Troubleshooting Tip: ADVPN Hub-and-Spoke tunnels fail after upgrade to FortiOS v7.4.9+ when Mode-CFG (assign-ip) is enabled on tunnels with manually configured overlay IPs
| Description | This article describes the solution when hub-and-spoke ADVPN (mode-cfg) tunnels down after upgrade to FortiOS v7.4.9 or later when assign-ip is enabled on the spoke and the tunnel IP is manually configured. |
| Scope | FortiOS v7.4.9 and above. |
| Solution | The issue occurs when both conditions below are present:
Example of configuration:
config system interface end
config vpn ipsec phase1-interface end
Symptoms:
IKE Debug Logs:
On the Spoke:
ike V=root:0:vpn-pfi-hub: connection expiring due to mode-cfg client IPv4 error ike V=root:0:vpn-pfi-hub: going to be deleted ike V=root:0:vpn-pfi-hub: schedule auto-negotiate
On the Hub:
twin connection
Solution: Before the upgrade, change the spoke configuration to the following:
config vpn ipsec phase1-interface |
