Hello everyone,
we would like to distribute an IPSec tunnel configuration to other users, including external contractors, using the export/import of an XML file.
However, I’ve noticed that when a user imports such an XML file, it overwrites all previously configured tunnels.
Is there any way to create an XML file that allows users to import only one or several tunnels in a simple and user-friendly way, without replacing all existing ones?
Thank you very much in advance for your help!
Solved! Go to Solution.
in it, states about a setting that you can change
You can create a partial config by hand-editing the XML file. There's an option near the top you can change from 0 to 1 to designate it as a partial config (so it will merge instead of replace).
hi,
have a look at https://community.fortinet.com/t5/Support-Forum/Exporting-importing-a-single-VPN-connection/m-p/2115...
Hi,
thanks for the link, but I don’t think that topic provides a solution for importing a single VPN tunnel configuration without overwriting the existing ones.
in it, states about a setting that you can change
You can create a partial config by hand-editing the XML file. There's an option near the top you can change from 0 to 1 to designate it as a partial config (so it will merge instead of replace).
Hi,
thank you very much for pointing that out! I must have overlooked that line, and it’s exactly the piece of information I needed.
Hi,
FortiClient doesn’t support importing just one IPSec tunnel without replacing the whole configuration. The XML import always overwrites the existing file. If you want to distribute a single tunnel, the best options are to share the connection parameters so users can add it manually, or use FortiClient EMS to centrally deploy and manage VPN profiles.
Hi,
that’s quite unfortunate, as in my case I specifically need to distribute a configuration with a slightly modified XML — namely with the parameters <implied_SPDO>1</implied_SPDO> and <implied_SPDO_timeout>60</implied_SPDO_timeout>, which cannot be configured directly through the GUI.
I need to deliver this configuration to a larger number of external contractors, and asking each of them to manually edit or rebuild the XML file is not really practical.
If there was an easier way to set these parameters without manually editing or replacing the entire XML configuration, that would also be a perfectly acceptable solution.
| User | Count |
|---|---|
| 2712 | |
| 1416 | |
| 810 | |
| 733 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.