Skip to main content
JeffreyMik
New Member
April 23, 2024
Solved

Multiple phase 2 selectors needed for multiple subnets?

  • April 23, 2024
  • 5 replies
  • 7410 views

Hello,

I am trying to setup a IPSec VPN tunnel between a Fortigate VM and a Cisco ASAv in GNS3. I have multiple subnets behind the Fortigate and one subnet behind the ASA. When I create a IPSec tunnel on the Fortigate, I use a group-object with all the local subnets from the Fortigate as the local-network at the phase 2 selectors.

When the tunnel is configured at both ends, the fortigate lists the IPSec tunnel, but the phase 2 tunnel is not up all the way. Only one subnet is listed up and the other subnets are down. I found the following Technical Tip where they say that I need to create multiple phase 2 selectors for each local subnet from the Fortigate.

How to configure VPN for multiple subnets - Fortinet Community

When I do this, the VPN works as it should. But is there a way to only need one phase 2 selector for every local subnet? Or do I need to make a selector for every subnet that needs to be allowed over the VPN?


Kind regards,

Jeffrey

Best answer by ozkanaltas

Hello @JeffreyMik ,

 

For example, you can configure 10.0.0.0/8 instead of 10.10.10.0/24. 

 

After that, you can restrict access with the policy. 

5 replies

ozkanaltas
Valued Contributor III
April 23, 2024

Hello @JeffreyMik ,

 

Yes, you are right. If you want to add more subnets in your tunnel you need to configure multiple phase 2 on FortiGate. If you don't want this. You can configure a wide subnet on your tunnel. This is how Fortigate works.

JeffreyMik
New Member
April 23, 2024

"You can configure a wide subnet on your tunnel"

What do you mean with this? How does this work?

ozkanaltas
Valued Contributor III
April 23, 2024

Hello @JeffreyMik ,

 

For example, you can configure 10.0.0.0/8 instead of 10.10.10.0/24. 

 

After that, you can restrict access with the policy. 

hbac
Staff
Staff
April 23, 2024

Hi @JeffreyMik,

 

Multiple subnets in one phase2 selector works fine between 2 FortiGates but not with Cisco. I would suggest keeping them separated with multiple phase2 selectors. 

 

Regards, 

sanjayputhalath_FTNT
Staff
Staff
April 25, 2024

Hi @JeffreyMik  

If it is IKEV1 you can use 'set mesh-selector-type subnet' command in Phase1 configuration. Refer the following link for more details.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dynamic-creation-of-IPsec-tunnels-IKEv1-dynamic/ta-p/190346

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!