Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jvarouxis
New Contributor

Wan ip to map with host which belongs to an ipsec network (No matching IPsec selector)

Dear All,

 

i have a Fortigate 100D 5.2.2 latest firmware.

my scope is to  map a public ip A to a host that is accessible on another site to site through ipsec vpn.

 

What i have done is :

 

Create a virtual ip  A mapped to host 10.20.10.2

Create the firewall policy from Wan to the vpn interface using the Virtual IP that is created.

The Vpn phase2 that i have is the A public ip A/255.255.255.255 to remote 10.20.10.2.

 

In Debug logs i see No matching IPsec selector,drop.

s

Do i have to use 0.0.0.0/0.0.0.0 in phase 2 of the vpn (which i would like to avoid) or exists any other method to pass the requests from Wordl wan -> My public A ip-> Ipsec Vpn -> Host 10.20.10.2 ?

 

Any help /Suggestion would be much appreciated.

 

 

 

 

5 REPLIES 5
emnoc
Esteemed Contributor III

Put the  VIP ext-ip in the phase2 selectors,  this is what your presenting to the remote-peer not the inside-mapped-ip.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
jvarouxis
New Contributor

Dear Emnoc ,

 

thank you for your reply.

i have already added the A public ip of y wan interface and with this action i still getting the same .

In the phase 2 i have the a/32  and the network 10.20.10.2 and still getting the same ( No matching IPsec selector).

 

 

 

 

ashukla_FTNT
Staff
Staff

what is the source and destination ip of the packet which is getting denied and it is in which direction?

post the debug output if possible

jvarouxis
New Contributor

Thank you too for your reply.

 

the debug  log results is the below:

==========================================

2015-02-14 07:37:48 id=20085 trace_id=1 func=print_pkt_detail line=4373 msg="vd-root received a packet(proto=1, 178.128.20.20:1->150.150.216.28:8) from wan2. code=8, type=0, id=1, seq=750." 2015-02-14 07:37:48 id=20085 trace_id=1 func=resolve_ip_tuple_fast line=4432 msg="Find an existing session, id-000034c5, original direction" 2015-02-14 07:37:48 id=20085 trace_id=1 func=__ip_session_run_tuple line=2534 msg="DNAT 150.150.216.28:8->10.20.10.2:1" 2015-02-14 07:37:48 id=20085 trace_id=1 func=ipsecdev_hard_start_xmit line=121 msg="enter IPsec interface-Pri_VPN" 2015-02-14 07:37:48 id=20085 trace_id=1 func=ipsec_common_output4 line=619 msg="No matching IPsec selector, drop"

=========================================================================================

 

The Virtual ip is below

======================================

config firewall vip     edit "Public IP"      set extip 150.150.216.28      set extintf "wan2"      set mappedip "10.20.10.2"    next

[size="1"]======================================[/size]

 

If you need any further info please let me know.

Thanks in Advanced

 

 

jvarouxis
New Contributor

Dear All,

 

finally i solved it.

I create and IP Pool with My Public IP and i have used it in the firewall policy and it worked.

As Summary i have done Source Nat to my Public Ip.

 

Thank you all for your reply.

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors