ssg5 - netscreenos removing vpn configs

How do you remove a VPN gateway from the netscreen os config when it says in use or bound to a tunnel interface.
- can't unset tunnel either because it says it's in use.
cisco20Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

DonConsolioCommented:
first remove the route(s) and/or policy/ies to the tunnel
0
deimarkCommented:
As above.

You have to basically reverse all the config used in the VPN bud, ie remove the route that points to the tunnel interface, then you can edit/delete the autokey IKE not to bind to the interface, then edit the/delete the IKE GW.

I know it van be a bit of a pain but it is there to make sure that you do not inadvertently delete aspects of the config that are used elsewhere.
0
cisco20Author Commented:
I was attempting to reso my vpn config but noticed my issue might only be my outgoing interface shows is e0/0 (ineternet) but the CLI shows e0/6 (my mngmnt int) am I looking at 2 different screens ?

See attached:
vpn.docx
0
What were the top attacks of Q1 2018?

The Threat Lab team analyzes data from WatchGuard’s Firebox Feed, internal and partner threat intelligence, and a research honeynet, to provide insightful analysis about the top threats on the Internet. Check out our Q1 2018 report for smart, practical security advice today!

deimarkCommented:
That part of the screen you show is if you wanted to create a new IKE GW bud, it does not relate to the selected GW at the top, ie "Gateway for 10.1.45.0/24"

To confirm this, run "get ike gw <name>  ie "Gateway for 10.1.45.0/24"

This should show the outgoing interface that will be used.
0
cisco20Author Commented:

Hmm - I posted my config I think I didn't ask the right question but when I entered the get ike it does show the remote firewall address but not sure where the ethernet 0/6 falls into the picture.

I posted my config for what I thought was going to be a simple setup 2 networks and 1 L2L connection to Headquarters, has been somewhat frustrating.

 If you can review config I would really appreciate it.
ssg5.txt
0
deimarkCommented:
In the config, the GW stuff is under :

set ike gateway "Gateway for 10.1.45.0/24" address 28.149.29.191 Main outgoing-
interface "ethernet0/6" preshare "zZeNo+PWNQHpghvflkjTVNVJnvLXcZxA==" proposal
 "pre-g2-3des-sha" "pre-g2-3des-md5" "pre-g2-des-sha" "pre-g2-des-md5"

So your outgoing interface is definitely e0/6
0
cisco20Author Commented:
No that's what I was trying to post. Ethernet 0/6 is only my management port I'm using to configure from WEBUI - My outgoing interface should be Ethernet 0/0 ( Internet connection ) right ?
0
deimarkCommented:
Sorry for the misunderstanding bud

Open up the web UI on the Ike GW page and clock on edit for you IKE GW

From there you can select the correct outgoing interface bud.

If this fails with an error on "cannot do this, its in use", then go to the autokey IKE VPN and remove the IKE GW from there or delete the whole phase 2 VPN.  You can then edit the IKE GW, then recreate the phase 2 bind to the IKE GW and the tunnel interface

Also as you want to use the route based VPN, then you will need to add a route for the remote network to go to the tunnel interface, this will then route all required traffic to the tunnel interface and the VPN binding will do the rest

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
cisco20Author Commented:
Thanks deimark for the info, once you do it a couple times it gets easier as is using the cli.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.