Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
moumoumatt
New Contributor

Unable to install policy

FMG-VM64 v5.2.1

 

I'm trying to push the policy to a Fortigate 500D Cluster, Fortigate 5.2.1.

 

When I attempt to install the policy, I get the following error messages;

 

Policy console event 90% state:5 dvm_err:0 Prepare commit fail: vip overlap, Copy Package 'Name'   Policy console event Failed to commit policies to devdb   Any ideas what could be causing this?

 

Thanks.

8 REPLIES 8
moumoumatt
New Contributor

Problem solved - please ignore.

mnaccarato

moumoumatt wrote:

Problem solved - please ignore.

Can you please provide information on how to solve this, I'm facing the same problem.

 

Thank you!

scao_FTNT

 

Can you please provide information on how to solve this, I'm facing the same problem.

 

Thank you!

if policy validation fail, pls provide copy log and task details, also debug output if possible (diag debug application securityconsole 255)

 

if policy install fail, pls provide device install log

 

and pls provide FMG version, ADOM version and FGT version

 

Thanks

 

Simon

HaTiMuX
New Contributor III

The problem is a vip overlap. You can run "diag debug application securityconsole 255" to get more details.

 

SECURITY_CONSOLE: Installing firewall policy completed - 117 entries installed, 0 errors

SECURITY_CONSOLE: (1) [FGT(root)[copy] root] Initiate request to install to real device (reason:none)

SECURITY_CONSOLE: (1) [Write summary[preview] ] Prepare commit fail: vip overlap - VIP1, VIP2 (reason:none)

SECURITY_CONSOLE: (1) Compile time: 0 hours 0 minutes 0.628502 seconds.

SECURITY_CONSOLE: (1) Import time: 0 hours 0 minutes 0.016277 seconds.

SECURITY_CONSOLE: (1) Change dvm status time: 0 hours 0 minutes 0.000000 seconds.

SECURITY_CONSOLE: (1) Failed to commit policies to devdb

emnoc
Esteemed Contributor III

yes fortimanger has to  do a juniper like verification before the committal and it flags  and will fail a committal . It's a great  check imho.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
sw2090
Honored Contributor

It says "vip overlap". That looks like if you have an error in your portforward config (=vip). In this case obviously your port forwards overlap.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
mounirDDBE

Hello,

I ran into the same issue.

when i tried to push a policy via Fortimanager i got the following error:

 

Post vdom failed:

error :-999 - vip overlap - vip-SMTP1, vip-SMTP2

 

config of VIPs:

edit "vip-SMTP1"

               set service "HTTP"

                set extip 177.123.09.09

                set extintf "port2.75"

                set mappedip "192.168.1.272"

                next

edit "vip-SMTP2"

               set service "HTTPS"

               set extip 177.123.09.09

               set extintf "port2.75"

               set mappedip "192.168.1.272"

                next

 

Has anyone run into the same problem?

chall_FTNT

What you are trying to configure is not support in FortiOS.   For 2 VIPs to share the same external IP, they must have unique ports that are being forwarded.

Chris Hall
Fortinet Technical Support
Labels
Top Kudoed Authors