Skip to main content
sha-1_FTNT
Staff
Staff
June 28, 2018

Technical Tip: 'set net-device' new route-based IPsec logic

  • June 28, 2018
  • 0 replies
  • 73906 views

Description

 

This article describes that, as of v5.6.3 and v6.0, a new behavior is implemented for route-based IPsec dialup tunnels.
As of v6.2.1, this behavior is implemented for ADVPN shortcuts.
 
Scope

 

Dialup phase1 :
v5.6.3 and above.
v6.0 and above.
This option is removed from v7.0.0 and above.
 
Static phase1 (for ADVPN shortcuts):
v6.2.1 and above.

This option is removed from FortiOS 7.0.0 and above.


Solution

 

This behavior is controlled by two new CLI settings:

config vpn ipsec phase1-interface
    edit <ph1-name>
         set type { dynamic | static }
         set net-device { disable* | enable }
         set tunnel-search { selectors* | nexthop }
         ( ... )
end


These settings and the corresponding behaviors are detailed in the PDF file available in the Attachments section.
 
Note:
These commands are valid for versions that are no longer supported. Make sure to follow the recommendations in the more recent guides available for the supported firmware versions: Upgrade Path Tool Table   Product LifeCycle information