Created on 02-18-2024 10:07 PM Edited on 10-07-2024 05:51 AM By Anthony_E
Description | This article describes why the tunnel type can no longer be changed after upgrading to v7.2.0 and later. |
Scope | FortiGate v7.2.0 and later. |
Solution |
On v7.2.0 and later, after 'tun_id' is generated, the IPSEC VPN phase 1 interface type cannot be altered. Routes intended for the IPsec tunnel are matched using 'Tun_ID'. As a result, it will not be possible to change the interface type from static remote gateway to DDNS or vice versa.
Output on firmware versions earlier than v7.2.0 can be changed without error:
On v7.2.0 and later the '-9999: -9999' error will appear when changing the tunnel type.
It will also show the same results on the GUI:
To fix this issue and change the tunnel type from the static gateway to dynamic DNS, recreate the VPN tunnel or create a new tunnel interface.
Step 5: After the device is up and running with the restored configuration, verify that all settings from the uploaded file have been correctly applied.
Below command can be run:
This command is utilized to diagnose issues that arise following an upgrade or major configuration change. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.