Technical Tip: Unable to add the Phase-2 Selectors in IPSec tunnel
| Description | This article describes how to add an IPSec phase 2 selector when FortiGate is giving the error: '-56 empty values are not allowed'. |
| Scope | FortiGate. |
| Solution | This issue arises when no Phase-2 selector is configured in the IPSec tunnel. Adding the Phase-2 selector by selecting the edit button shows the error '-56 empty values are not allowed'.
The following Image shows the error:
The following Image shows the example of a configuration with no Phase-2 selector:
Select 'Convert to Custom Tunnel' and try to add Phase-2 selectors as shown in the image below:
Note:
config vpn ipsec phase2-interface Related article: Technical Tip: To Delete IPSec VPN tunnel Phase2 selector from FortiGate CLI |



