Skip to main content
FortiOSman
New Member
October 17, 2016
Solved

Wildcard network for IPSEC phase2 selectors

  • October 17, 2016
  • 3 replies
  • 8256 views

Hello,

 

Is anyone running 0.0.0.0/0.0.0.0 as the source and destination for a P2 selector? 

I have a growing list of about 30 P2's that would be much easier to manage if it were just the one wildcard entry. I would still be controlling the traffic on my policies.

 

Any pros/cons to doing it this way? The unit on the other side of the tunnel is a Fortigate as well. 

 

 

Thanks

Best answer by emnoc

yes and no 

 

PRO

 

[ul]
  • Simple fool proof
  • one time configure ( still requires routs and fwpolicies )
  • ease of management ( configure it once and forget about it )[/ul]

     

    CON

     

    [ul]
  • Statistics  will not show you if one local/remote subnet traffic selector has problems
  • not compatible with certain firewall or VirtDC vpns ( juniper and panos supports it but  ciscoASA, and most linux of  BSD solutions don't )
  • probably not benetficial in a hub-to-spoke sets  &  at the spokes
  • No means to set IPSEC-SA key life for specific local/remote-subnets if you want or need  less or more key life renewals
  • if you are a fan of fortinet and drink the kook-aid they recommend   specific src/dst-nets in the BCP in a "dialup"vpn
  • any traffic can bring up a tunnel regardless if it correct or a mistake ( no control on what can bring a IPSEC-SA tunnel up )
  • if you monitor or like to monitor SPIs and for specific unique traffic pairs you can loose that visibility with quad 0s[/ul]

     

     

     

    YMMV

     

  • 3 replies

    emnoc
    emnocAnswer
    New Member
    October 18, 2016

    yes and no 

     

    PRO

     

    [ul]
  • Simple fool proof
  • one time configure ( still requires routs and fwpolicies )
  • ease of management ( configure it once and forget about it )[/ul]

     

    CON

     

    [ul]
  • Statistics  will not show you if one local/remote subnet traffic selector has problems
  • not compatible with certain firewall or VirtDC vpns ( juniper and panos supports it but  ciscoASA, and most linux of  BSD solutions don't )
  • probably not benetficial in a hub-to-spoke sets  &  at the spokes
  • No means to set IPSEC-SA key life for specific local/remote-subnets if you want or need  less or more key life renewals
  • if you are a fan of fortinet and drink the kook-aid they recommend   specific src/dst-nets in the BCP in a "dialup"vpn
  • any traffic can bring up a tunnel regardless if it correct or a mistake ( no control on what can bring a IPSEC-SA tunnel up )
  • if you monitor or like to monitor SPIs and for specific unique traffic pairs you can loose that visibility with quad 0s[/ul]

     

     

     

    YMMV

     

  • emnoc
    New Member
    October 18, 2016

    and to add one more critical and easily overlooked

     

    If you use  quad Zeros, and no PFS, than any key material from  the IKE and IPSEC-SAs can compromise ALL traffic carried by just the single IPSEC SA, at least with multiple  IPSEC-SA ( aka phase2-interfaces ) you have some better means for protection single a hijacker would need to hack  each IPSEC-SA independently

     

    FWIW: We should always use   PFS when support by  both vpn-peers imho

     

     

    FortiOSman
    New Member
    October 18, 2016

    Thanks for the input. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!