FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
salemneaz
Staff
Staff
Article Id 350645
Description This article describes the solution to remove IP from an Interface.
Scope FortiOS 7.2 and above.
Solution

Attempting to remove LAN IP from the interface gives an error 'Entry in Use'.

The steps given below need to be followed:

 

  • This error is coming because the Interface has references associated with it, as shown on the screenshot below.

1.jpg

 

2.jpg

 

  • The references need to be cleared.
  • Hover the mouse pointer on the references and select it. 
  • It will bring up the reference section as shown in the screenshot given below.

 

3.jpg

 

  • Delete each of the references by selecting them individually.
  • For example, select 'Internet(1)' under the Firewall Policy and select 'View List' this brings up the Reference that needs to be deleted.

 

5.jpg

 

  • Either the entire policy is deleted or the interface 'Port2' is removed from the 'Incoming interface'.

 

7.jpg

 

6.jpg

 

  • The same procedure is followed for the rest of the other two reference objects.
  • Once all the references are cleared then try to remove the address from the interface.

 

8.jpg

 

  • The references are showing 'Zero' but still it is impossible to remove the IP address. It is because it is being used at the syslog as a source-ip.

 

9.jpg

 

  • From the firewall CLI remove the 'Source-IP' for the Syslog server.

 

10.jpg

 

  • The command used to unset the source-ip 'unset source-ip'.
  • After that, the IP can be removed from the interface.

 

11.jpg