IPSec VPN - Policy Based?

BMS
BMS Posts: 21  Freshman Member
Second Anniversary
I've been asked to set up a policy based VPN instead of route based.  I'm not even sure what the difference is or if it can be done with a ZyXel firewall.  I've done a bunch of IPSec VPN work, but all the same configuration, and apparently there is a difference.

All Replies

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Route based VPN is more flexible than policy based.
    e.g. you can run dynamic routing, IGMP proxy in Route based VPN. Dual wan traffic routing with policy route for failover.
    Terminology:
    Policy-based VPN- Policy-based VPNs encrypt and encapsulate a subset of traffic flowing through an interface according to a defined policy.
    Route-based VPN- A route based VPN creates a virtual IPSec interface, and whatever traffic hits that interface is encrypted and decrypted according to the phase 1 and phase 2 IPSec settings. 

  • BMS
    BMS Posts: 21  Freshman Member
    Second Anniversary
    Thank you!

    How do you go about setting up a route-based VPN through IPSec there?
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,511  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

Security Highlight