cisco20
asked on
ssg5 - netscreenos removing vpn configs
How do you remove a VPN gateway from the netscreen os config when it says in use or bound to a tunnel interface.
- can't unset tunnel either because it says it's in use.
- can't unset tunnel either because it says it's in use.
first remove the route(s) and/or policy/ies to the tunnel
As above.
You have to basically reverse all the config used in the VPN bud, ie remove the route that points to the tunnel interface, then you can edit/delete the autokey IKE not to bind to the interface, then edit the/delete the IKE GW.
I know it van be a bit of a pain but it is there to make sure that you do not inadvertently delete aspects of the config that are used elsewhere.
You have to basically reverse all the config used in the VPN bud, ie remove the route that points to the tunnel interface, then you can edit/delete the autokey IKE not to bind to the interface, then edit the/delete the IKE GW.
I know it van be a bit of a pain but it is there to make sure that you do not inadvertently delete aspects of the config that are used elsewhere.
ASKER
I was attempting to reso my vpn config but noticed my issue might only be my outgoing interface shows is e0/0 (ineternet) but the CLI shows e0/6 (my mngmnt int) am I looking at 2 different screens ?
See attached:
vpn.docx
See attached:
vpn.docx
That part of the screen you show is if you wanted to create a new IKE GW bud, it does not relate to the selected GW at the top, ie "Gateway for 10.1.45.0/24"
To confirm this, run "get ike gw <name> ie "Gateway for 10.1.45.0/24"
This should show the outgoing interface that will be used.
To confirm this, run "get ike gw <name> ie "Gateway for 10.1.45.0/24"
This should show the outgoing interface that will be used.
ASKER
Hmm - I posted my config I think I didn't ask the right question but when I entered the get ike it does show the remote firewall address but not sure where the ethernet 0/6 falls into the picture.
I posted my config for what I thought was going to be a simple setup 2 networks and 1 L2L connection to Headquarters, has been somewhat frustrating.
If you can review config I would really appreciate it.
ssg5.txt
In the config, the GW stuff is under :
set ike gateway "Gateway for 10.1.45.0/24" address 28.149.29.191 Main outgoing-
interface "ethernet0/6" preshare "zZeNo+PWNQHpghvflkjTVNVJn vLXcZxA==" proposal
"pre-g2-3des-sha" "pre-g2-3des-md5" "pre-g2-des-sha" "pre-g2-des-md5"
So your outgoing interface is definitely e0/6
set ike gateway "Gateway for 10.1.45.0/24" address 28.149.29.191 Main outgoing-
interface "ethernet0/6" preshare "zZeNo+PWNQHpghvflkjTVNVJn
"pre-g2-3des-sha" "pre-g2-3des-md5" "pre-g2-des-sha" "pre-g2-des-md5"
So your outgoing interface is definitely e0/6
ASKER
No that's what I was trying to post. Ethernet 0/6 is only my management port I'm using to configure from WEBUI - My outgoing interface should be Ethernet 0/0 ( Internet connection ) right ?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks deimark for the info, once you do it a couple times it gets easier as is using the cli.