{"id":32198,"date":"2026-09-15T07:00:33","date_gmt":"2026-09-15T12:00:33","guid":{"rendered":"https:\/\/www.firewalls.com\/blog\/?p=32198"},"modified":"2026-08-31T09:28:37","modified_gmt":"2026-08-31T14:28:37","slug":"fortigate-next-generation-firewalls-and-how-to-configure-policy-routing","status":"publish","type":"post","link":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/","title":{"rendered":"FortiGate Next-Generation Firewalls and How to Configure Policy Routing"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"32198\" class=\"elementor elementor-32198\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8bc7733 e-flex e-con-boxed e-con e-parent\" data-id=\"8bc7733\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-684f621 elementor-widget elementor-widget-text-editor\" data-id=\"684f621\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">There\u2019s a lot to consider when working with <\/span><a href=\"https:\/\/www.firewalls.com\/brands\/fortinet\/fortigate.html\"><span style=\"font-weight: 400;\">FortiGate next-generation firewalls<\/span><\/a><span style=\"font-weight: 400;\"> (NGFWs). However, one angle you don\u2019t want to overlook with the hardware is policy routing configurations.<\/span><\/p><p><span style=\"font-weight: 400;\">For the short version, this allows your FortiGate NGFWs to direct selected traffic through a preferred WAN connection or IPsec tunnel. Instead of relying on the default routing path, you get more control over your network traffic as a whole. Throughout this article, you\u2019re going to gain a core understanding of policy routing configurations for your Fortinet firewall hardware.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7ebdfb8 elementor-widget elementor-widget-heading\" data-id=\"7ebdfb8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<p class=\"elementor-heading-title elementor-size-default\">Key Takeaways:\n<\/p>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0a79008 elementor-widget elementor-widget-text-editor\" data-id=\"0a79008\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use policy routing to direct selected traffic through specific network connections<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure a secondary WAN for traffic that needs a preferred path<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access Policy Routes through System &gt; Feature Visibility<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Send matching DNS traffic toward internal apps through an IPsec tunnel<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Apply policy routing to VoIP, guest networks, high-bandwidth users, internal apps, and more<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aec9d9c elementor-widget elementor-widget-heading\" data-id=\"aec9d9c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What is Policy Routing on FortiGate Next-Generation Firewalls?\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f9f1d28 elementor-widget elementor-widget-text-editor\" data-id=\"f9f1d28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">If you aren\u2019t exactly sure what policy routing does for your <\/span><a href=\"https:\/\/www.firewalls.com\/brands\/fortinet\/fortigate\/smb.html\"><span style=\"font-weight: 400;\">Fortinet firewalls<\/span><\/a><span style=\"font-weight: 400;\">, it provides more specific control over where select traffic ends up across your network. Moreover, this goes off the standard routing path where matching traffic can be sent through a designated interface.<\/span><\/p><p><span style=\"font-weight: 400;\">Here are several important key details about firewall policy management overall:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy routing gives admins the ability to control the path used by selected network traffic<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rules can identify traffic based on details like protocol, source IP, or even destination<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Matching traffic follows the path specified by the policy route, instead of the default routing decision<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Note that the SD-WAN can also continue to play a helpful role when the preferred path isn\u2019t available<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic can switch to another available WAN connection if the preferred connection fails<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Even though you have a few fallback support pillars here, a matching policy route takes priority. This is why the word \u2018configuration\u2019 gets thrown around so much when it comes to network security. Without it, you may not get the best possible experience from your Fortinet FortiGate firewall.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-97cd6c2 elementor-widget elementor-widget-image\" data-id=\"97cd6c2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.firewalls.com\/brands\/fortinet\/fortigate.html\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1280\" height=\"200\" src=\"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/05\/generic-firewalls-banner.png\" class=\"attachment-full size-full wp-image-29323\" alt=\"Generic Firewalls Banner\" srcset=\"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/05\/generic-firewalls-banner.png 1280w, https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/05\/generic-firewalls-banner-300x47.png 300w, https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/05\/generic-firewalls-banner-1024x160.png 1024w, https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/05\/generic-firewalls-banner-768x120.png 768w\" sizes=\"(max-width: 1280px) 100vw, 1280px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0171868 elementor-widget elementor-widget-spacer\" data-id=\"0171868\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6add86d elementor-widget elementor-widget-heading\" data-id=\"6add86d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How to Configure Policy Routing for a Secondary WAN\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3126ddb elementor-widget elementor-widget-text-editor\" data-id=\"3126ddb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">To make sure you end up configuring your <\/span><a href=\"https:\/\/www.firewalls.com\/blog\/fortigate-ngfw-specs\/\"><span style=\"font-weight: 400;\">FortiGate NGFW<\/span><\/a><span style=\"font-weight: 400;\"> properly, there are a couple of steps you\u2019ll want to go through. It\u2019s a lot simpler than you think, but following the right steps is crucial to avoid any unnecessary trial and error.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-353701d elementor-widget elementor-widget-heading\" data-id=\"353701d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 1: Enable Advanced Routing\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-21953fd elementor-widget elementor-widget-text-editor\" data-id=\"21953fd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Before you dive off into creating a policy route, it\u2019s essential to verify that the routing options you need are available. Moreover, if you find that the option is missing, you may need to enable <\/span><b>Advanced Routing.<\/b><\/p><p><span style=\"font-weight: 400;\">Here\u2019s how to get that done:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Navigate to <\/span><b>System &gt; Feature Visibility<\/b><span style=\"font-weight: 400;\"> in your FortiGate interface<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turn on <\/span><b>Advanced Routing<\/b><span style=\"font-weight: 400;\"> if <\/span><b>Policy Routes<\/b><span style=\"font-weight: 400;\"> is unavailable<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Once you have it enabled, go back to the <\/span><b>Network<\/b><span style=\"font-weight: 400;\"> section<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm that <\/span><b>Policy Routes <\/b><span style=\"font-weight: 400;\">is visible before moving on to create the rule<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">I\u2019d say this is all pretty simple, but once this is out of the way, you&#8217;re ready to create a policy route. For the most part, this process is straightforward with <\/span><a href=\"https:\/\/www.firewalls.com\/blog\/fortigate-401f\/\"><span style=\"font-weight: 400;\">Fortinet firewall models<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c6da45e elementor-widget elementor-widget-heading\" data-id=\"c6da45e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step 2: Create a Policy Route\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-af7fffc elementor-widget elementor-widget-text-editor\" data-id=\"af7fffc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Any time you\u2019re working on creating a policy route, your starting point is determining which device or source traffic should use the secondary WAN. By the end of this, your policy route should specify where that matching traffic should be sent.<\/span><\/p><p><span style=\"font-weight: 400;\">Follow the steps below to create a policy route with your FortiGate NGFW:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Navigate to <\/span><b>Network &gt; Policy Routes<\/b><span style=\"font-weight: 400;\"> and create a new policy route<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Set the incoming interface to the LAN interface<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Select the relevant address object and set the destination to all or restrict it as needed<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Select <\/span><b>WAN 2 <\/b><span style=\"font-weight: 400;\">as the outgoing interface, enter its gateway, and save the rule so matching traffic uses WAN 2 instead of WAN 1<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Having control of your general network traffic is one thing. On the other hand, they carry a deeper purpose with the likes of internal applications and DNS, for example.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-94a49c7 elementor-widget elementor-widget-video\" data-id=\"94a49c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;youtube_url&quot;:&quot;https:\\\/\\\/www.youtube.com\\\/watch?v=HMFACBDSUQE&quot;,&quot;video_type&quot;:&quot;youtube&quot;,&quot;controls&quot;:&quot;yes&quot;}\" data-widget_type=\"video.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-wrapper elementor-open-inline\">\n\t\t\t<div class=\"elementor-video\"><\/div>\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0bfbd51 elementor-widget elementor-widget-spacer\" data-id=\"0bfbd51\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eeff72d elementor-widget elementor-widget-heading\" data-id=\"eeff72d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Using Policy Routing for Internal Applications and DNS\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-34f0614 elementor-widget elementor-widget-text-editor\" data-id=\"34f0614\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This particular scenario would commonly come into play for those dealing with connections from <\/span><a href=\"https:\/\/www.firewalls.com\/brands\/fortinet\/fortigate\/enterprise.html\"><span style=\"font-weight: 400;\">multiple locations<\/span><\/a><span style=\"font-weight: 400;\">. An example of this could include two locations connected through an IPsec tunnel. Whereas the headquarters location hosts internal apps, including DNS, both of which are needed by users in a different location.<\/span><\/p><p><span style=\"font-weight: 400;\">Below is how policy routing can help in this situation:<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User DNS queries generally travel toward the internet for resolution<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-based DNS resolution does not provide access to apps hosted within the internal environment<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turn off DNS encryption so the destination of the traffic can be identified<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure DNS using <\/span><b>UDP port 53<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define an address object for the relevant internal domain or server<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create a rule that matches the internal destination and <\/span><b>UDP port 53<\/b><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure the IPsec tunnel as the policy route\u2019s outgoing interface<\/span><\/li><\/ol><p><span style=\"font-weight: 400;\">From here, matching DNS requests are sent through the IPsec tunnel toward the internal environment, rather than out to the internet. Once again, it might seem complex on paper, but FortiGate next-generation firewalls make it all pretty seamless.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b37fa2a elementor-widget elementor-widget-heading\" data-id=\"b37fa2a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Policy Routing Use Cases for Fortinet Firewalls\n<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e0ab02d elementor-widget elementor-widget-text-editor\" data-id=\"e0ab02d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Aside from creating a policy route, it also helps to understand the many different use cases behind them. In the table below, you\u2019ll find several popular use cases for policy routing, especially when it comes to business network security.\u2019<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-82158fb elementor-widget elementor-widget-shortcode\" data-id=\"82158fb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n<table id=\"tablepress-220\" class=\"tablepress tablepress-id-220\">\n<thead>\n<tr class=\"row-1\">\n\t<th class=\"column-1\">Use Case<\/th><th class=\"column-2\">How Policy Routing Helps<\/th>\n<\/tr>\n<\/thead>\n<tbody class=\"row-striping row-hover\">\n<tr class=\"row-2\">\n\t<td class=\"column-1\">VoIP Traffic<\/td><td class=\"column-2\">Directs VoIP traffic through a preferred WAN connection<\/td>\n<\/tr>\n<tr class=\"row-3\">\n\t<td class=\"column-1\">High-Bandwidth Users<\/td><td class=\"column-2\">Routes selected users through a designated network path<\/td>\n<\/tr>\n<tr class=\"row-4\">\n\t<td class=\"column-1\">Guest Networks<\/td><td class=\"column-2\">Allows guest traffic to use a specific routing path of their own<\/td>\n<\/tr>\n<tr class=\"row-5\">\n\t<td class=\"column-1\">Secondary WAN<\/td><td class=\"column-2\">Sends matching traffic through WAN 2 instead of the default WAN 1 path<\/td>\n<\/tr>\n<tr class=\"row-6\">\n\t<td class=\"column-1\">Internal Applications<\/td><td class=\"column-2\">Directs traffic toward internal apps through an IPsec tunnel<\/td>\n<\/tr>\n<tr class=\"row-7\">\n\t<td class=\"column-1\">DNS Traffic<\/td><td class=\"column-2\">Routes matching DNS requests through the IPsec tunnel toward the internal environment<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<!-- #tablepress-220 from cache --><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-bd5252d e-flex e-con-boxed e-con e-parent\" data-id=\"bd5252d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-19cc8d4 elementor-widget elementor-widget-text-editor\" data-id=\"19cc8d4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">I\u2019m sure we can all see a trend here regarding the purpose of policy routing for your Fortinet FortiGate firewall. Regardless of how simple or challenging this may seem, there are many reasons companies like to let the <\/span><a href=\"https:\/\/www.firewalls.com\/professional-services.html\"><span style=\"font-weight: 400;\">professionals manage<\/span><\/a><span style=\"font-weight: 400;\"> these network technicalities.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">At the end of the day, policy routing can serve multiple purposes, depending on the type of traffic you\u2019re dealing with. Moreover, the examples highlighted throughout this write-up offer a good look into how policy routing can complement firewall policy management as a whole.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb3ac9f elementor-widget elementor-widget-image\" data-id=\"eb3ac9f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.firewalls.com\/professional-services.html\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1280\" height=\"200\" data-src=\"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/03\/Managed-Services-1.png\" class=\"attachment-full size-full wp-image-28915 lazyload\" alt=\"Managed Security Services\" data-srcset=\"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/03\/Managed-Services-1.png 1280w, https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/03\/Managed-Services-1-300x47.png 300w, https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/03\/Managed-Services-1-1024x160.png 1024w, https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/03\/Managed-Services-1-768x120.png 768w\" data-sizes=\"(max-width: 1280px) 100vw, 1280px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1280px; --smush-placeholder-aspect-ratio: 1280\/200;\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19b0c41 elementor-widget elementor-widget-spacer\" data-id=\"19b0c41\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-047793f elementor-widget elementor-widget-heading\" data-id=\"047793f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Here\u2019s the Final Word\n<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b61be2 elementor-widget elementor-widget-text-editor\" data-id=\"4b61be2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Policy routing for your FortiGate next-generation firewalls provides more targeted traffic control across your network. Admins can easily and safely keep traffic directed to the right place, giving you better overall control, even when handling multiple locations.<\/span><\/p><p><span style=\"font-weight: 400;\">On another note, you can also gain a better understanding of this topic in the video below from one of our dedicated network engineers at Firewalls.com. You can also <\/span><a href=\"https:\/\/www.firewalls.com\/contact\"><span style=\"font-weight: 400;\">hop into a chat<\/span><\/a><span style=\"font-weight: 400;\"> with us and learn everything you need to know about policy routing with Fortinet firewall models.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0b06d99 elementor-widget elementor-widget-button\" data-id=\"0b06d99\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"tel:3172254117\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Call Now<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cad5245 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"cad5245\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a57ee5a elementor-widget elementor-widget-heading\" data-id=\"a57ee5a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<p class=\"elementor-heading-title elementor-size-default\">Frequently Asked Questions\n<\/p>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9e1c811 elementor-widget elementor-widget-n-accordion\" data-id=\"9e1c811\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;all_collapsed&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-1650\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-1650\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> What is Policy Routing on a FortiGate Firewall? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-1650\" class=\"elementor-element elementor-element-a6fd12b e-con-full e-flex e-con e-child\" data-id=\"a6fd12b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ef33e39 elementor-widget elementor-widget-text-editor\" data-id=\"ef33e39\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Policy routing directs selected traffic through a specific path based on conditions such as source IP, destination, incoming interface, or protocol.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-1651\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-1651\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> How Can I Configure a FortiGate to Use a Secondary WAN? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-1651\" class=\"elementor-element elementor-element-8f56eeb e-con-full e-flex e-con e-child\" data-id=\"8f56eeb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3362137 elementor-widget elementor-widget-text-editor\" data-id=\"3362137\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Enable Advanced Routing, open Network &gt; Policy Routes, identify the desired source traffic, and set WAN 2 and its gateway as the outgoing path.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-1652\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-1652\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> Can FortiGate Policy Routing Work with SD-WAN? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-1652\" class=\"elementor-element elementor-element-4a228c9 e-con-full e-flex e-con e-child\" data-id=\"4a228c9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-be9d3dd elementor-widget elementor-widget-text-editor\" data-id=\"be9d3dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, a matching policy route takes priority, while SD-WAN can still provide an alternative path when the preferred connection is unavailable.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-1653\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-1653\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> Can Policy Routing Direct DNS Traffic Through an IPsec Tunnel? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-1653\" class=\"elementor-element elementor-element-e233929 e-flex e-con-boxed e-con e-child\" data-id=\"e233929\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4103842 elementor-widget elementor-widget-text-editor\" data-id=\"4103842\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, the example in this article uses a policy route matching an internal destination and UDP port 53, with the IPsec tunnel selected as the outgoing interface.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-1654\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-1654\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> What Types of Traffic Can Benefit from FortiGate Policy Routing? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-1654\" class=\"elementor-element elementor-element-c9f3b9c e-flex e-con-boxed e-con e-child\" data-id=\"c9f3b9c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-90ee437 elementor-widget elementor-widget-text-editor\" data-id=\"90ee437\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Common examples include VoIP traffic, high-bandwidth users, guest networks, secondary-WAN traffic, internal apps, and DNS traffic.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is Policy Routing on a FortiGate Firewall?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Policy routing directs selected traffic through a specific path based on conditions such as source IP, destination, incoming interface, or protocol.\"}},{\"@type\":\"Question\",\"name\":\"How Can I Configure a FortiGate to Use a Secondary WAN?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Enable Advanced Routing, open Network &gt; Policy Routes, identify the desired source traffic, and set WAN 2 and its gateway as the outgoing path.\"}},{\"@type\":\"Question\",\"name\":\"Can FortiGate Policy Routing Work with SD-WAN?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, a matching policy route takes priority, while SD-WAN can still provide an alternative path when the preferred connection is unavailable.\"}},{\"@type\":\"Question\",\"name\":\"Can Policy Routing Direct DNS Traffic Through an IPsec Tunnel?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, the example in this article uses a policy route matching an internal destination and UDP port 53, with the IPsec tunnel selected as the outgoing interface.\"}},{\"@type\":\"Question\",\"name\":\"What Types of Traffic Can Benefit from FortiGate Policy Routing?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Common examples include VoIP traffic, high-bandwidth users, guest networks, secondary-WAN traffic, internal apps, and DNS traffic.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.<\/p>\n","protected":false},"author":13,"featured_media":32440,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[597,600],"tags":[],"class_list":["post-32198","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-firewalls","category-fortinet"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FortiGate Next-Generation Firewalls and Configuring Policy Routing - Firewalls.com<\/title>\n<meta name=\"description\" content=\"Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FortiGate Next-Generation Firewalls and Configuring Policy Routing - Firewalls.com\" \/>\n<meta property=\"og:description\" content=\"Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/\" \/>\n<meta property=\"og:site_name\" content=\"Firewalls.com\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/firewallscom\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T12:00:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/08\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lucas Modrall\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@firewallscom\" \/>\n<meta name=\"twitter:site\" content=\"@firewallscom\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lucas Modrall\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/\"},\"author\":{\"name\":\"Lucas Modrall\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#\\\/schema\\\/person\\\/cc1ba4fb3acd1d71c1c04434567b3f53\"},\"headline\":\"FortiGate Next-Generation Firewalls and How to Configure Policy Routing\",\"datePublished\":\"2026-09-15T12:00:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/\"},\"wordCount\":1354,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png\",\"articleSection\":[\"Firewalls\",\"Fortinet\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/\",\"url\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/\",\"name\":\"FortiGate Next-Generation Firewalls and Configuring Policy Routing - Firewalls.com\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png\",\"datePublished\":\"2026-09-15T12:00:33+00:00\",\"description\":\"Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png\",\"contentUrl\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png\",\"width\":1200,\"height\":600,\"caption\":\"FortiGate Next-Generation Firewalls and How to Configure Policy Routing\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiGate Next-Generation Firewalls and How to Configure Policy Routing\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/\",\"name\":\"Firewalls.com\",\"description\":\"Your Home For Cyber Security News, Stories, &amp; Tutorials\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#organization\",\"name\":\"Firewalls.com\",\"url\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/wp-content\\\/uploads\\\/2017\\\/08\\\/BrandedLogo-TagLineBelow.png\",\"contentUrl\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/wp-content\\\/uploads\\\/2017\\\/08\\\/BrandedLogo-TagLineBelow.png\",\"width\":365,\"height\":85,\"caption\":\"Firewalls.com\"},\"image\":{\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"http:\\\/\\\/www.facebook.com\\\/firewallscom\",\"https:\\\/\\\/x.com\\\/firewallscom\",\"https:\\\/\\\/www.linkedin.com\\\/company-beta\\\/1439857\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/firewallsDotCom\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/#\\\/schema\\\/person\\\/cc1ba4fb3acd1d71c1c04434567b3f53\",\"name\":\"Lucas Modrall\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c7d2017c4bb69e7b8adb91dbbfcc089b8e3a8f50a1ea2fddd1fdb91a7c47cd74?s=96&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c7d2017c4bb69e7b8adb91dbbfcc089b8e3a8f50a1ea2fddd1fdb91a7c47cd74?s=96&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c7d2017c4bb69e7b8adb91dbbfcc089b8e3a8f50a1ea2fddd1fdb91a7c47cd74?s=96&r=g\",\"caption\":\"Lucas Modrall\"},\"description\":\"Lucas is a Content Writer for Firewalls.com and is a seasoned technical writer with nearly a decade of experience crafting content that balances precision with performance. His background is rooted in research and development, where he built a strong foundation in breaking down complex systems into clear, actionable insights. Over time, he expanded into blog management, overseeing content strategies that drive engagement and long term visibility. His work often sits at the intersection of technical depth and accessibility, making it valuable for both industry professionals and broader audiences.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/lucas-m-5b4106186\\\/\"],\"url\":\"https:\\\/\\\/www.firewalls.com\\\/blog\\\/author\\\/lucasm\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FortiGate Next-Generation Firewalls and Configuring Policy Routing - Firewalls.com","description":"Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/","og_locale":"en_US","og_type":"article","og_title":"FortiGate Next-Generation Firewalls and Configuring Policy Routing - Firewalls.com","og_description":"Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.","og_url":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/","og_site_name":"Firewalls.com","article_publisher":"http:\/\/www.facebook.com\/firewallscom","article_published_time":"2026-09-15T12:00:33+00:00","og_image":[{"width":1200,"height":600,"url":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/08\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png","type":"image\/png"}],"author":"Lucas Modrall","twitter_card":"summary_large_image","twitter_creator":"@firewallscom","twitter_site":"@firewallscom","twitter_misc":{"Written by":"Lucas Modrall","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#article","isPartOf":{"@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/"},"author":{"name":"Lucas Modrall","@id":"https:\/\/www.firewalls.com\/blog\/#\/schema\/person\/cc1ba4fb3acd1d71c1c04434567b3f53"},"headline":"FortiGate Next-Generation Firewalls and How to Configure Policy Routing","datePublished":"2026-09-15T12:00:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/"},"wordCount":1354,"commentCount":0,"publisher":{"@id":"https:\/\/www.firewalls.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/08\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png","articleSection":["Firewalls","Fortinet"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/","url":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/","name":"FortiGate Next-Generation Firewalls and Configuring Policy Routing - Firewalls.com","isPartOf":{"@id":"https:\/\/www.firewalls.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#primaryimage"},"image":{"@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/08\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png","datePublished":"2026-09-15T12:00:33+00:00","description":"Learn how FortiGate next-generation firewalls use policy routing to control traffic paths, route DNS through IPsec tunnels, and more.","breadcrumb":{"@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#primaryimage","url":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/08\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png","contentUrl":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2026\/08\/FortiGate-Next-Generation-Firewalls-and-How-to-Configure-Policy-Routing.png","width":1200,"height":600,"caption":"FortiGate Next-Generation Firewalls and How to Configure Policy Routing"},{"@type":"BreadcrumbList","@id":"https:\/\/www.firewalls.com\/blog\/fortigate-next-generation-firewalls-and-how-to-configure-policy-routing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.firewalls.com\/blog\/"},{"@type":"ListItem","position":2,"name":"FortiGate Next-Generation Firewalls and How to Configure Policy Routing"}]},{"@type":"WebSite","@id":"https:\/\/www.firewalls.com\/blog\/#website","url":"https:\/\/www.firewalls.com\/blog\/","name":"Firewalls.com","description":"Your Home For Cyber Security News, Stories, &amp; Tutorials","publisher":{"@id":"https:\/\/www.firewalls.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.firewalls.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.firewalls.com\/blog\/#organization","name":"Firewalls.com","url":"https:\/\/www.firewalls.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.firewalls.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2017\/08\/BrandedLogo-TagLineBelow.png","contentUrl":"https:\/\/www.firewalls.com\/blog\/wp-content\/uploads\/2017\/08\/BrandedLogo-TagLineBelow.png","width":365,"height":85,"caption":"Firewalls.com"},"image":{"@id":"https:\/\/www.firewalls.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["http:\/\/www.facebook.com\/firewallscom","https:\/\/x.com\/firewallscom","https:\/\/www.linkedin.com\/company-beta\/1439857\/","https:\/\/www.youtube.com\/user\/firewallsDotCom"]},{"@type":"Person","@id":"https:\/\/www.firewalls.com\/blog\/#\/schema\/person\/cc1ba4fb3acd1d71c1c04434567b3f53","name":"Lucas Modrall","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c7d2017c4bb69e7b8adb91dbbfcc089b8e3a8f50a1ea2fddd1fdb91a7c47cd74?s=96&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c7d2017c4bb69e7b8adb91dbbfcc089b8e3a8f50a1ea2fddd1fdb91a7c47cd74?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c7d2017c4bb69e7b8adb91dbbfcc089b8e3a8f50a1ea2fddd1fdb91a7c47cd74?s=96&r=g","caption":"Lucas Modrall"},"description":"Lucas is a Content Writer for Firewalls.com and is a seasoned technical writer with nearly a decade of experience crafting content that balances precision with performance. His background is rooted in research and development, where he built a strong foundation in breaking down complex systems into clear, actionable insights. Over time, he expanded into blog management, overseeing content strategies that drive engagement and long term visibility. His work often sits at the intersection of technical depth and accessibility, making it valuable for both industry professionals and broader audiences.","sameAs":["https:\/\/www.linkedin.com\/in\/lucas-m-5b4106186\/"],"url":"https:\/\/www.firewalls.com\/blog\/author\/lucasm\/"}]}},"_links":{"self":[{"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/posts\/32198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/comments?post=32198"}],"version-history":[{"count":22,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/posts\/32198\/revisions"}],"predecessor-version":[{"id":32505,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/posts\/32198\/revisions\/32505"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/media\/32440"}],"wp:attachment":[{"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/media?parent=32198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/categories?post=32198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.firewalls.com\/blog\/wp-json\/wp\/v2\/tags?post=32198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}