Skip to main content
sw2090
SuperUser
SuperUser
February 4, 2025
Question

FortiManager IPSec provisioning templates - phase2 partly broken?

  • February 4, 2025
  • 3 replies
  • 1454 views

Heyho,

 

just ran into this:

 

On my FortiManager in an adom I added an IPSec VPN provisioning template in device manager. This has a phase1 and also a phase2. I had no problems with phase1. But I do have a big problem with phase2:

I need to enter the selectors (dst-subnet and src-subnet) and I do enter the correct ones. However it doesn't matter wether i input them in the form subnet/suffix or subnet,suffix. When I click apply it says its invalid.

If I create the phase2 without templete and the same subnets it works fine.

Any clues?

3 replies

Anthony_E
Staff
Staff
February 7, 2025

Hello :)!,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
February 10, 2025

Hello,

 

I hope you are doing well.

 

I have the answer to troubleshoot an issue where the IPsec phase 2 is partly broken in FortiManager's IPsec provisioning templates:

  1. Check the IPsec template configuration in FortiManager to ensure all phase 2 settings are correctly defined.
  2. Verify that the IPsec template is properly assigned to the device in question.
  3. Review the device's configuration status in FortiManager to see if any errors or inconsistencies are reported.
  4. If the phase 2 settings are not being applied correctly, consider un-assigning the IPsec template from the device and then re-assigning it.
  5. After making any changes, install the modified device configuration to ensure the correct phase 2 settings are pushed to the device.
Best Regards
sw2090
SuperUser
sw2090Author
SuperUser
February 12, 2025

This is due to the irritating way of FMG displaying the selectors in a template:

FMG itself in a template lists selectors in format <subnet>,<mask> but it doesn't accept this format as input. You have to input <subnet> <mask> or maybe <subnet>/<mask> to have it accepted but when you reopen the phase2 afterwards it is dispayes as <subnet>,<mask>.

There also is no notice around there which format you should enter.So you have to know it.

Only FortiNet know why they do different in template then in Device manager's VPN Settings....

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!