Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Discriminate Policy base & Route Base

Dear all, I read document about VPN which mention about Route Base VPN Firewall Policy & Policy Base VPN Firewall Policy. But I' m not sure function of those. Policy Base
Define IPSEC firewall policy to permit communications between the source and destination address
Route Base
Define an ACCEPT firewall policy to permit communication betwen the source and destination addresses.
Would you please explain for me about this. Thanks
4 REPLIES 4
Carl_Wallmark
Valued Contributor

Hi, Route Based (Interface mode) - When creating in interface mode, your VPN connection is shown as a interface instead of a policy. With this mode you can do much more advanced configurations. For example: VPN_Connection (any) -> Internal (any) Policy Based - Your VPN connection is shown as a policy, for example: Internal (any) -> WAN1 (any) -> Action (IPSEC).

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
rwpatterson
Valued Contributor III

In the list, the action may say ' ENCRYPT' . It means an IPSec tunnel.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thanks for your reply. With case I want create 2 or 3 groups on one IP WAN. After user login with their user name + password, Fortinet VPN Server will apply policy for user. Currently, I finish setup VPN for Sale Dept with Policy base. However, when I continue setup VPN for Operation Dept with different preshare key + username password with Sale Dept. Result is Operation Dept can connect VPN but Sale Dept can not. Please advice me in this case I should config VPN server with Routing Policy Base or Policy Base???
red_adair
New Contributor III

smells like you used " main mode" in Phase1. For multiple dialup Clients you should use aggressive mode.
Labels
Top Kudoed Authors