FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
tana
Staff
Staff
Article Id 196631

Description

 

This article describes that iIn some case(s), it may be necessary to reset a VPN tunnel so the SA sessions will be cleared.
It is possible to 'flush' a tunnel so the SAs can be re-established.
 
Scope
 
FortiGate.


Solution

 

diagnose vpn tunnel flush <my-phase1-name>

 
or use the below command as well:
 
diagnose vpn ike gateway clear name <my-phase1-name>
 
Note.

Replace 'my-phase1-name' with the name of the Phase1 part of the VPN tunnel. If the name is NOT specified, all tunnels will be 'flushed'.

Some FortiOS version the command 'diagnose vpn tunnel flush' might not flush the tunnel. Use 'diagnose vpn ike gateway clear name <my-phase1-name>' instead. Check the output when both commands are used on v7.4.3. 

 

diag vpn ike gateway clear name.png

 

Related article:

Technical Note: How to bring down the shortcut VPN tunnel created by Auto-Discovery VPN (ADVPN)