I am trying to delete IPsec tunnel interface but not able to delete it.
I have checked the tunnels are configured with 0 reference. Need to delete the interface
Firewall is in HA mode but unable to delete from both the firewalls
Hi Omkam, have you made sure there are no IP addresses referencing the VPN interface, under Policy Objects --> Addresses? Any addressing related to the interface will prevent you from removing it I believe. Also check there are no static routes still in place for that VPN, this caught me out a few times.
I have already deleted address objects as well as routes but still unable to delete it.
Created on 09-09-2023 12:26 AM Edited on 09-09-2023 12:26 AM
I see, well that should do it. What about deleting it via the cli. if you have tried that already them maybe this will help see the tunnel configurastion. get vpn ipsec stats tunnel or diagnose vpn tunnel list name $VPN_NAME. Hope you get it sorted.
Hello @omkam ,
Thank you for reaching Fortinet forum.
-Can you try to run the below command on CLI this will show all dependencies with name
show full-config | grep r2sggn_tata2tik
-Did you try to restart Fortigate? if not what are the chances of considering it?
-Can you also run the below debug and try deleting the tunnel paste output here
di de application https -1
di de en
di de disable ----- to stop logs
-Also refer this below link:
Technical Tip: Unable to delete a tunnel interface - Fortinet Community
Best regards,
Manasa
Hello Manasa,
I have restarted the FortiGate post which I am able to delete the VPN tunnel.
Can you please explain this behavior?
It could be a bug , but unfortunately we don't have enough data to confirm .
534444 |
Unable to delete IPsec VPN tunnel phase-1 interface config even though we do not have any reference. |
https://docs.fortinet.com/document/fortigate/6.2.1/fortios-release-notes/289806
But this bug is in 6.2 version. But we are using 7.0.12 version.
Yes, that was just a reference. You may have faced something similar, but we are not able to confirm.
Hi @omkam,
Can you please try to run the following command
diagnose sys cmdb refcnt show system.interface.name RS2GGN_TATA2TIK
if it will not provide you with any output then you might have to reboot the firewall.
Even after rebooting the firewall, it won't work please download the backup config delete the interface from there and try to restore the config, it will delete but it will require downtime.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.