Skip to main content
Daryaya
Visitor III
December 21, 2020
Question

connectivity issues between FortiGate and FortiManager

  • December 21, 2020
  • 8 replies
  • 29706 views

# diagnose fdsm central-mgmt-status Connection status: Down Registration status: Unknown

 

I can ping FMG and I have already enabled FMG-access on the interface. 

 

is there a diagnose command that I could use to find out what the issue could be?

 

Thanks

    8 replies

    nicerobot_FTNT
    Staff
    Staff
    December 21, 2020

    Usual suspects: TCP ports. Make sure TCP541 is allowed if there are any devices in between with ACLs.

     

    See allowed inbound/outbound ports:

    https://docs.fortinet.com...cols/969270/open-ports

     

    Other issues: You might want to check to see if there are fragmentation issues with the connection between FGT and FGM. I've seen it cause issues in FortiGates hosted on DSL lines.

    Yurisk
    SuperUser
    SuperUser
    December 21, 2020

    Ping is a good start, but verify they exchange port 514 packets TCP freely diag sniffer packet any 'port 514' 4

    And if it seems like they do, run debug to see inside this port 514 communication:

    diag deb app fgfm 255 

    diag deb enable

     

    When it is ok you get Response 200, see example here https://yurisk.info/2020/07/19/fortigate-to-fortimanager-tunnel-connection-debug/ 

     

    yurisk.info - all things Fortinet blog, no ads
    Daryaya
    DaryayaAuthor
    Visitor III
    December 21, 2020

    I cant see port 514 packets are being exchanged with Fortianalyzer but not with Fortimanager

    sw2090
    SuperUser
    SuperUser
    December 9, 2021

    Im my case the soltion was easier. Just wanted to let you know if anyone stumbles across this.

    My FGT send Logs to (and communicate with) FMG via an IPSec tunnel that is established by the onsite FGT and the HQ FGT (Where FMG is). Routing and Policies all were fine. 

    Finally the packet sniffer showed me the problem: FortiAnalyzer on the FGT was simply using a completely wrong source interface (it was set to auto and detected that for whatever reason) so packets did go the right way to FMG competely but had a totally wrong source ip address due to that.

    This however did not affect the rest of FortiManager communication. Rolling out device config or policy package to the FGT or retrieving a config from the FGT worked fine all the time. It only affected the FortiAnalyzer. 

    Setting the FMG Source iP on cli did not help at all but once I manually set the correct source interface in the Log settings on the FGT it startet working like a charm...

     

    Sometimes the solution is easier than you think ;)

     

    cheers

    Sebastian

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!