This article describes the multiple options to configure phase2 selectors on VPN IPsec.
Scope
FortiOS 7.0, 7.2 and 7.4.
Solution
Below is the way to configure each of these options:
Subnet.
IP Range.
Address Group.
Note: It is important to mention that FQDN is supported on the Address group, however, VPN IPsec does not support FQDN objects as named addresses. Therefore, if adding a FQDN object on the Address Group, the address group will not be available on the phase2 selector as below:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.