Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carlanderska_S
New Contributor

IPsec Tunnels Phase 2 and groups

Hi!

 

I've added a addressgroup under Remote Address for Phase 2 Selectors. Does this work or do I have to add the addresses separately?

 

Thank you.

4 REPLIES 4
Toshi_Esumi
Esteemed Contributor III

How did you create a group in IPsec Phase2 setting GUI? I don't see any option to set a "group" there.

The traffic selectors are pare of local<->remote. If you need to set multiple subnets on remote side you need add a new set like 172.16.0.0/16<->192.168.0.0/16 and 172.16.0.0/16<->10.10.0.0/16.

Toshi_Esumi
Esteemed Contributor III

Ok, through the wizard, you can put multiple subnets like my previous post on remote side separated by a comma ','. Then it would generate two pairs with the same local subnet.

emnoc
Esteemed Contributor III

It really depends

 

1: if it's  FGT-to-FGT firewall and  route-based, than a  0..0.0.0/0:0  is good enough

 

2: if it's  FGT-toSRX firewall and  route-based, than a  0..0.0.0/0:0  is good enough

 

3: if it a FGT-2- <insert almost anything else  CHKP/SonicWall/ASA/ForcePT/pfSense > than unique src/dst-subnets or unique named-network-elements must be used in the phase2

 

YMMV,  but the 1-3 rules are pretty much what it is

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Carlanderska_S

Thank you for the answers. What I meant was that I added an address-group which contains more than one address into the Phase 2 Selectors Remote Address.

Labels
Top Kudoed Authors