Skip to main content
gabriel24
New Member
March 31, 2020
Question

Protected subnets not pushed to fortigate

  • March 31, 2020
  • 0 replies
  • 1487 views

Hello,

 

I'm fairly new to using fortimanager for VPN configuration, so here is my problem.

I have to fortigates in a lab environment both on the same Adom for simplicity and I want to create a Site-to Site VPN between them.

What I have observed is that no matter what subnet/s I define as a protected subnet the manager when pushes the configuration to the fortigates it does not define any subnets in the phase2-interface and so the fortigate has 0.0.0.0/0.

I tried using static objects as well as dynamic mapping but with no luck.

Could you please advise?

 

This is part of the configuration to be pushed to the fortigate:

 

"config vpn ipsec phase2-interface edit "Default_1_0"         set phase1name "Default_1"         set proposal aes128-sha1         set auto-negotiate enable         set comments "[created by FMG VPN Manager]"         set keylifeseconds 1800 next"

 

Regards

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!