for future reference:
If you want to have multiple subnets across an IPsec VPN then you can create an address group with multiple address objects in it, and put that into the QM selector as source or destination network.
Here are the restrictions:
1. this usually works only from Fortigate to Fortigate
2. you have to switch the QM type to ' address' in the CLI
3. you have to use address groups for BOTH source and destination subnets even if one contains a single item only (the CLI does not enforce this requirement)
Given these restrictions, it' s usually less hassle to create a bunch of phase 2' s if the number of subnets is small.
I haven' t tried it but with an address you can specify an IP range as well as a subnet. You cannot do that directly in a QM, can you? So that would be another case for using the address group configuration.
Ede
"Kernel panic: Aiee, killing interrupt handler!"