I'm trying to create a ipsec VPN tunnel on routing policy by using VTI between Fortigate and Stormshield.
Network side Stormshield is 172.28.100.0/24
And Fortigate side is 172.19.0.0/16 and 172.20.0.0/16
SNS vti is 192.168.155.3
FG vti is 192.168.155.1
On Stormshield in phase 2, I put VTI ip address on local network (192.168.155.3) and remote network (192.168.155.1).
Tunnel is up when phase 2 selector n Fortigate side:
proxyid=HQ-wan1 proto=0 sa=1 ref=3 serial=1 ads
Fortigate drop packet because "No matching IPsec selector, drop"
I have implement BGP routing and it's work.
Thank you for your help