StudyToCert

All certifications / FortiGate Admin / Lessons

Fortinet NSE 4 - FortiOS 7.6 Administrator NSE4_FGT_AD-7.6 · Domain 5: VPN

Routes and firewall policies needed for tunnel traffic

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A common surprise with route-based IPsec is that the tunnel can show up while no traffic passes between the sites. That is because bringing the tunnel up is only half the job: you must also tell the FortiGate to route the remote subnets into the tunnel and to permit that traffic with firewall policies. This is heavily tested because it separates people who clicked through a wizard from people who understand the data path.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study FortiGate Admin for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the FortiGate Admin study plan