Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zmag
New Contributor

How do I see where an address is being used??

I am trying to change the associated interface for a route based tunnel. In order to do this I have to delete the address and recreate it, but i am unable to do so because " cannot change interface binding! This address is being used." I dont see it in any group or policy. Is there a way to show where this is being used?
5 REPLIES 5
Carl_Wallmark
Valued Contributor

Hi, take a look at this: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD30620&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=11077329&stateId=0 0 11075817

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
ede_pfau
SuperUser
SuperUser

Hi, there are inofficial debug commands to show you the objects connected to it. But I recommend a different approach which works 100% of the time regardless of the FortiOS version: - download the current config, unencrypted - edit the entry you would like to change, in this case the interface IP - restore the config from this file The unit will reboot now. You should have a local serial connection to the console as config errors only show up there. Or you may use the command
diag debug config-error-log read
after the reboot from the CLI.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
zmag
New Contributor

Thanks, I should have included my build version, FG 620 4.0 MR2. I dont have the " diag sys checkused" command but I was able to edit the conf file and reload it. That' s a great fix for an offline box, but i wonder about downtime once in production. Good for now.
rwpatterson
Valued Contributor III

If you at least search the config, you' ll know where the associations are that need to be deleted, then do it old school.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
FortiRack_Eric
New Contributor III

the correct syntax is in this case: dia sys checkused firewall.address.name <address name> cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors