FortiManager cannot roll out Policy package it imported from FortiGate before
hi,
I have the following Constellation:
One FGT100D that was in FMG in an Adom for 5.4 and got Polices and all from it fine.
Now that FGT has been upgraded (following the supported upgrade path) to Firmware 6.02.
This worked fine. Now since I cannot rollout this FGT in the 5.4 adom anymore I have created a new adom for 6.0 and moved the FGT over there. Since the new adom is empty I imported the policy package from the FortiGate whdh cworked fine. Thus there were some conflicts betweet FGT and FMG even though I followed the uprade path. FMG prompted me to solve them which I did.
Now if I try to roll that policy package out to the FortiGate it keeps failing but the log shows no definite error.
Log shows just this:
Starting log (Run on device) Start installing xxxx1 $ config system ntp xxxx1 (ntp) $ set syncinterval 60 xxxx1 (ntp) $ end xxxx1 $ config vpn certificate ca xxxx1 (ca) $ edit "xxxxxxxxx_CA2" xxxx1 (xxxxx_CA2) $ set ca "-----BEGIN CERTIFICATE----- xxxx1 (xxxxx_CA2) $ -----END CERTIFICATE-----" xxxx1 (xxxxx_CA2) $ set range global xxxx1 (xxxxx_CA2) $ next xxxx1 (ca) $ end xxxx1 $ config firewall address xxxx1 (address) $ edit "all" xxxxx1 (all) $ set uuid 2cd4f0da-3a72-51e9-7adb-cded3a23c736 xxxxx1 (all) $ next xxxxx1 (address) $ end ---> generating verification report (global: system ntp:syncinterval) remote original: to be installed: 60 ------- Start to retry -------- xxxx1 $ config system ntp xxxx1 (ntp) $ set syncinterval 60 xxxx1 (ntp) $ end ---> generating verification report (global: system ntp:syncinterval) remote original: to be installed: 60 install failed
I also rechecked on system ntp:syncinverval. Gui on the FortiGate says it is set to 60.
Does anyone have any advice on this?
