Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carlanderska_S
New Contributor

Phase 2 Selectors

Hi!

 

Should the Local Address be an internal address like 192.168.14.0 at our site and the remote address an internal address for the remote site lika 192.168.15.0 or should it be external addresses?

 

Thank you.

1 Solution
rwpatterson
Valued Contributor III

The selectors (as the name implies) 'select' the networks that are allowed to pass through the tunnels on the INSIDE of the VPN, so yes the private addresses are the ones to be used here. Phase 1 determines the peer connections.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

View solution in original post

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
9 REPLIES 9
rwpatterson
Valued Contributor III

The selectors (as the name implies) 'select' the networks that are allowed to pass through the tunnels on the INSIDE of the VPN, so yes the private addresses are the ones to be used here. Phase 1 determines the peer connections.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Carlanderska_S

Thank you! The firewall tells me that the IPsec tunnel is down. I can't bring it up. The log says that Phase 1 is successfully though.

emnoc
Esteemed Contributor III

What are you connecting  with ( cisco  palo fortigate juniper ). You need to validate ike/ipsec settings and monior for IKE/IPSEC SAs

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Carlanderska_S

Thank you for the reply. I'm trying to connect to a Cisco ASA. Where do I find the monitor for IPsec/IKE?

 

 

JD168
New Contributor III

Hi, please set as local address the local internal lan (192.168.14.0) and as remote address the remote lan (192.168.15.0). Kind regards.

Kind regards

Jens

Kind regards Jens
Carlanderska_S

Thank you!

GabLVillarreal

I have this same Issue, everything seems to be correctly configured, outgoing and incomming policies, static route, ike, encryption and DS groups on both FG devices. But when I try to bring up phase 2 selectors, it pretty much does nothing but keep successfully negotiating phase 1. 

rwpatterson

Welcome to the forums.

 

Look into the logs. (Log&Report, Event log) There should show you the result of the tunnel negotiation in detail.

 

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

If these are route-based vpn, ensure a route is present.

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors