Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Floto
New Contributor II

"Enable IPsec Interface Mode"-Option missing

Hello everyone,

 

since Fortigate Firmware Version 7.6.0 (and above) the "Enable IPsec Interface Mode"-Option is missing when creating a new costum VPN Tunnel.

 

On Firmware Version 7.4.7 everything is fine. The checkbox is displayed and can be unchecked.New_VPN_on_7.4.7.PNG

When creating a new policy i can switch the Action to "IPsec" an choose the VPN tunnel:

Test_Pol_on_7.4.7.PNG

 

After upgrading the same Fortigate 40F to Version 7.6.0 the "Enable IPsec Interface Mode" is disappeared:

New_VPN_on_7.6.0.PNG

Without unchecking this option i can't choose the VPN tunnel in a new policy

Test_Pol_on_7.6.0.PNG

 

I already tried to deactivate the "policy-based IPsec VPN" Feature and active it again. It did not work. I also updated the Firmware to 7.6.1 and 7.6.2. On both versions the same problem.

 

Is this a bug or kinda a feature?

 

Best regards from Germany,

Florian

7 REPLIES 7
funkylicious
SuperUser
SuperUser

hi,

try from cli

 

config system settings

set gui-policy-based-ipsec enable

end

 

or from GUI , System > Feature Visibility > Policy based IPsec

"jack of all trades, master of none"
"jack of all trades, master of none"
Floto
New Contributor II

Hi funky,

 

thanks for your advice, unfortunately it didn't help.
I also tried to disable first and enable via cli.

dingjerry_FTNT

Hi @Floto ,

 

"I already tried to deactivate the "policy-based IPsec VPN" Feature and active it again"

 

How did you do it?

Regards,

Jerry
Floto

Hi dingjerry_FTNT,

 

i tried it via GUI and CLI, neither worked.

dingjerry_FTNT

Hi @Floto ,

 

As I mentioned, this should be a GUI bug.  Please raise a TAC ticket to request for a Bug report on this issue.

 

Meanwhile, you may create the policy-based IPSec VPN using the CLI commands  "config vpn ipsec phase1 | phase2]" for your phase1 & phase2 settings as a workaround. 

 

Once created, I believe that you can see it in GUI.

Regards,

Jerry
dingjerry_FTNT

Hi @Floto ,

 

I just did a quick test and think that this is a bug. 

 

You may raise a TAC ticket to request the TAC team to report a bug for you.

Regards,

Jerry
dingjerry_FTNT

@Floto ,

 

BTW, I think that this is a GUI bug.  Because I still see the CLI commands for policy-based IPSec VPN configurations.

Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors