DescriptionAs of FortiOS 5.6.3 & 6.0, a new behavior is implemented for route-based IPsec dialup tunnels.
As of FortiOS 6.2.1, this behavior is implemented for ADVPN shortcuts
ScopeDialup phase1 :
FortiOS 5.6.3 and above
FortiOS 6.0 and above
Static phase1 (for ADVPN shortcuts):
FortiOS 6.2.1 and above
SolutionThis behavior is controlled by two new CLI settings:
config vpn ipsec phase1-interface
edit <ph1-name>
set type { dynamic | static }
set net-device { disable* | enable }
set tunnel-search { selectors* | nexthop }
( ... )
end
These settings and their corresponding behaviors are detailed in the PDF file available in the Attachments section.