Technical Tip: How to combine two phase two selectors in IPsec VPN into one phase two selector using super net
| Description | This article describes how to combine two Phase Two selectors in an IPSEC VPN into one Phase Two selector using a super net. |
| Scope | FortiGate. |
| Solution | In this example, subnets of two selectors are to be combined into one super net.
Subnet of first phase two selector: 192.168.98.0/26
Step 1: Determine the IP ranges.
192.168.98.0/26 192.168.100.0/24
192.168.98.0 (lowest IP) Convert to binary to find the common prefix:
Step 3: Compare bit by bit.
Hence, super net is 192.168.96.0/21 . (192.168.96.0 255.255.248.0)
Step 4: Apply the super net in a single-phase two-selector as required.
|
