cannot be routed  drop-down list and select what you want done to the traffic if the cloud security vendor's tunnels are down: Blackhole—Traffic is dropped. Send to Internet—Traffic is sent to the default internet interface chosen by  ITC . Connected Site—If you select this option, provide the following information: By default the  Customize where the app group is routed  toggle is off, and traffic is routed to a connected site already configured as described in  Configure routing . Click the  Customize where the app group is routed  toggle to create a custom route. The following fields appear: Site—Select the site where the application group traffic is routed. Destination VPN Zone—Select the destination zone where the application group is hosted. This allows the security rules to permit this application group access from the source zones in your policy. Prioritize a network based on—Select one of the following options: Specified Network Order—Route traffic from the ANAP to the connected site based on the order (top to bottom) specified in the table at the bottom of the pane. Longest Prefix Match and Cost—Allow the ANAP to find longest prefix match and lowest cost and select the best network from those you list in the table. In the event of a tie, the order (top to bottom) in the table is used to select the network. Include networks and define the order: Click the toggle for each network that this application group should use when accessing the destination site. Click the  Reorder  icon to reposition the corresponding row in the table. Click  OK  to save this routing customization. The custom route appears in the VPN Zone Customizations table on the Routing tab on the Add Application Group Policy page. Do one of the following: Configure custom DMZ routing as described in the next section. Click the  Next  icon or the  VPN Path Aryaka  icon to complete the configuration on the VPN Path Aryaka tab as described in  Customize VPN Path Aryaka for an application group . To customize DMZ zone routing Click  Add New  in the DMZ Zone Customization pane. The Details pane appears. Enter a name for your custom routing configuration. (Optional) Enter a description of the customization. Click  Add  in the Source DMZ Zones pane. The Add Source Zone dialog appears. Do one of the following: Click one or more zones in the Name column. The selected applications appear highlighted in a dark band. Click  Select All  to select  every  zone. This can result in a large, difficult-to-mange list of zones. Enter a text string in the Search field, then select one or more of the results or click  Select All  to select all of the matching search results. Click  Add Selected . The selected zones appear in the table in the Source DMZ Zones pane. Click the  Permit Access  toggle in the Routing pane. The associated routing fields appear. Click the  Route To  drop-down list, then select one of the following options to determine where the application traffic is routed: Direct Internet—If you select this option, provide the following information:  Click  Default  or  Custom  in the Internet Interface field.  Default allows the ANAP to select the healthier link available at the site as measured by the  Internet Traffic Controller (ITC)  running on the ANAP Custom requires you to specify an interface from those listed that the ANAP must use. If the selected custom interface is unavailable, the traffic is dropped by the ANAP. This behavior can changed by contacting  Aryaka Customer Support . Cloud Security Connector—If you select this option, provide the following information: Click the  Vendor  drop-down list. This list is populated by the Cloud Security Vendors added as described in  View and add a Cloud Security Vendor network . Click the  When traffic cannot be routed  drop-down list and select what you want done to the traffic if the cloud security vendor's tunnels are down: Blackhole—Traffic is dropped. Send to Internet—Traffic is sent to the default internet interface chosen by  ITC . Click  OK  to save this routing customization. The custom route appears in the DMZ Zone Customizations table on the Routing tab on the Add Application Group Policy page. Click the  Next  icon or the  VPN Path Aryaka  icon to complete the configuration on the VPN Path Aryaka tab as described in  Customize VPN Path Aryaka for App Group . Next Step Customize VPN Path Aryaka for an application group Related Topics Add a custom application group Create and application group control policy Configure zones Configure routing Related videos Configure routing policies for application groups Configure application groups