Description | This article addresses the issue of not being able to reach out to peer IP when connecting to a non FortiGate unit with multiple subnets configured. |
Scope | |
Solution |
If there are more than one subnets (both local and remote) configured over the IPsec VPN, there should be more than one phase2 selector configured instead of including multiple firewall addresses in a single firewall deal with group and defining it as a single phase2 selector.
Route-based IPsec VPN. # config vpn ipsec phase2-interface
Policy Based IPsec VPN. # config vpn ipsec phase2
It is possible to configure mesh-selector-type.
mesh-selector-type {disable | subnet | host}
Note. This entry is only available when ike-version is set to 1. Disable (by default) or set dynamic mesh selectors for IKEv1 VPNs to either subnet or host.
Note that dynamic selectors are not saved to the configuration and will be removed when tunnels are flushed.
Use subnet to install a selector for the address group that matches traffic packets.
Use host to install selector for the source and destination IP addresses of traffic packets. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.