Question
Adding more subnets to existing tunnel
Hi I have some issues when i add subnets to an existing vpn tunnel. For example i have in phase2 address groups with only one source and one destionation subnet. Tunnel is up and running with these and the i add on both side another subnet. I can see in VPN/Monitor that the new subnet is not in the source or destionation on the other side only the original subnet. I can take down the tunnel and the bring it up but is does not help. I have tried cli commands: diagnose vpn tunnel flush/reset/dumpsa etc nothing clears out the old config. Only way to be 100% sure is to remove old and paste it back into cli with the new subnet, or reboot the fortigate. I have this issue on multiple versions, FortiOS 4 branch, 5 branch... Does anyone else have this issue and does someone know a better way to resolve it ? Example of running tunnel with this issue name=MGMT ver=1 serial=42 111.222.222.222:0->222.111.111.111:0 lgwy=dyn tun=intf mode=auto bound_if=16 proxyid_num=1 child_num=0 refcnt=5 ilast=90 olast=90 stat: rxp=52851 txp=61272 rxb=24854888 txb=5249462 dpd: mode=active on=0 idle=5000ms retry=3 count=0 seqno=80939 natt: mode=none draft=0 interval=0 remote_port=0 proxyid=MGMT-2 proto=0 sa=1 ref=2 auto_negotiate=0 serial=1 src: 0:10.10.10.0/255.255.255.192:0 dst: 0:10.2.0.0/255.255.255.0:0 SA: ref=3 options=0000000e type=00 soft=0 mtu=1436 expire=1740 replaywin=1024 seqno=1 life: type=01 bytes=0/0 timeout=1747/1800 dec: spi=fd2887b0 esp=3des key=24 41f8e32f3502ce3619c8e858f6d2cf64dca029d30498a68b ah=sha1 key=20 5dcb309a77a4f040c52dc99de21a4de61ef84857 enc: spi=f464468b esp=3des key=24 c9848deada3c3620d3c4e8f89bf690906b250e4feafa2ac5 ah=sha1 key=20 b8e2c4ed2e035315a0071150ff39684bd2f83edc config phase 2 edit " MGMT-2" set dst-addr-type name set phase1name " MGMT" set proposal 3des-sha1 aes128-sha1 set src-addr-type name set dst-name " mgmt-destinations" set src-name " mgmt-network" next firewall group edit " mgmt-destinations" set member " 10.2.0.0/24" " 10.3.1.0/25" next Tunnel is interface based but it does not matter which mode i use.
