Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
martyyy
New Contributor III

Cannot add the aggregate vpn member

Hi There,

I tried to create a aggregate VPN between two fortigate node. FOS 7.0.14.
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/779544/ipsec-aggregate-for-redundancy-a...

there are two VPN tunnel established already. and I added one tunnel to the aggregate vpn successfully. But I cannot add another member into the group.

according to the guidance, I have to set aggregate-member enable. But I cannot do it, check the error message below.

 # next
Please enable phase2 auto-negotiate if ipsec-aggregate uses redundant algorithm.
This interface is currently in use.
object set operator error, -23, roll back the setting
Command fail. Return code 1

I tried to enable the phase 2 autonegotiation and delete the vpn tunnel and create a new one. the result is same.

I tried to disable the virtual interface but the result is same. Since there is traffic on the physical interface already. I cannot disable it. I don't want to break the service.

Appreciate your advice on how I can achieve it? TIA :) 

1 REPLY 1
AlexC-FTNT
Staff
Staff

"Please enable phase2 auto-negotiate if ipsec-aggregate uses redundant algorithm."

-- this will be displayed even when "set auto-negotiate enable" is set
"This interface is currently in use." 

-- this is probably the source of the problem - you need to make sure the interface is removed from all policies before adding it to aggregate


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors