Description | This article describes why recreating an IPsec VPN may fail with an error 'Unable to setup VPN' when using the IPsec Wizard due to duplicate elements from the previous IPsec VPN with the same name which already exists. |
Scope |
FortiGate. |
Solution |
An error 'Unable to Setup VPN' appears in the last step when recreating a VPN using the IPsec Wizard template when using the same IPsec name as the old one. The IPsec Wizard is unable to create the local address group as there is already a local address object and address group from the old VPN configuration that was not deleted. There are other elements from the previous VPN configuration that should be deleted to ensure a smoother VPN setup.
A simple fix for this is to use a new IPsec VPN name when recreating the VPN. If using the same name, then remove all VPN tunnel references from the previous VPN configuration, VPN tunnel itself, local address (including address group), and the blackhole found in static routes.
Try creating the VPN again. It should now be set up successfully.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.