To provide more flexible routing methods, policy-based IPsec-VPN is changed to route-based IPsec-VPN.
Changes
After policy-based IPsec-VPN is changed to route-based IPsec-VPN, VPN Gateway has the following changes:
You can view two types of route tables on the details page of a VPN gateway.
- Policy-based route table: routes traffic based on source and destination IP addresses.
- Destination-based route table: routes traffic based on destination IP addresses.
Impacts
- Existing VPN Gateway instances do not support route-based IPsec-VPN. To use this feature, you must upgrade your VPN Gateway to the latest version. For instructions, see Upgrade a VPN Gateway.
- Newly created VPN gateways support route-based IPsec-VPN by default.
- SSL-VPN is not affected.