Troubleshooting Tip: Policy installation fails
| Description | This article describes a scenario where policy installation fails on some devices due to a default CLI syntax difference between FortiManager and FortiGates. |
| Scope | FortiManager and FortiGate. |
| Solution | After Fortimanager or FortiGate firmware upgrade, it might happen when the default CLI syntax doesnt match between FortiManager and FortiGate. In such a scenario, most certainly it doesnt affect Installation and the desired configuration change will be pushed from FortiManager to FortiGate. However administrator may see in the installation log verification report fails. The log explains that the default value on the FortiGate side ('remote original:') does not match the default value on the FortiManager side ('to be installed:').
The example below describes one of the known software issues, and it is resolved in the latest FortiManager firmware versions.
This particular FortiGate 30G model does not support SSL VPN. The following can be seen in the verification report on the FortiManager:
---> generating verification report
If an upgrade is not possible at the moment to the latest firmware version, the following workaround can be applied:
config system dm
It is advised to re-enable policy verification after installing the new firmware version that fixes the CLI syntax mismatch. |
