The option only make the firewall from drop to accept. But does not handle port forward etc.

It cannot handle port forward, but can do DMZ, which may not be the user want.

It can also handle routing, but routing should be processed in all the nodes of the vpn, not only one node. Like our S2S solution need to push the routing to all nodes via cloud.