Description | This article describes a known issue when editing any parameter on tunnel interfaces with IP/Netmask set to 0.0.0.0/0.0.0.0 will throw an error 'A tunnel IP must have a mask of 255.255.255.255'. The article also mentions the workaround to edit such interfaces. |
Scope | FortiManager v7.2.x, FortiManager v7.4.6, and below. |
Solution |
Editing any parameter of tunnel interfaces whose IP/Netmask is set to 0.0.0.0/0.0.0.0 will result in FortiManager showing an error 'A tunnel IP must have a mask of 255.255.255.255'. The user can still modify parameters directly on FortiGate, which will be updated on FortiManager through auto-update or config retrieval, but modification directly on FortiManager will throw the following error.
This is a known issue in FortiManager v7.2.x and FortiManager v7.4.6 and below versions. This issue will be fixed in versions 7.4.7, and 7.6.3 of the FortiManager as part of issue ID 1101829.
The workaround for this issue is to make the changes on these tunnel interfaces using the CLI script in the FortiManager.
For example: The user wants to allow PING, HTTP & HTTPS access on the IPSec tunnel Spoke-HUB.
The following steps should be followed.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.