Description | This article describes why the tunnel type can no longer be changed after upgrading to v7.2.0 and later. |
Scope | FortiGate v7.2.0 and later. |
Solution |
On v7.2.0 and later, after 'tun_id' is generated, the IPSEC VPN phase 1 interface type cannot be altered. Routes intended for the IPsec tunnel are matched using 'Tun_ID'. As a result, it will not be possible to change the interface type from static remote gateway to DDNS or vice versa.
Output on firmware versions earlier than v7.2.0 can be changed without error:
On v7.2.0 and later the '-9999: -9999' error will appear when changing the tunnel type.
It will also show the same results on the GUI:
To fix this issue and change the tunnel type from the static gateway to dynamic DNS, recreate the VPN tunnel or create a new tunnel interface. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.