Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RichardH
New Contributor

Policy Based or Route Based IPSec VPN?

I have 6 sites, I' ll end up with partially meshed topology, should I design my VPN using policy based or route based? I currently have two sites on policy based and have come across issues with dual WAN setup on my 110C. I' m asking the above question looking for next steps before I continue to troubleshoot my routing issues with dual WAN. With route based, I can have partially redundant tunnels... it' s nice to have, but not something I need. Also, to add a bit of background, while reading about route based, the configuration is what I originally expected. For example, I expected to configure routes manually for each VPN tunnel rather then using inbound NAT on policy based. Anyways, if it doesn' t matter, so be it, I' ll pick one and run with it. If I' ll have less headache running dual WAN using route based, I' ll switch gears and run with it.
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
10 REPLIES 10
RichardH
New Contributor

I read page 16 of the " Configuring IPSec VPNs" doc at docs.fortinet.com... I' ll stick with policy based and use a concentrator... I' ll leave this thread open, just in case someone can share some similar experience or guide me.
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
rwpatterson
Valued Contributor III

Route based is less configurable. You cannot route over route based to subnets that are not directly attached to the remote FGT. There are issues (I have had) where NATting can be a problem. You probably won' t run into those. Also if you use interface based tunnels, you can place them into a zone, and will have to configure one single policy for all tunnels included in the zone. A definite plus in the maintenance area... My $.02

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
g3rman
New Contributor

Richard, interface based tunnels are the way to go. Routed VPN tunnels aren' t exactly legacy but as Bob mentioned interface based VPNs are much more powerful.
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
RichardH
New Contributor

I' ll test route based vpn using zones...
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
rwpatterson
Valued Contributor III

Zones require interfaces....

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
g3rman
New Contributor

Route based VPNs dont' support zones since you are not creating any additional interfaces.
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
abelio

Hello all, just for clarify (the thread became confusing for me at least): Routed (= interface) based VPN are those with ACCEPT action firewall policies. On the other side, Policy based VPNs are those with IPSec action firewall policies.

regards




/ Abel

regards / Abel
rwpatterson
Valued Contributor III

LOL.. true. I was right, kinda...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
FortiRack_Eric
New Contributor III

Policy based VPN are legacy. And Interface (route) mode don' t need zone per sé.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors