Skip to main content
hbac
Staff
Staff
August 24, 2023

Troubleshooting Tip: Error '-9999' when changing remote gateway type of an IPsec tunnel

  • August 24, 2023
  • 0 replies
  • 4773 views
Description

This article describes how to fix Error '-9999: -9999', which appears when trying to change the Remote Gateway type of an IPsec tunnel on the GUI or CLI. In this example, an attempt was made to change the Remote Gateway from static to Dynamic DNS under an IPsec tunnel 'SiteA'.

 

                               SiteA.png

                                    

CLI.png

Scope FortiGate v7.2.0 and later.
Solution

This is an expected behavior in v7.2.0 and later. The IPsec phase 1 interface type cannot be changed after it is configured.

This is due to the tunnel ID parameter (tun_id), which is used to match routes to IPsec tunnels to forward traffic. If the IPsec phase 1 interface type needs to be changed, a new interface must be configured.

Here is a related article on how to reconfigure the IPSEC and change the tunnel type:
Technical Tip: Unable to change IPSEC tunnel type and getting -9999: -9999 error

 

Note:

This is only applicable to Route-based IPsec VPN. Changing of the remote gateway is still possible with a Policy-based IPsec VPN. Refer below to learn more about the difference between the two.

 

Related document:

VPN security policies

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!