Skip to main content
TomFortinet
New Member
April 18, 2012
Question

Cannot delete VPN tunnel configuration

  • April 18, 2012
  • 4 replies
  • 22179 views
I cannot delete the PH1 of an existing tunnel configuration. All rules have been deleted. Routing also. When I try the command: XXX-XXXX(phase1-interface)#delete TUNNEL-NAME this is what I get: This phase1-interface is currently used command_cli_delete:3724 delete table entry TUNNEL-NAME unset oper error ret=-23 Command fail. Return code -23 Reboot the box would be a nightmare, anyone has a solution to this? Thanks!

    4 replies

    ede_pfau
    SuperUser
    SuperUser
    April 18, 2012
    Hi, welcome to the forums. A phase1 in interface mode is an interface. You can attach several objects to an interface, including - addresses - VIPs - IP pools - a DHCP server - policies - routes - policy routing I' d get a backup of the config and search it with an editor for the phase1 name. Aside, does it really bug you to have a dangling phase1?
    TomFortinet
    New Member
    April 18, 2012
    Hi Thanks for the hints I would not bother actually...but a customer is flogging me!! This is also why I am looking for a silver bullet. Every change I do has to be scheduled and approved and it would look very bad if I gave the impression to rummage in his configuration rather then make some aimed changes. Thanks!
    rwpatterson
    New Member
    April 18, 2012
    ORIGINAL: ede_pfau Bob, there' s a diag command to check the dependency of an object, could you post it?
    Take a look here: http://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&externalId=FD30620
    TomFortinet
    New Member
    April 18, 2012
    THAAANKS!!!!! That is the silver bullet!!!
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.