Skip to main content
Carlanderska_S
New Member
May 11, 2018
Question

IPsec Tunnels Phase 2 and groups

  • May 11, 2018
  • 4 replies
  • 5298 views

Hi!

 

I've added a addressgroup under Remote Address for Phase 2 Selectors. Does this work or do I have to add the addresses separately?

 

Thank you.

    4 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    May 11, 2018

    How did you create a group in IPsec Phase2 setting GUI? I don't see any option to set a "group" there.

    The traffic selectors are pare of local<->remote. If you need to set multiple subnets on remote side you need add a new set like 172.16.0.0/16<->192.168.0.0/16 and 172.16.0.0/16<->10.10.0.0/16.

    Toshi_Esumi
    SuperUser
    SuperUser
    May 11, 2018

    Ok, through the wizard, you can put multiple subnets like my previous post on remote side separated by a comma ','. Then it would generate two pairs with the same local subnet.

    emnoc
    New Member
    May 11, 2018

    It really depends

     

    1: if it's  FGT-to-FGT firewall and  route-based, than a  0..0.0.0/0:0  is good enough

     

    2: if it's  FGT-toSRX firewall and  route-based, than a  0..0.0.0/0:0  is good enough

     

    3: if it a FGT-2- <insert almost anything else  CHKP/SonicWall/ASA/ForcePT/pfSense > than unique src/dst-subnets or unique named-network-elements must be used in the phase2

     

    YMMV,  but the 1-3 rules are pretty much what it is

    Carlanderska_S
    New Member
    May 14, 2018

    Thank you for the answers. What I meant was that I added an address-group which contains more than one address into the Phase 2 Selectors Remote Address.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.