| Description | This article describes the solution when hub-and-spoke ADVPN (mode-cfg) tunnels down after upgrade to FortiOS 7.4.9+ when assign-ip is enabled on the spoke and the tunnel IP is manually configured |
| Scope | FortiOS 7.4.9+. |
| Solution |
The issue occurs when both conditions below are present:
Example of configuration:
config system interface end
config vpn ipsec phase1-interface end
Symptoms:
Solution:
Before the upgrade, change the spoke configuration to the following:
config vpn ipsec phase1-interface |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.