tried using the wizard to create VPn tunnels between two fortinet boxes.
start creating VPN on first box, selected site to site VPN, get to the part where you put in the local interface, local subnet, and remote subnet, and when I click on CREATE I get the error:
Unable to setup VPN: Empty values are not allowed.
where is the empty value? I have put information in at each step.
anyone ran into this before?
I can create one manually, just want to understand what the problem is.
Can't say much about the wizard, but you will get that if you try to use an address entity that is on a different interface than what you're trying to set up.
Example: You have "server" set up on internal, but you use it as the destination for a DMZ -> WANx policy.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Just got the same error. Opened the wizard again from the beginning and with the exact same steps in place it worked.
Now if the VPN itself would just work....!
Norris Carden
Fortinet XTreme Team USA (2015, 2016)
CISSP (2005), CISA (2007), NSE4 (2016)
cybernorris wrote:Just got the same error. Opened the wizard again from the beginning and with the exact same steps in place it worked.
Now if the VPN itself would just work....!
did this last week, got this same error, just opened the wizard again and configured the vpn and it just worked.
allwynmasc wrote:cybernorris wrote:Just got the same error. Opened the wizard again from the beginning and with the exact same steps in place it worked.
Now if the VPN itself would just work....!
did this last week, got this same error, just opened the wizard again and configured the vpn and it just worked.
Yup, after going backwards through the wizard a few times.
BTW, the VPN connected just fine. The laptop I was loaned to use for testing had a VM interface in the same subnet as the remote network, so it never sent any of the VPN traffic out the LAN port.
Norris Carden
Fortinet XTreme Team USA (2015, 2016)
CISSP (2005), CISA (2007), NSE4 (2016)
jamestiberius wrote:Use the dot-decimal notation instead of a net mask for the subnet maskUnable to setup VPN: Empty values are not allowed.
i.e. 255.255.255.0 instead of /24 etc.
I had the same problem, but when I created the VPN with another name it went through fine. I tried rebooting, but somehow it still remembers my first try. How could I erase the old tunnel? I can't see it in the tunnels menu or anywhere else but somewhere Fortigate remembers I had another tunnel with same name.
aaltojuk wrote:This seems to be a caching issue, open Chrome in Incognito mode and it stops reverting back to the old template you tried to create.I had the same problem, but when I created the VPN with another name it went through fine. I tried rebooting, but somehow it still remembers my first try. How could I erase the old tunnel? I can't see it in the tunnels menu or anywhere else but somewhere Fortigate remembers I had another tunnel with same name.
Finally solved this after letting Fortinet support take control of my computer.
Instead of using the Custom template, just choose Cisco, fill in the basics, then modify it to you needs.
Still run into this endlessly, even on 6.0; so frustrating if you build up a big phase 2 only to have no way to save any of it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1744 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.