If multiple phase 2 exist, FortiGate directs traffic to the correct phase 2.
Allows granular security settings for each LAN.
If traffic does not match an lPsec SA selector, it is dropped.
ln point-to-pointVPNs, selectors must match.
- The source on one FortiGate is the destination setting on the other.
Select which SA to apply using:
Destination and source IP subnet(s)
Protocol number
Source port and destination port
Select one of the following: