Created on 11-29-2022 09:18 PM Edited on 12-11-2024 05:51 AM By Jean-Philippe_P
Description | This article explains the change in behavior regarding dial-up tunnel interfaces configured as SD-WAN interface members. |
Scope | FortiGate, FortiOS v7.0.8, v7.2.1. |
Solution |
The following configuration is assumed:
If the monitored server is not reachable anymore, over that particular tunnel, it is seen that the static route is not removed.
This is expected behavior for dynamic tunnels configured with 'set net-device disable'.
The workaround would be to configure the tunnel with 'set net-device enable'.
This is not recommended and, as of FortiOS v7.0.8 and v7.2.1, a check has been introduced and it is not possible anymore to add an IPsec tunnel configured with 'set net-device enable' as a member of an SD-WAN zone.
When attempting to enable net-device on an IPsec interface a part of the SD-WAN zone, the following error, 'This interface is used by vwl' is displayed.
HQ-FW # config vpn ipsec phase1-interface HQ-FW (phase1-interface) # edit HQ-ADVPN HQ-FW (HQ-ADVPN) # set net-device enable
This interface is used by vwl.
value parse error before 'enable'
HQ-FW (HQ-ADVPN) #
This means that the IPsec tunnel interface is being used by a virtual wan link. In order to enable net-device on the IPsec tunnel interface, it will be required to remove all SD-WAN references (SD-WAN Zone, SD-WAN Rules, and Performance SLAs). |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.