Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RichardH
New Contributor

Policy Based or Route Based IPSec VPN?

I have 6 sites, I' ll end up with partially meshed topology, should I design my VPN using policy based or route based? I currently have two sites on policy based and have come across issues with dual WAN setup on my 110C. I' m asking the above question looking for next steps before I continue to troubleshoot my routing issues with dual WAN. With route based, I can have partially redundant tunnels... it' s nice to have, but not something I need. Also, to add a bit of background, while reading about route based, the configuration is what I originally expected. For example, I expected to configure routes manually for each VPN tunnel rather then using inbound NAT on policy based. Anyways, if it doesn' t matter, so be it, I' ll pick one and run with it. If I' ll have less headache running dual WAN using route based, I' ll switch gears and run with it.
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
10 REPLIES 10
rwpatterson

I have 6 sites in interface mode with the same requirement. I put them into a single zone = one policy. Easier to manage, but yes, not required.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors