Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Agent_1994
Contributor

extra P2s when using address group in the P2 configuration

Hello Forum,

 

 I have a setup similar to this recipe: https://cookbook.fortinet.com/hub-and-spoke-vpn-using-quick-mode-selectors/. There's only one datacenter (hub) and múltiple spokes using a single P1 and XAUTH. What we really need about this setup are the routes from the hub to the spokes' subnets.

 

 The P2 contains an Address Group object with three Adresses (for each remote subnet).

 

 It's working, with a "but": in the spokes i go to Monitor -> IPSEC Monitor and i see four P2s: one for each subnet, and the last one for the group. I tried setting "mesh-selector-type" to disable, and i saw one P2 for the group... but on the hub side i see only one route (there should be three).

 

 Is this a "deal with it" kind of thing? or is there a way to solve this?

 

 I repeat, it's working, but the customer asked my "why?" :)

 

 FWIW,

 

Hub: FortiOS 5.6.5

Spokes: FortiOS 5.4.9

 

Thanks in advance,

0 REPLIES 0
Labels
Top Kudoed Authors