Multiple phase 2 selectors needed for multiple subnets?
Hello,
I am trying to setup a IPSec VPN tunnel between a Fortigate VM and a Cisco ASAv in GNS3. I have multiple subnets behind the Fortigate and one subnet behind the ASA. When I create a IPSec tunnel on the Fortigate, I use a group-object with all the local subnets from the Fortigate as the local-network at the phase 2 selectors.
When the tunnel is configured at both ends, the fortigate lists the IPSec tunnel, but the phase 2 tunnel is not up all the way. Only one subnet is listed up and the other subnets are down. I found the following Technical Tip where they say that I need to create multiple phase 2 selectors for each local subnet from the Fortigate.
How to configure VPN for multiple subnets - Fortinet Community
When I do this, the VPN works as it should. But is there a way to only need one phase 2 selector for every local subnet? Or do I need to make a selector for every subnet that needs to be allowed over the VPN?
Kind regards,
Jeffrey
