Created on
‎02-18-2024
10:07 PM
Edited on
‎01-14-2025
06:32 AM
By
Stephen_G
Description | This article describes why the tunnel type can no longer be changed after upgrading to v7.2.0 and later. |
Scope | FortiGate v7.2.0 and later. |
Solution |
On v7.2.0 and later, after 'tun_id' is generated, the IPSEC VPN phase 1 interface type cannot be altered. Routes intended for the IPsec tunnel are matched using 'Tun_ID'. As a result, it will not be possible to change the interface type from static remote gateway to DDNS or vice versa.
Output on firmware versions earlier than v7.2.0 can be changed without error:
On v7.2.0 and later the '-9999: -9999' error will appear when changing the tunnel type.
It will also show the same results on the GUI:
To fix this issue and change the tunnel type from the static gateway to dynamic DNS, recreate the VPN tunnel or create a new tunnel interface.
set remotegw-ddns <string> -->Dynamic DNS
Note: remotegw-ddns will only be available if the type is set to 'ddns'.
Step 5: After the device is up and running with the restored configuration, verify that all settings from the uploaded file have been correctly applied.
The below command can be run:
This command is utilized to diagnose issues that arise following an upgrade or major configuration change. |