Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JeffreyMik
New Contributor

Multiple phase 2 selectors needed for multiple subnets?

Hello,

I am trying to setup a IPSec VPN tunnel between a Fortigate VM and a Cisco ASAv in GNS3. I have multiple subnets behind the Fortigate and one subnet behind the ASA. When I create a IPSec tunnel on the Fortigate, I use a group-object with all the local subnets from the Fortigate as the local-network at the phase 2 selectors.

When the tunnel is configured at both ends, the fortigate lists the IPSec tunnel, but the phase 2 tunnel is not up all the way. Only one subnet is listed up and the other subnets are down. I found the following Technical Tip where they say that I need to create multiple phase 2 selectors for each local subnet from the Fortigate.

How to configure VPN for multiple subnets - Fortinet Community

When I do this, the VPN works as it should. But is there a way to only need one phase 2 selector for every local subnet? Or do I need to make a selector for every subnet that needs to be allowed over the VPN?


Kind regards,

Jeffrey

2 Solutions
hbac
Staff
Staff

Hi @JeffreyMik,

 

Multiple subnets in one phase2 selector works fine between 2 FortiGates but not with Cisco. I would suggest keeping them separated with multiple phase2 selectors. 

 

Regards, 

View solution in original post

ozkanaltas

Hello @JeffreyMik ,

 

For example, you can configure 10.0.0.0/8 instead of 10.10.10.0/24. 

 

After that, you can restrict access with the policy. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
5 REPLIES 5
ozkanaltas
Contributor III

Hello @JeffreyMik ,

 

Yes, you are right. If you want to add more subnets in your tunnel you need to configure multiple phase 2 on FortiGate. If you don't want this. You can configure a wide subnet on your tunnel. This is how Fortigate works.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
JeffreyMik

"You can configure a wide subnet on your tunnel"

What do you mean with this? How does this work?

ozkanaltas

Hello @JeffreyMik ,

 

For example, you can configure 10.0.0.0/8 instead of 10.10.10.0/24. 

 

After that, you can restrict access with the policy. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
hbac
Staff
Staff

Hi @JeffreyMik,

 

Multiple subnets in one phase2 selector works fine between 2 FortiGates but not with Cisco. I would suggest keeping them separated with multiple phase2 selectors. 

 

Regards, 

sanjayputhalath_FTNT

Hi @JeffreyMik  

If it is IKEV1 you can use 'set mesh-selector-type subnet' command in Phase1 configuration. Refer the following link for more details.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dynamic-creation-of-IPsec-tunnels-IKEv1-dy...

Labels
Top Kudoed Authors