Skip to main content
RBA
Staff
Staff
July 24, 2025

Technical Tip: Configuration state shows 'failed' while adding specific source countries

  • July 24, 2025
  • 0 replies
  • 207 views
Description This article provides an example to collect the necessary logs while configuration state shows failed for specific source countries under GeoFencing -> Regional Compliance.
Scope FortiSASE.
Solution

The issue would not be observed for all the countries. As an illustration, India as a source works fine however, Saudi Arabia shows the state as failed.

 

KSA_1.png

 

Install the Fortinet Support Tool extension as described in this KB article: Troubleshooting Tip: Collect GUI slowness and errors debugs via Fortinet Support Tool

 

Start the capture. Navigate to GeoFencing -> Regional Compliance and create the rule and reproduce the issue.

 

Fortinet-support-tools.png

 

Stop the captures once the issue is reproduced. The output file can be analyzed by loading the capture into the same extension by clicking on 'View existing capture'.

 

KSA_2.png

 

Navigate to Logs and select network Requests from the dropdown. select the GET request for: '/api/v1/security/sites/network/vpn_settings/fail_over_connections'.

 

KSA_3.png

 

Here, the config status can be viewed as failed

 

"config_status": "failed",
"a_record_id": null,
"deprecated": false,
"deprecated_v2": null,
"deprecated_region": null,
"additional_parameters": null

 

The reason for failure here is an issue related to DNS, which can be resolved by opening a support ticket with the GUI capture.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.