![Fortinet FortiWAN Handbook Download Page 140](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088140.webp)
Load Balancing & Fault Tolerance
Tunnel Routing
IPSec Support
Although Tunnel Routing provides itself a simple data protection by encrypting the data payload of original packets, it
is not secure enough as standard IPSec's protection. IPSec defines rigorous procedures on security parameters
negotiation, key exchange and authentication to prevent any compromise. Various encryption and authentication
algorithms, and key strengths are contained in IPSec, so that various security levels are provided. With IPSec
protection, a standard virtual private network (VPN) can be implemented.
Although Tunnel Routing connects two incompatible networks (private networks) by tunneling through Internet, it is
seriously not a standard VPN since it is short on security. FortiWAN IPSec (Transport mode) is capable of protecting
Tunnel Routing tunnels, so that Tunnel Routing becomes qualified to the standard VPN. With IPSec protection,
Tunnel Routing not only functions in a securer way, but also keeps the advantage of bandwidth aggregation and fault
tolerance between tunnels. The only sacrifice is dynamic IP addresses and NAT pass through are not supported for
Tunnel Routing over IPSec. Besides, deployments of Tunnel Routing over IPSec is limited. For more information
about Tunnel Routing over IPSec, please refer to "
IPSec - About FortiWAN IPSec VPN
" and "
IPSec - Define routing policies for an IPSec VPN
".
Performance
Tunnel Routing spreads packets of a session over multiple tunnels and arranges the packets in correct order at the
opposite site, then forwards the well-ordered packets to the destinations. Different quality of tunnels causes different
latency to packets arriving, which is the major factor for data transmission performance. Tunnels with bad quality or
greatly unequal quality cause packet loss and retransmission in higher possibility. A tunnel can be roughly divided into
three parts, the WAN link between local FortiWAN and its ISP, the WAN link between remote FortiWAN and its ISP,
and links between ISPs (Internet). Although there is nothing can do to transmission quality within Internet, it can be
achieved to ensure good and equal quality for the WAN links between FortiWAN sites and ISPs. Therefore, WAN links
with good and equal quality are necessary to construct qualified tunnels. Tunnel Routing's Benchmark helps to
evaluate configured tunnels (See "
").
140
FortiWAN Handbook
Fortinet Technologies Inc.