Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mahmoud_ahmed1684
New Contributor

which IPSec selector has higher priority in fortigate

I need to know the way based on it fortigate select  ipsec phae2 selector when there is more than one selector convent for traffic for example

Let there is below 2 selectors 

Selector1 : from 192.168.1.0/28.   >>>>>  10.10.10.0/28

Selector 2 :  from 192.168.1.0/24.  >>>>> 10.10.10.0/24

Selector 3 : 0.0.0.0/0 >>>>>>> 0.0.0.0/0

When traffic come from 192.168.1.3. >>>> 10.10.10.5 which selector will fortigate use to forward traffic

2 REPLIES 2
hbac
Staff
Staff

Hi @mahmoud_ahmed1684,

 

It depends on the phase2 selectors on the other side. It has to match on both sides. 

 

Regards, 

flamer
New Contributor II

It's a fair question but the other answer is correct, phase 2 selectors are negotiated and it depends on the other end vendor, Check Point for example will also pick the largest mask size so Selector 1 and 2 would never establish in the first place (assuming Check Point also had the knuckle selector configured)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors