Description | This article describes that for troubleshooting and some configuration change scenarios, it is maybe necessary to temporarily prevent an IPSEC tunnel from attempting to initiate or respond to IKE requests. |
Scope | FortiGate. |
Solution |
This can be achieved by disabling the tunnel interface from under Network>Interface -> Expanding the Outgoing Interface of IPSec tunnel -> 'Right-Click' the tunnel Interface -> Set Status -> Disable.
config system interface This will function similarly to disabling a physical interface but will simply prevent IKE from making attempts to establish a tunnel (for a site-to-site tunnel) or responding to connection attempts for this specific tunnel. To confirm the behavior, use ike debugs: dia debug application ike -1 dia debug en
To stop the debug, run the following commands:
diagnose debug disable diagnose debug reset
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.