Created on
09-23-2024
05:57 AM
Edited on
04-08-2025
09:49 AM
By
Stephen_G
| Description | This article describes how to delete an IPsec tunnel that was created. |
| Scope | FortiGate. |
| Solution |
Follow the steps below to delete the IPsec tunnel:
Note: In the case of IPsec tunnel reference to the Sniffer object, see the screenshot below:
However, when navigating to sniffer under GUI, there is no related packet sniffer of Tunnel interface associated. The attached screenshot above indicates the sniffer ID of IPsec related is '2', using the below command show/delete the sniffer:
config firewall sniffer show delete 2 end
Sometimes, even when there are no visible references, the 'delete' option for the IPsec tunnel in the GUI remains greyed out.
Additionally, attempting to delete Phase 1 or Phase 2 from the CLI results in the error 'cannot delete a static table entry.'
This can be resolved with a few steps. First, search the reference for the tunnel interface with the following command:
show full-configuration | grep <name of the tunnel either phase 1 or phase 2> -f
After, enter to that configuration and manually delete it to remove all references.
After making this change, the reference object for the IPsec tunnel should be removed and can be deleted from this related object.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.