Skip to main content
New Member
August 13, 2026
Question

Changing Address Object Associated-Interface settings breaks configuration

  • August 13, 2026
  • 3 replies
  • 74 views

I have a Fortigate FGT200F running 7.4.11.

It has a large number of physical connections that I’d like to rationalize down to VLAN interfaces on a trunk of multiple 10G lines. As such, the “names” of many of my networks are going to change from “portx” to “some-name-I-pick”. This has follow-on consequences for firewall objects and policies. Naturally, I don’t really want to delete all my policies and objects to get this done.

Many of the objects are tied to associated-interfaces. To ease the migration, I tried as a first step to reconfigure the objects by removing the “set associated-interface” command from each object in a backup of the config, then restoring the altered backup.

The firewall accepted the altered configuration and booted, however it permitted no traffic to traverse any policies while in this state. During this time it logged errors such as

action="connect" status="failure" reason="SSL accept failed" msg="40B84138E57F0000:error:0A000416:SSL routines:ssl3_read_bytes:ssl/tls alert certificate unknown:ssl/record/rec_layer_s3.c:911:SSL alert number 46

 

Reviewing the diff between the backup and altered backup confirmed that the only lines that diff sees as changed are the replacement of the “set associated-interface bwah” with blank lines.

Running a flow trace on the firewall in this state showed the firewall was recognizing the incoming traffic properly, associating it to the correct interface, finding the correct egress route, but then denying it on policy id 0 anyways. This was examined specifically on a traffic rule which did not include a molested object.

Reverting to the unmolested copy of the backup returned the firewall to service.

Can anyone tell me why making this apparently simple change completely broke the traffic handling?

Thank you for your time.

3 replies

sjoshi
Staff
Staff
August 13, 2026

Hi 

 

where do you see those logs

action="connect" status="failure" reason="SSL accept failed" msg="40B84138E57F0000:error:0A000416:SSL routines:ssl3_read_bytes:ssl/tls alert certificate unknown:ssl/record/rec_layer_s3.c:911:SSL alert number 46

 

So what was the fix, you restore the previous backup and it fix the issue?

Thanks, Salon
chellyoAuthor
New Member
August 13, 2026

The firewall was still able to transmit data from itself properly, so the logs were sent to the SIEM system we have set up.

Yes, re-installing the un-molested copy of the backup returned everything back to working the way it was.

chellyoAuthor
New Member
August 13, 2026

Update: I spent a bunch of time in the logging system and I think the SSL message above is a red herring (or a symptom of the wider problem). Looking at the messages logged during the startup, there’s no indication of any configuration error, and the SSL message actually only appears after I start trying to log into it over the network. So I don’t know what’s actually going on here. The boot messages are logged in the same sequence for the recovery boot that they do in the broken boot.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!