Hello,
Is anyone running 0.0.0.0/0.0.0.0 as the source and destination for a P2 selector?
I have a growing list of about 30 P2's that would be much easier to manage if it were just the one wildcard entry. I would still be controlling the traffic on my policies.
Any pros/cons to doing it this way? The unit on the other side of the tunnel is a Fortigate as well.
Thanks
Solved! Go to Solution.
yes and no
PRO
[ul]
CON
[ul]
YMMV
PCNSE
NSE
StrongSwan
yes and no
PRO
[ul]
CON
[ul]
YMMV
PCNSE
NSE
StrongSwan
and to add one more critical and easily overlooked
If you use quad Zeros, and no PFS, than any key material from the IKE and IPSEC-SAs can compromise ALL traffic carried by just the single IPSEC SA, at least with multiple IPSEC-SA ( aka phase2-interfaces ) you have some better means for protection single a hijacker would need to hack each IPSEC-SA independently
FWIW: We should always use PFS when support by both vpn-peers imho
PCNSE
NSE
StrongSwan
Thanks for the input.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.