Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Geoffrey
New Contributor

Problem adding a phase 2 Selector

Hey guys,

 

I have an up and running site-to-site vpn between two fortigates.

This is the ip config:

Location 1: 10.1.20.0/24 -> 10.2.20.0/24

Location 2: 10.2.10.0/24 -> 10.1.20.0/24

 

This seems to be working well we can ping clients on both locations.

 

Now we want to add our server networks, i added a phase 2 selector like this:

Location 1: 10.1.10.0/24 -> 10.2.10.0/24

Location 2: 10.2.10.0/24 -> 10.1.10.0/24

 

I have added the static routes and firewall policies on both FG's, but we cannot ping any server on both locations.

Are we forgetting something? I checked the manual about vpn but i cannot for the life of me find what could be wrong.

 

Any vpn guru that can point me in the direction that i have to look in to?

 

Thx in advance!

 

11 REPLIES 11
MikePruett

No worries. After reading my message again it comes off abrasive. Not my intention at all.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Toshi_Esumi

I didn't mean for you to feel like that. I've just been trained to check thoroughly any network issues so long time, like it's not relying on the default route, which might have changed, and so on. That's all.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors