Cannot add the aggregate vpn member
Hi There,
I tried to create a aggregate VPN between two fortigate node. FOS 7.0.14.
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/779544/ipsec-aggregate-for-redundancy-and-traffic-load-balancing
there are two VPN tunnel established already. and I added one tunnel to the aggregate vpn successfully. But I cannot add another member into the group.
according to the guidance, I have to set aggregate-member enable. But I cannot do it, check the error message below.
# next
Please enable phase2 auto-negotiate if ipsec-aggregate uses redundant algorithm.
This interface is currently in use.
object set operator error, -23, roll back the setting
Command fail. Return code 1
I tried to enable the phase 2 autonegotiation and delete the vpn tunnel and create a new one. the result is same.
I tried to disable the virtual interface but the result is same. Since there is traffic on the physical interface already. I cannot disable it. I don't want to break the service.
Appreciate your advice on how I can achieve it? TIA :)