Hello,
I am trying to setup a IPSec VPN tunnel between a Fortigate VM and a Cisco ASAv in GNS3. I have multiple subnets behind the Fortigate and one subnet behind the ASA. When I create a IPSec tunnel on the Fortigate, I use a group-object with all the local subnets from the Fortigate as the local-network at the phase 2 selectors.
When the tunnel is configured at both ends, the fortigate lists the IPSec tunnel, but the phase 2 tunnel is not up all the way. Only one subnet is listed up and the other subnets are down. I found the following Technical Tip where they say that I need to create multiple phase 2 selectors for each local subnet from the Fortigate.
How to configure VPN for multiple subnets - Fortinet Community
When I do this, the VPN works as it should. But is there a way to only need one phase 2 selector for every local subnet? Or do I need to make a selector for every subnet that needs to be allowed over the VPN?
Kind regards,
Jeffrey
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @JeffreyMik,
Multiple subnets in one phase2 selector works fine between 2 FortiGates but not with Cisco. I would suggest keeping them separated with multiple phase2 selectors.
Regards,
Hello @JeffreyMik ,
For example, you can configure 10.0.0.0/8 instead of 10.10.10.0/24.
After that, you can restrict access with the policy.
Hello @JeffreyMik ,
Yes, you are right. If you want to add more subnets in your tunnel you need to configure multiple phase 2 on FortiGate. If you don't want this. You can configure a wide subnet on your tunnel. This is how Fortigate works.
"You can configure a wide subnet on your tunnel"
What do you mean with this? How does this work?
Hello @JeffreyMik ,
For example, you can configure 10.0.0.0/8 instead of 10.10.10.0/24.
After that, you can restrict access with the policy.
Hi @JeffreyMik,
Multiple subnets in one phase2 selector works fine between 2 FortiGates but not with Cisco. I would suggest keeping them separated with multiple phase2 selectors.
Regards,
Hi @JeffreyMik
If it is IKEV1 you can use 'set mesh-selector-type subnet' command in Phase1 configuration. Refer the following link for more details.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dynamic-creation-of-IPsec-tunnels-IKEv1-dy...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.