Technical Tip: FortiManager fails to push 'device-identification enable' to FortiGate
| Description | This article describes an issue where, when using CLI Templates or Device Manager to enable device identification on an interface, the setting may fail to be pushed to the FortiGate, or FortiManager may incorrectly display the setting as disabled after installation. This issue is associated with Bug ID 1215090. |
| Scope | FortiManager v7.4.x (specifically v7.4.10 and earlier). |
| Solution | Symptoms:
Root cause: In FortiManager v7.4.10 and earlier, a logic dependency exists between the interface role and the device-identification feature. FortiManager skips pushing the device-identification command when the interface role is set to Undefined or WAN. This behavior is based on the assumption that device identification (MAC/OUI tracking) is only applicable to internal networks, such as LAN or DMZ.
Solution and workaround:
To resolve the issue without upgrading, change the interface role to LAN or DMZ.
Verification. After changing the interface role to LAN/DMZ:
|
