Technical Tip: Address Objects with ‘Interface-Subnet’ Address Type Cannot be added under IPv4 Split Tunnel Configuration for Remote Access VPN
| Description | This article describes an issue where the following errors may appear in the GUI when adding an address or address group configured with the Interface Subnet address type under the IPv4 split tunnel option in a dialup IPSec VPN. Error: 'Invalid address selected' - appears when adding an address object. Error: 'Invalid address group selected' - appears when adding an address group. |
| Scope | FortiGate v7.6.3, v7.6.4 |
| Solution | FortiGate GUI prevents adding an address or address group configured with the Interface Subnet address type under the IPv4 split tunnel option in a dial-up IPsec VPN. When attempted, the following errors appear: Address/Address group configuration:
config firewall address edit "port1" set type interface-subnet set subnet 10.126.245.0 255.255.255.248 set interface "port1" next end config firewall addrgrp edit "port1-test" set member "port1" next end GUI:
This issue has been resolved in:
These timelines for firmware release are estimates and may be subject to change. Workaround:
config firewall address edit "Split-Subnet" set subnet 10.126.245.0 255.255.255.248 next end config vpn ipsec phase1-interface GUI:
|






