Advantages of Using SonicWALL Route-Based VPN Instead of Site-to-Site VPN (2024)

Date:
Nov. 19, 2020
Author:
Global Knowledge

There are several advantages to implementing a route-based VPN (a.k.a. tunnel interface VPN) instead of asite-to-site one. While both establish a secure tunnel between appliances, a route policy controls the traffic that passes through the tunnel, giving you more flexibility for the services (ports) you want to open across the tunnel as well as redundancy to reroute traffic in case of an outage between the appliances.

Let’s say you have built tunnel interfaces between three sites: New York, Los Angeles, and Houston. They all have route policies directly to each other, and you must build a backup policy to reroute the traffic if the direct tunnels go down. Consider this scenario: The New York tunnel interface to Los Angeles goes down, but the interfaces between New York and Houston and between Houston and Los Angeles are still up. You can reroute traffic from New York to Los Angeles via Houston. You can accomplish this by having a second route policy in New York with a different metric whose destination network is still Los Angeles. But, you must use the tunnel interface policy that sends traffic to Houston first by making that selection under the Interface field. Houston, seeing the destination network is actually Los Angeles, will use its tunnel to Los Angeles to then route the traffic. Same thing happens with traffic from Los Angeles back to New York.

A site-to-site VPN does not give you that type of redundancy since the network is configured in the policy itself. Tunnel interface offloads that configuration from source network to destination network to a route policy. Tunnel interface also has the ability to turn on advanced routing, which utilizes either RIP or OSPF routing protocols. In the Advanced tab of a tunnel interface policy, you will find a check box for advanced routing. Once that’s on, you can go to the Network Routing window and switch the view to Advanced Routing. There, you will see the tunnel interface policy which will allow you to turn on RIP, a distance vector routing protocol that uses the path with the least amount of hops between points, or OSPF, a link state routing protocol that uses a metric of link speed to determine the best path between points. Once RIP or OSPF is configured, the appliances will advertise their routes to each other, which avoids needing to build static route policies between the tunnel interface VPNs. It will become dynamic, which is a definite advantage over site-to-site.

Develop these skills in the following courses

How to configure redundant routes for route-base VPNs

For details on configuring redundant routes for route-based VPN, take a look at the SonicWall's How Can I Configure A Tunnel Interface VPN (Route-Based VPN)? article.

How to configure OSPF

Read SonicWall's Configuring Dynamic Route Based VPN Using OSPF (Tunnel Interface VPN With Advanced Routing) article.

Advantages of Using SonicWALL Route-Based VPN Instead of Site-to-Site VPN (2024)
Top Articles
Building Resilience in Children: the 7 C's of Resilience
Determining Fault After a Vehicle Accident
Ohio Houses With Land for Sale - 1,591 Properties
Lakers Game Summary
Design215 Word Pattern Finder
Botanist Workbench Rs3
Unlocking the Enigmatic Tonicamille: A Journey from Small Town to Social Media Stardom
Nation Hearing Near Me
Poplar | Genus, Description, Major Species, & Facts
Cars For Sale Tampa Fl Craigslist
fltimes.com | Finger Lakes Times
18443168434
Chicken Coop Havelock Nc
Directions To O'reilly's Near Me
Echo & the Bunnymen - Lips Like Sugar Lyrics
No Hard Feelings Showtimes Near Cinemark At Harlingen
What Happened To Anna Citron Lansky
Nhl Wikia
Lcwc 911 Live Incident List Live Status
Quadcitiesdaily
Johnnie Walker Double Black Costco
پنل کاربری سایت همسریابی هلو
Jackie Knust Wendel
Pioneer Library Overdrive
Srjc.book Store
Page 2383 – Christianity Today
What Is Opm1 Treas 310 Deposit
100 Million Naira In Dollars
Publix Coral Way And 147
Devargasfuneral
Sun-Tattler from Hollywood, Florida
Play 1v1 LOL 66 EZ → UNBLOCKED on 66games.io
Lake Dunson Robertson Funeral Home Lagrange Georgia Obituary
Ducky Mcshweeney's Reviews
What Are Digital Kitchens & How Can They Work for Foodservice
Maxpreps Field Hockey
Stanley Steemer Johnson City Tn
Vocabulary Workshop Level B Unit 13 Choosing The Right Word
Craigslist Pets Plattsburgh Ny
Flipper Zero Delivery Time
Stosh's Kolaches Photos
The Nikki Catsouras death - HERE the incredible photos | Horror Galore
26 Best & Fun Things to Do in Saginaw (MI)
The Cutest Photos of Enrique Iglesias and Anna Kournikova with Their Three Kids
Jackerman Mothers Warmth Part 3
Windy Bee Favor
Walmart Front Door Wreaths
San Diego Padres Box Scores
Ty Glass Sentenced
French Linen krijtverf van Annie Sloan
Mkvcinemas Movies Free Download
7 Sites to Identify the Owner of a Phone Number
Latest Posts
Article information

Author: Dean Jakubowski Ret

Last Updated:

Views: 6212

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Dean Jakubowski Ret

Birthday: 1996-05-10

Address: Apt. 425 4346 Santiago Islands, Shariside, AK 38830-1874

Phone: +96313309894162

Job: Legacy Sales Designer

Hobby: Baseball, Wood carving, Candle making, Jigsaw puzzles, Lacemaking, Parkour, Drawing

Introduction: My name is Dean Jakubowski Ret, I am a enthusiastic, friendly, homely, handsome, zealous, brainy, elegant person who loves writing and wants to share my knowledge and understanding with you.