Created on
06-08-2023
09:31 PM
Edited on
03-26-2025
11:37 PM
By
Jean-Philippe_P
Description | This article describes how to add a subnet on the local or remote side or both. To do that, it is necessary to make changes in phase2 of the existing custom tunnel. |
Scope |
FortiGate. |
Solution |
To add a new subnet in the phase2 selector of a custom tunnel, there are 2 approaches:
If the tunnel looks like the following, do not create a separate phase2 selector:
In the image below, it is possible to see how the address group looks with the existing settings. The 'VPNCustomLocal' and 'VPNCustomremote' are the address groups used in this example VPN tunnel:
It is possible to add the new subnet address to the existing group, either remote or local, and select OK. If the static route and firewall policy also have the same group, it will be updated. Enable 'static route configuration' on the address and address group objects to select the 'VpnCustomlocal' address group in the static route.
To add a new phase 2 selector, go to VPN -> IPsec Tunnel and select to edit the tunnel. On Phase 2 Selectors, locate the Add button as shown in the screenshot below, and add the new subnet as the selector, then select OK to save the new settings:
If there is no 'Add' button as above, it means that it was created by the wizard. There are two ways to accomplish this task, which is converting from the wizard mode to custom on the GUI or changing it from the CLI with the command:
Or create an address object with the subnet, which is required in phase2, and add it to the group 'VpnCustomloca' or 'VpnCustomremote'.
Related article: |