Skip to main content
kumarh
Staff
Staff
October 16, 2023

Technical Tip: FortiGate is showing inactive in FortiGate Cloud

  • October 16, 2023
  • 0 replies
  • 8884 views

Description

This article describes the scenario where FortiGate is showing inactive in the FortiGate Cloud.

Scope

FortiGate, FortiGate Cloud.

Solution

There could be an instance where FortiGate Cloud is already activated but shows as inactive in the FortiGate Cloud portal. 

mgmt-connectivity-inactive.png

 

Refer to the following for such a case:

  1. If the device is in an HA cluster, then it is expected that the secondary device will show as inactive. This is because the management tunnel can only be up for the primary device. If the device is not in an HA cluster or acting as the secondary device, the status should show as active.

  2. Check the Region where FortiGate Cloud is activated and verify that the portal is logged in to the same Region.

  3. Access the inactive FortiGate and verify connectivity to FortiGuard servers. Refer to this link to troubleshoot any issues with FortiGuard server reachability: Troubleshooting Tip: Unable to connect to FortiGuard servers.

  4. If FortiGuard servers are reachable, check the central-management settings if enabled:

 

config system central-management
    set type fortiguard
end

 

  1. Verify if there is an upstream device that could be blocking/inspecting traffic between the FortiGate and FortiGate Cloud. TCP/541 is used for management access. Refer to Technical Tip: IP address and port used for FortiCloud for the list of IP ranges and ports used by FortiGate Cloud.

To confirm if TCP 541 connection or other FortiCloud port between the FortiGate and FortiCloud is working, run packet capture in FortiGate while executing the following command:

 

fnsysctl killall fgfmd

 

To capture the relevant packets, run the CLI commands below or use the Packet Capture feature on the GUI.


CLI:

 

diagnose sniffer packet any 'port 541' 4 0 l


Or:

 

diagnose sniffer packet any 'port 541' 6 0 l

 

While collecting the above sniffer, check the connectivity with telnet to port 541.

diagnose test application forticldd 3 <--- Look for "Home log server" IP
execute telnet <Home log server IP from above command> 541

 

Collect debug log using the following commands:

 

diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application forticldd -1
diagnose debug enable
diagnose debug disable ---> Run this to stop the debug.
diagnose debug reset

 

  1. Another troubleshooting step that can be performed is to undeploy the FortiGate on FortiGate Cloud. From the FortiGate, log out of the FortiCloud account under Central Management and then log in again with the correct region. Refer to: Undeploying and redeploying a FortiGate.

 

FortiGate Cloud management connectivity should then show as active:

 

mgmt-connectivity-active.png

 

  1. To remove the inactive devices, go to Device and Provisioning -> Provisioning -> Choose the Firewalls and select Deprovision.


0bbb32e3.png


Related articles:

Technical Tip: FortiGate Cloud shows management tunnel down

Technical Tip: How to register/activate FortiGate Cloud from GUI and enable logging 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!