The FortiGate has two Phase2 definitions under the same Phase1:
10.202.159.192/26 <-> 10.200.0.0/14
10.202.159.192/26 <-> 10.224.0.0/11
OPNsense currently has only the first Child SA configured.
Could FortiGate reject Quick Mode if it expects both selectors to be configured on the peer?
Also, OPNsense generates start_action=start while FortiGate has auto-negotiate disable.
10.202.159.192/26 <-> 10.200.0.0/14
10.202.159.192/26 <-> 10.224.0.0/11
OPNsense currently has only the first Child SA configured.
Could FortiGate reject Quick Mode if it expects both selectors to be configured on the peer?
Also, OPNsense generates start_action=start while FortiGate has auto-negotiate disable.
"