Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Parents
  • We have just changed our site to site IPsec VPNs (Tunnel Interface) to use specified local and remote subnets (instead of 'any' and static routes). There is a small bug in that you can't rename the xfrm interfaces in the Network, Interfaces section. Gives the error message "You must configure at least one IP family" (which you can't do if you use specified local and remote subnets).

Reply
  • We have just changed our site to site IPsec VPNs (Tunnel Interface) to use specified local and remote subnets (instead of 'any' and static routes). There is a small bug in that you can't rename the xfrm interfaces in the Network, Interfaces section. Gives the error message "You must configure at least one IP family" (which you can't do if you use specified local and remote subnets).

Children
  • Did you change the IP Family in the IPsec tunnel? 

    __________________________________________________________________________________________________________________

  • Yes, you have to change it (in my case to IPv4) to be able to specify local and remote subnets.

    In the Network, Interfaces section, it tells you that you 'can't assign and IP address or routes to the interface'. That's correct but it also won't let you save the name change - "You must configure at least one IP family" - which you aren't allowed to do because "The XFRM interface is configured for specific local and remote subnets"!