Technical Tip: How to bring up specific phase 2 selectors or all selectors of IPSec VPN from GUI
| Description | This article describes how to bring up specific phase 2 selectors or all selectors of IPSec VPN via GUI. |
| Scope | FortiGate v6.4 onwards. |
| Solution | In v6.2, it is mandatory to go to Monitor -> IPsec Monitor to bring up the phase 2 selector of IPsec VPN via GUI as shown in the screenshot below.
From v6.4, it is possible to bring up from VPN -> IPsec Tunnels and select the status of VPN. For example, select the 'Inactive' status as shown below.
It will redirect to another Web page showing multiple phase 2 selectors columns as shown in the previous version, select the tunnel and bring up a specific phase 2 selector or all phase 2 selectors shown below.
Another method is to go under Dashboard -> Network -> IPsec.
Note: If a phase 2 selector did not come up after using the force bring-up option, check each device to see if the set phase 2 selector IP address or subnet mask is the same. Also, the bring-up option is not available for dial-up tunnels.
If the Phase 2 tunnel is still down. Check the following.
If Phase-2 is still not operational, start the packet capture on port 500/4500.
CLI method:
execute vpn ipsec tunnel up <Phase2 name> diag vpn tunnel up <phase2 name>
Related articles: Technical Tip: How to bring the IPsec tunnel down from the CLI and GUI |




