FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
HarveyRebelo
Staff
Staff
Article Id 332845
Description

 

This article describes the multiple options to configure phase2 selectors on VPN IPsec.

 

Scope

 

FortiOS 7.0, 7.2 and 7.4.

 

Solution

  1. During Phase 2 selectors you have the next option to configure the source and destinations.

HarveyRebelo_18-1723582814498.png

 

Below is the way to configure each of these options:

 

  • Subnet: Allow to configure a subnet, which can be a default subnet or a specific subnet.
     

HarveyRebelo_19-1723582814499.png

 

  • IP Range: Allow to configure a range of IP addresses in case it is desired to allow a specific host to send traffic over VPN IPsec that owns the same LAN.

HarveyRebelo_20-1723582814499.png

 

  • IP Address: Allow to configure a specific IP address.
     

HarveyRebelo_21-1723582814500.png

 

  • Named Address: Allow to set the next address objects:

Subnet.

IP Range.

Address Group.

 

HarveyRebelo_22-1723582814501.png

 

HarveyRebelo_23-1723582814503.png

 

HarveyRebelo_24-1723582814505.png

 

Note: It is important to mention that FQDN is supported on the Address group, however, VPN IPsec does not support FQDN objects as named addresses. Therefore, if adding a FQDN object on the Address Group, the address group will not be available on the phase2 selector as below:

 

HarveyRebelo_25-1723582814506.png

 

HarveyRebelo_26-1723582814507.png