Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
omkam
New Contributor II

Unable to delete IPsec tunnel interface

I am trying to delete IPsec tunnel interface but not able to delete it.

 

I have checked the tunnels are configured with 0 reference. Need to delete the interface

Firewall is in HA mode but unable to delete from both the firewalls

 

MicrosoftTeams-image (10).png

Omkar
Omkar
11 REPLIES 11
garrychapple
New Contributor II

Hi Omkam, have you made sure there are no IP addresses referencing the VPN interface, under Policy Objects --> Addresses? Any addressing related to the interface will prevent you from removing it I believe. Also check there are no static routes still in place for that VPN, this caught me out a few times.

Garry D Chapple
Garry D Chapple
omkam
New Contributor II

I have already deleted address objects as well as routes but still unable to delete it.

Omkar
Omkar
garrychapple
New Contributor II

I see, well that should do it. What about deleting it via the cli. if you have tried that already them maybe this will help see the tunnel configurastion. get  vpn ipsec stats tunnel or diagnose vpn tunnel list name $VPN_NAME. Hope you get it sorted.

Garry D Chapple
Garry D Chapple
mpeddalla
Staff
Staff

Hello @omkam ,

 

Thank you for reaching Fortinet forum.

 

-Can you try to run the below command on CLI this will show all dependencies with name 

show full-config | grep r2sggn_tata2tik

-Did you try to restart Fortigate? if not what are the chances of considering it? 

-Can you also run the below debug and try deleting the tunnel paste output here 

di de application https -1

di de en 

 

di de disable ----- to stop logs 

 

-Also refer this below link:

Technical Tip: Unable to delete a tunnel interface - Fortinet Community

 

 

Best regards,

Manasa

omkam
New Contributor II

Hello Manasa,

I have restarted the FortiGate post which I am able to delete the VPN tunnel.

Can you please explain this behavior?

Omkar
Omkar
srajeswaran

It could be a bug , but unfortunately we don't have enough data to confirm .

534444

Unable to delete IPsec VPN tunnel phase-1 interface config even though we do not have any reference.

 

https://docs.fortinet.com/document/fortigate/6.2.1/fortios-release-notes/289806

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

omkam
New Contributor II

But this bug is in 6.2 version. But we are using 7.0.12 version.

Omkar
Omkar
srajeswaran

Yes, that was just a reference. You may have faced something similar, but we are not able to confirm.

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

maulishshah
Staff
Staff

Hi @omkam,

Can you please try to run the following command

 

diagnose sys cmdb refcnt show system.interface.name RS2GGN_TATA2TIK

 

if it will not provide you with any output then you might have to reboot the firewall. 

 

Even after rebooting the firewall, it won't work please download the backup config delete the interface from there and try to restore the config, it will delete but it will require downtime. 

Maulish Shah
Top Kudoed Authors