Hello Forum,
I have a setup similar to this recipe: https://cookbook.fortinet.com/hub-and-spoke-vpn-using-quick-mode-selectors/. There's only one datacenter (hub) and múltiple spokes using a single P1 and XAUTH. What we really need about this setup are the routes from the hub to the spokes' subnets.
The P2 contains an Address Group object with three Adresses (for each remote subnet).
It's working, with a "but": in the spokes i go to Monitor -> IPSEC Monitor and i see four P2s: one for each subnet, and the last one for the group. I tried setting "mesh-selector-type" to disable, and i saw one P2 for the group... but on the hub side i see only one route (there should be three).
Is this a "deal with it" kind of thing? or is there a way to solve this?
I repeat, it's working, but the customer asked my "why?" :)
FWIW,
Hub: FortiOS 5.6.5
Spokes: FortiOS 5.4.9
Thanks in advance,
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.