- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"Enable IPsec Interface Mode"-Option missing
Hello everyone,
since Fortigate Firmware Version 7.6.0 (and above) the "Enable IPsec Interface Mode"-Option is missing when creating a new costum VPN Tunnel.
On Firmware Version 7.4.7 everything is fine. The checkbox is displayed and can be unchecked.
When creating a new policy i can switch the Action to "IPsec" an choose the VPN tunnel:
After upgrading the same Fortigate 40F to Version 7.6.0 the "Enable IPsec Interface Mode" is disappeared:
Without unchecking this option i can't choose the VPN tunnel in a new policy
 
I already tried to deactivate the "policy-based IPsec VPN" Feature and active it again. It did not work. I also updated the Firmware to 7.6.1 and 7.6.2. On both versions the same problem.
Is this a bug or kinda a feature?
Best regards from Germany,
Florian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi,
try from cli
config system settings
set gui-policy-based-ipsec enable
end
or from GUI , System > Feature Visibility > Policy based IPsec
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi funky,
thanks for your advice, unfortunately it didn't help.
I also tried to disable first and enable via cli.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Floto ,
"I already tried to deactivate the "policy-based IPsec VPN" Feature and active it again"
How did you do it?
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi dingjerry_FTNT,
i tried it via GUI and CLI, neither worked.
Created on ‎02-18-2025 07:26 AM Edited on ‎02-18-2025 07:26 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Floto ,
As I mentioned, this should be a GUI bug. Please raise a TAC ticket to request for a Bug report on this issue.
Meanwhile, you may create the policy-based IPSec VPN using the CLI commands "config vpn ipsec phase1 | phase2]" for your phase1 & phase2 settings as a workaround.
Once created, I believe that you can see it in GUI.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Floto ,
I just did a quick test and think that this is a bug.
You may raise a TAC ticket to request the TAC team to report a bug for you.
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Floto ,
BTW, I think that this is a GUI bug. Because I still see the CLI commands for policy-based IPSec VPN configurations.
Jerry
