Created on 06-08-2023 09:31 PM Edited on 12-22-2024 04:14 PM By Stephen_G
Description | This article describes how to add a subnet on the local or remote side or both. To do that, it is necessary to make changes in the phase2 of the existing custom tunnel. |
Scope |
FortiGate. |
Solution |
To add a new subnet in the phase2 selector of a custom tunnel there are 2 approaches:
In the image below, it is possible to see how the address group looks with the existing settings. The 'VPNCustomLocal' and 'VPNCustomremote' are the address groups used in this example VPN tunnel:
It is possible to add the new subnet address to the existing group, either remote or local, and select OK. If the static route and firewall policy also has the same group, it will be updated. Enable 'static route configuration' on the address and address group objects to select the 'VpnCustomlocal' address group in the static route.
On Phase 2 Selectors, locate the Add button as shown in the screenshot below, and add the new subnet as the selector, then select OK to save the new settings:
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.