Skip to main content
Contributor
May 29, 2007
Question

Route-based vs Policy based VPN

  • May 29, 2007
  • 2 replies
  • 7558 views
What is the difference between the two, and what is the best way to decide which one to use?

    2 replies

    doshbass
    New Member
    May 29, 2007
    Route based - sets up the VPN tunnel as a virtual interface. You can apply policies to and from an interface as normal. Policy based VPN, requires you to create policies to teh external interface using teh ENCRYPt or IPSEC option. to mind mind Interface based are much more logical and controllable than policy based. Interface mode is the new way - policy mode is the old way. IMHO of course
    matchan
    New Member
    May 29, 2007
    agree with doshbass, but would just add that I' ve found interface mode to be easier if you are trying to connect to a 3rd party device, particulary snapgear and pix, whereas policy based are very simple to create to other fortigates. ymmv Matt