Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mahmoud_ahmed1684
New Contributor

which IPSec selector has higher priority in fortigate

I need to know the way based on it fortigate select  ipsec phae2 selector when there is more than one selector convent for traffic for example

Let there is below 2 selectors 

Selector1 : from 192.168.1.0/28.   >>>>>  10.10.10.0/28

Selector 2 :  from 192.168.1.0/24.  >>>>> 10.10.10.0/24

Selector 3 : 0.0.0.0/0 >>>>>>> 0.0.0.0/0

When traffic come from 192.168.1.3. >>>> 10.10.10.5 which selector will fortigate use to forward traffic

2 REPLIES 2
hbac
Staff
Staff

Hi @mahmoud_ahmed1684,

 

It depends on the phase2 selectors on the other side. It has to match on both sides. 

 

Regards, 

flamer
New Contributor II

It's a fair question but the other answer is correct, phase 2 selectors are negotiated and it depends on the other end vendor, Check Point for example will also pick the largest mask size so Selector 1 and 2 would never establish in the first place (assuming Check Point also had the knuckle selector configured)

Labels
Top Kudoed Authors