VPN phase2 doesn't come up because local subnet is wrong
Hi,
I have the following issue I am trying to solve: setup a static site2site VPN tunnel between a Fortigate 100E (local) and a Cisco ASA (remote). Configuration of phase1 and phase2 parameters is ok and checked, but the tunnel doesn't come up due to a local subnet issue.
Fortigate 100E, v5.6.6 with physical interfaces as follows:
Lan (Switch): P1-P13, P1 connected, subnet 192.168.0.x/22
P16: 172.16.10.0/24
VPN Tunnel comes up correct if my peer configures the local (100E) subnet to 192.168.0.x. But I would like to use the tunnel from port16 with 172.16.10.0 subnet. If my peer changes configuration to 172.16.10.0, phase 1 comes up but phase 2 never starts. So it is an issue with the correct interface/subnet configuration on my (local) side.
How do I configure the 100E to use port16 / subnet 172.16.10.0 as the local ip? Trying to set the tunnel interface address doesn't allow me to use a 172.16.10.0 IP address with "conflicts with port 16 subnet". So where do you specify, which interface/subnet a VPN tunnel should use as the local side?
thx,
Christian
