Created on
08-13-2024
10:14 PM
Edited on
08-11-2025
01:10 AM
By
Anthony_E
This article describes the multiple options to configure phase2 selectors on VPN IPsec.
Scope
FortiOS v7.0, v7.2, and v7.4.
Solution
Below is the way to configure each of these options:
Subnet.
IP Range.
Address Group.
Note: It is important to mention that FQDN is supported on the Address group, however, VPN IPsec does not support FQDN objects as named addresses. Therefore, if adding an FQDN object to the Address Group, the address group will not be available on the phase2 selector as below:
See the example below:
There are 2 address groups created: VPN Group subnet (consists of only subnets) and VPN Group with name address (consists of both subnets and FQDN).
See the Phase 2 selector below, in which it is populating the address group that does not have the FQDN called:
It is not possible to use an FQDN for Phase 2 during tunnel construction. However, FQDN address groups can be added to the existing address group after Phase 2 has been created.
The phase2 will be deleted when the device is upgraded or rebooted because the firewall does not permit generating with a FQDN address object.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.