Description |
This article describes the issue when FortiManager pushes VPN config with the domain command, resulting in an error.
------- Start to retry -------- XXXXXXX1 config vdom
---> generating verification report <--- done generating verification report install failed |
Scope | FortiManager and FortiGate. |
Solution |
To ensure FortiManager can push the config, it is necessary to check the VPN IKE version. If the VPN config is using IKEv1, it is necessary to enable the domain as below:
config vpn ipsec phase1-interface
If the VPN config is using IKEv2, it is not possible to enable the config as IKEv2 does not support Unity extensions; therefore 'set domain' configuration is not available for FortiOS IKEv2.
Hence, if getting an error as above, consider using IKEv1 rather than IKEv2. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.