Fortinet black logo

Cookbook

Fixing the settings in the policy package

6.2.0
Copy Link
Copy Doc ID 2d0f1673-0a61-11ea-8977-00505692583a:632530
Download PDF

Fixing the settings in the policy package

After you have verified the configurations in the tunnel interfaces and dynamic mapping, fix the settings that were modified when you installed the configurations and policies. After you have fixed the configurations, ensure the devices are Up.

Tooltip

To complete this task, enable CLI Configurations in each device you want to configure.

To enable CLI configurations:
  1. Go to Device Manager > Device & Groups.
  2. In the tree menu, click Managed Devices, and then select a device from the list.
  3. In the toolbar, click Display Options.
  4. Click Customize.
  5. Enable CLI configurations.
To fix the configurations:
  1. Go to Device Manager > Device & Groups.
  2. In the tree menu, click Managed Devices, and then select a device from the list.
  3. In the toolbar, click CLI configuration.
  4. Go to vpn > ipsec > phase1-interface.
  5. Select a policy from the list, and click Edit.
    1. On the hub device, enable auto-discovery-forwarder and auto-discovery-sender, then configure the required parameters.
    2. On the branch devices, enable auto-discovery-reciever, and then configure the required parameters.
    3. Install the policy on the hub and branches.

To ensure the devices are up:
  1. Go to VPN Manager > Monitor.
  2. In the tree menu, click All VPN Communities.
  3. In the Status column, ensure the device status is Up.

Fixing the settings in the policy package

After you have verified the configurations in the tunnel interfaces and dynamic mapping, fix the settings that were modified when you installed the configurations and policies. After you have fixed the configurations, ensure the devices are Up.

Tooltip

To complete this task, enable CLI Configurations in each device you want to configure.

To enable CLI configurations:
  1. Go to Device Manager > Device & Groups.
  2. In the tree menu, click Managed Devices, and then select a device from the list.
  3. In the toolbar, click Display Options.
  4. Click Customize.
  5. Enable CLI configurations.
To fix the configurations:
  1. Go to Device Manager > Device & Groups.
  2. In the tree menu, click Managed Devices, and then select a device from the list.
  3. In the toolbar, click CLI configuration.
  4. Go to vpn > ipsec > phase1-interface.
  5. Select a policy from the list, and click Edit.
    1. On the hub device, enable auto-discovery-forwarder and auto-discovery-sender, then configure the required parameters.
    2. On the branch devices, enable auto-discovery-reciever, and then configure the required parameters.
    3. Install the policy on the hub and branches.

To ensure the devices are up:
  1. Go to VPN Manager > Monitor.
  2. In the tree menu, click All VPN Communities.
  3. In the Status column, ensure the device status is Up.