Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GM-GME
New Contributor

IPsec with duplicated phase 2 selector

Hi Community,

 

we have a fortigate vm with a ipsec tunnel. The tunnel is up, but in the IPsec Monitor it shows the phase 2 selector twice (same name, one  up, one down). Also via snmp we get information for two phase 2 selectors with the same name.

 

We tried to recreate phase 2, reboot the fortigate and recreate the complete ipsec tunnel. It still shows the phase 2 selector twice.

 

Did somebody had a similar behavior in the past?

2 REPLIES 2
AEK
SuperUser
SuperUser

Hello

Check phase 2 selector of both FG, source and destination may mismatch. In that case the first tunnel attempt fails and shows tunnel down before re-establish the tunnel.

AEK
AEK
GM-GME
New Contributor

Thanks for this information. On the other side there was a ip address in phase 2 and on our side there was the subnet configured. We changed it from subnet to the ip address and phase 2 is now shown once.

Labels
Top Kudoed Authors