<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange traffic selectors in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258453#M43643</link>
    <description>&lt;P&gt;Thanks Andy. As that is not under my control, I will ask them what they have. When I had debug on, I was seeing 'universal group' coming back, so I think that is what is set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Sep 2025 12:10:25 GMT</pubDate>
    <dc:creator>ibrown</dc:creator>
    <dc:date>2025-09-29T12:10:25Z</dc:date>
    <item>
      <title>Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258447#M43641</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I've been trying to establish a tunnel with a third party Fortigate in AWS, and whilst I have a working tunnel, I am seeing most peculiar errors coming back from the Fortigate, it basically is rejecting my traffic selectors, but I don't understand how the traffic selectors are being built. I have an R81.20 cluster with a specific vpn domain and we seem to be sending every address it knows about, even though they are outside the encryption domain and in some cases our infrastructure; even the sync interfaces are in there. I've even got the tunnel config for this 3rd party overriding the default and supplying a single address as the encryption domain, and yet this still comes back.&lt;/P&gt;&lt;P&gt;The other VPNs connected to this cluster are star with no routing through the center gateway. This tunnel is set to host to host, partly as that is what I was asked for, and partly because setting it to gateway-to-gateway it does not work, it does the phase1 and phase 2 but encrypted outbound traffic does not reach the host behind the endpoint.&lt;/P&gt;&lt;P&gt;Time: 2025-09-29T10:39:51Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: daemon&lt;BR /&gt;Source: &amp;lt;Single 3rd party vpn terminator&amp;gt;&lt;BR /&gt;Destination: &amp;lt;internal address&amp;gt;&lt;BR /&gt;VPN Peer Gateway:&amp;nbsp;&amp;lt;Single 3rd party vpn terminator&amp;gt;&lt;BR /&gt;Scheme: IKEv2 [UDP (IPv4)]&lt;BR /&gt;Ike: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable MyTSi: &amp;lt;every address the gateway cluster knows about, including the sync interfaces and other vpn devices&amp;gt; MyTSr: &amp;lt;Single 3rd party vpn terminator&amp;gt; &amp;lt;Single 3rd party vpn host&amp;gt; &amp;lt;224.0.0.0 - 224.0.0.255&amp;gt; Peer TSi: &amp;lt;Single 3rd party vpn terminator&amp;gt; Peer TSr:&lt;BR /&gt;IKE Initiator Cookie: 97644c4ac718ec96&lt;BR /&gt;IKE Responder Cookie: 1ee98d9668bb508e&lt;BR /&gt;IKE Phase2 Message ID: 00000002&lt;BR /&gt;IKE IDs: &amp;lt;Single 3rd party vpn terminator&amp;gt;&lt;BR /&gt;Community: VPN_fortigate&lt;BR /&gt;Reject Category: IKE failure&lt;BR /&gt;VPN Feature: IKE&lt;BR /&gt;Action: Reject&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: VPN&lt;BR /&gt;Interface: daemon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas ?&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 11:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258447#M43641</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-09-29T11:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258451#M43642</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Just make sure you have right things selected in what I attached. You can add as many as needed. I have fully licenses Fortigate lab, so if you want me to test anything, let me know. Its on latest firmware, 7.6.4&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 11:59:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258451#M43642</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T11:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258453#M43643</link>
      <description>&lt;P&gt;Thanks Andy. As that is not under my control, I will ask them what they have. When I had debug on, I was seeing 'universal group' coming back, so I think that is what is set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 12:10:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258453#M43643</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-09-29T12:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258456#M43644</link>
      <description>&lt;P&gt;Im 100% sure thats what it is. Otherwise, Fortigate would never throw message like that.&lt;/P&gt;
&lt;P&gt;Not sure where they saw it, but you can have them run debug like this, if they have not already:&lt;/P&gt;
&lt;P&gt;di de di&lt;/P&gt;
&lt;P&gt;di de app ike -1&lt;/P&gt;
&lt;P&gt;di de en&lt;/P&gt;
&lt;P&gt;-get the output&lt;/P&gt;
&lt;P&gt;then have them run -&amp;gt; di de di&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 12:14:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258456#M43644</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T12:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258459#M43645</link>
      <description>&lt;P&gt;From my lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;***********&lt;/P&gt;
&lt;P&gt;Fortigate-VM # di de di&lt;/P&gt;
&lt;P&gt;Fortigate-VM # di de app ike -1&lt;BR /&gt;Debug messages will be on for 30 minutes.&lt;/P&gt;
&lt;P&gt;Fortigate-VM # di de en&lt;/P&gt;
&lt;P&gt;Fortigate-VM #&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Fortigate-VM # get sys status&lt;BR /&gt;Version: FortiGate-VM64-KVM v7.6.4,build3596,250820 (GA.F)&lt;BR /&gt;First GA patch build date: 240724&lt;BR /&gt;Current Security Level: High&lt;BR /&gt;Firmware Signature: certified&lt;BR /&gt;Virus-DB: 93.06103(2025-09-28 22:31)&lt;BR /&gt;Extended DB: 93.06103(2025-09-28 22:31)&lt;BR /&gt;Extreme DB: 1.00000(2018-04-09 18:07)&lt;BR /&gt;AV AI/ML Model: 4.03282(2025-09-28 21:50)&lt;BR /&gt;IPS-DB: 6.00741(2015-12-01 02:30)&lt;BR /&gt;IPS-ETDB: 34.00091(2025-09-26 00:22)&lt;BR /&gt;IPS-MLDB: 2507.00207(2025-07-30 01:00)&lt;BR /&gt;APP-DB: 34.00090(2025-09-25 00:37)&lt;BR /&gt;AIAP-DB: 34.00090(2025-09-25 00:37)&lt;BR /&gt;Proxy-IPS-DB: 6.00741(2015-12-01 02:30)&lt;BR /&gt;Proxy-IPS-ETDB: 34.00091(2025-09-26 00:22)&lt;BR /&gt;Proxy-APP-DB: 34.00090(2025-09-25 00:37)&lt;BR /&gt;FMWP-DB: 0.00000(2001-01-01 00:00)&lt;BR /&gt;IPS Malicious URL Database: 5.00550(2025-09-29 01:23)&lt;BR /&gt;IoT-Detect: 34.00091(2025-09-25 11:25)&lt;BR /&gt;OT-Detect-DB: 0.00000(2001-01-01 00:00)&lt;BR /&gt;OT-Patch-DB: 0.00000(2001-01-01 00:00)&lt;BR /&gt;OT-Threat-DB: 6.00741(2015-12-01 02:30)&lt;BR /&gt;IPS-Engine: 7.01154(2025-08-13 22:24)&lt;BR /&gt;Timezone DB Version: 1.0007&lt;BR /&gt;Timezone DB IANA Version: 2024b&lt;BR /&gt;Serial-Number: FGVMSLTM25001105&lt;BR /&gt;License Status: Valid&lt;BR /&gt;License Expiration Date: 2025-11-28&lt;BR /&gt;VM Resources: 2 CPU/2 allowed, 3850 MB RAM&lt;BR /&gt;Log hard disk: Not available&lt;BR /&gt;Hostname: Fortigate-VM&lt;BR /&gt;Private Encryption: Disable&lt;BR /&gt;Operation Mode: NAT&lt;BR /&gt;Current virtual domain: root&lt;BR /&gt;Max number of virtual domains: 2&lt;BR /&gt;Virtual domains status: 1 in NAT mode, 0 in TP mode&lt;BR /&gt;Virtual domain configuration: disable&lt;BR /&gt;FIPS-CC mode: disable&lt;BR /&gt;Current HA mode: standalone&lt;BR /&gt;Branch point: 3596&lt;BR /&gt;Release Version Information: GA&lt;BR /&gt;FortiOS x86-64: Yes&lt;BR /&gt;System time: Mon Sep 29 08:18:49 2025&lt;BR /&gt;Last reboot reason: power cycle&lt;/P&gt;
&lt;P&gt;Fortigate-VM &lt;SPAN class="lia-mentions-gte-v2-autocomplete"&gt;&lt;SPAN class="lia-mentions-gte-v2-trigger" contenteditable="false"&gt;#&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 12:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258459#M43645</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T12:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258466#M43646</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Apparently it's set to a single host, as per my end. What puzzles me more, is why my CP cluster is sending such a big traffic selector, surely that isn't normal ? It's got other 3rd party vpn endpoints in it, which are not routeable via the cluster so should never be there.&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:00:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258466#M43646</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-09-29T14:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258467#M43647</link>
      <description>&lt;P&gt;Can you show how is tunnel management configured in vpn community?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:01:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258467#M43647</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T14:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258469#M43648</link>
      <description>&lt;P&gt;Certainly, nothing special&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tunnel.png" style="width: 770px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31563iDAC7B8034E86E716/image-size/large?v=v2&amp;amp;px=999" role="button" title="tunnel.png" alt="tunnel.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:05:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258469#M43648</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-09-29T14:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258471#M43649</link>
      <description>&lt;P&gt;K, fair enough, so then traffic selectors phase 2 have to match on FGT.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:34:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258471#M43649</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-29T14:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258678#M43697</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;&lt;P&gt;Were you able to sort this out?&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 11:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258678#M43697</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T11:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258690#M43702</link>
      <description>&lt;P&gt;Sadly not. The 3rd party is a gov institution so I only get so much info. We've tried a host encryption domain on the fortigate and a universal one, only the former works but sends the errors.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 13:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258690#M43702</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-10-01T13:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258691#M43703</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Just to make sure, so currently, on FGT, its set as hosts? If yes, same error as before?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 13:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258691#M43703</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T13:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258694#M43705</link>
      <description>&lt;P&gt;Yes, exactly. When set to gateway to gateway on the CP end and 0.0.0.0 on the fortigate I saw the key exchange but traffic did not flow correctly. Hence reverting to this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 13:52:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258694#M43705</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-10-01T13:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258695#M43706</link>
      <description>&lt;P&gt;Right, but what when its set to host?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 13:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258695#M43706</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T13:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258696#M43707</link>
      <description>&lt;P&gt;when host to host, key exchange and success, but the fortigate reply complaining about the traffic selectors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 14:02:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258696#M43707</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-10-01T14:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258698#M43708</link>
      <description>&lt;P&gt;To me, though only way to tell for sure would be if I saw it via remote, but base don below, seems like GFT side "thinks" that either its own selectors are hosts and other side is everething else, or the other way around.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ike: Child SA exchange: Sending notification to peer: Traffic selectors unacceptable MyTSi: &amp;lt;every address the gateway cluster knows about, including the sync interfaces and other vpn devices&amp;gt; MyTSr: &amp;lt;Single 3rd party vpn terminator&amp;gt; &amp;lt;Single 3rd party vpn host&amp;gt; &amp;lt;224.0.0.0 - 224.0.0.255&amp;gt; Peer TSi: &amp;lt;Single 3rd party vpn terminator&amp;gt; Peer TSr:&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 14:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258698#M43708</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T14:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258701#M43709</link>
      <description>&lt;P&gt;Agreed, I am going to take this up with the TAC, as I can't fathom why my gateway should ever expose those addresses.&lt;/P&gt;&lt;P&gt;Thank you for the help !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 14:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258701#M43709</guid>
      <dc:creator>ibrown</dc:creator>
      <dc:date>2025-10-01T14:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Strange traffic selectors</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258703#M43711</link>
      <description>&lt;P&gt;Sounds good, keep us posted!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 14:17:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-traffic-selectors/m-p/258703#M43711</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T14:17:34Z</dc:date>
    </item>
  </channel>
</rss>

