Skip to main content
gced91
New Member
April 7, 2016
Question

Fortimanager 5.2.4 Out of Sync with Fortigate after upgrade v5.2.4

  • April 7, 2016
  • 1 reply
  • 7800 views

Hello,

I have a fortimanager v5.2.4 with an ADOM in 5.0 I updated the firewall of this Adom as this v5.0.7, v5.0.11 OK sync OK connectivity OK, install policy OK. Having put the cluster of firewall in version 5.2.4, the status on the FMG passed it out of sync connectivity down (down tunnel). I thus updated the adom of the version 5.0 to the version 5.2, it changed nothing. I tried a refresh, a retrieve of the configuration, I always have the same error message: cannot communicate with remote device (down tunnel)

Nevertheless the network connectivity is always good (ping OK) I made a backup of the cluster of firewall to the imported on the fortimanager in the revision history. The status passed of out of sync in conflict, and the connectivity is always down.

Is there a solution to this problem without having to separate the cluster of the fortimanager? Thank you for your help

 

Cedric.

    1 reply

    scao_FTNT
    Staff
    Staff
    April 7, 2016

    Having put the cluster of firewall in version 5.2.4, the status on the FMG passed it out of sync connectivity down (down tunnel).

       -- you mean after FGT HA upgrade from 5.0.11 to 5.2.4 then tunnel is down?

     

    do you see any unexpected device listed in unregistered device list?

     

    Thanks

     

    Simon

    gced91
    gced91Author
    New Member
    April 7, 2016

    Hello,

    There is no device unregistered in adom root.

    I tried on the cluster fortigate to delete configuration central-management, then to add it again, it changed nothing.

    And from the fortimanager we manage also to connect ssh on the fortigate

    Regards

    Cedric.

    scao_FTNT
    Staff
    Staff
    April 7, 2016

    can you see FMG SN still in FGT "get sys central-management"?

     

    I tried on the cluster fortigate to delete configuration central-management, then to add it again, it changed nothing.

       -- so you mean FMG re-add FGT still fails?

     

    Thanks

     

    Simon