| Description | This article describes the configuration needed to have all the shortcuts to a given remote spoke deleted when idle. |
| Scope | Available from FortiOS 7.6.0 |
| Solution |
The deletion of all shortcuts to a given spoke will be effective if the following configuration is applied:
set location-id 1.1.1.1 end
conf vpn ipsec phase1-interface edit advpn101 set idle-timeout enable set idle-timeoutinterval 5 set shared-idle-timeout enable next
Below is an example of a 'diagnose debug appli ike -1' when 4 shortcuts from 2 different local IPsec phase1 (advpn101 and advpn102) to a given remote spoke are no longer active and get suppressed.
ike V==root:0:advpn101_0: connection idle time-out for all shared connections ike V=root:0:advpn101_1: going to be deleted ike V=root:0:advpn101_1: flushing ike V=root:0:advpn101_1: deleting IPsec SA with SPI e2a0c6f0 ike V=root:0:advpn101_1:advpn101: deleted IPsec SA with SPI e2a0c6f0, SA count: 1 ike V=root:0:advpn101_1: deleting IPsec SA with SPI e2a0c6ef ike V=root:0:advpn101_1:advpn101: deleted IPsec SA with SPI e2a0c6ef, SA count: 0 ike V=root:0:advpn101_1: sending SNMP tunnel DOWN trap for advpn101 ike V=root:0:advpn101_1:advpn101: delete ike V=root:0:advpn101_1: deleting IPsec SA with SPI e2a0c6eb ike V=root:0:advpn101_1:advpn101: deleted IPsec SA with SPI e2a0c6eb, SA count: 0 ike V=root:0:advpn101_1: sending SNMP tunnel DOWN trap for advpn101 ... ike 0:advpn101: bundle advpn101_1_1.1.1.1 1 del member advpn101_1 ike 0:advpn101: release bundle advpn101_1_1.1.1.1 ... ike 0:advpn102: bundle advpn102_0_1.1.1.1 1 del member advpn102_0 ike 0:advpn102: release bundle advpn102_0_1.1.1.1 ... ike 0:advpn102: bundle advpn102_1_1.1.1.1 1 del member advpn102_1 ike 0:advpn102: release bundle advpn102_1_1.1.1.1 ... ike 0:advpn101: bundle advpn101_0_1.1.1.1 1 del member advpn101_0 ike 0:advpn101: release bundle advpn101_0_1.1.1.1 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.