Created on
05-31-2016
05:59 PM
Edited on
07-21-2025
05:21 AM
By
Anthony_E
Description
This article describes how to configure a policy route that only certain traffic will traverse through a route-based IPsec VPN tunnel.
Scope
FortiGate.
Solution
Although a static route with a destination interface of a VPN tunnel does not require a gateway IP address, a policy route does. The solution is to configure an 'IP' and 'Remote IP' on the virtual tunnel interface and use the 'Remote IP as the gateway IP address in the policy routes. By specifying the 'Remote IP " at tunnel interface will not require any static route through the tunnel to match the gateway IP address.
Note:
The IP is not required to be configured on the remote gateway tunnel interface. When the Policy route is configured with the tunnel interface, it doesn't check whether the gateway IP is reachable, unlike in the case of the physical interface.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.