Skip to main content
renanrdrigues
Explorer II
June 16, 2026
Question

FortiManager "unset cert-probe-failure"

  • June 16, 2026
  • 2 replies
  • 88 views

We have FortiManager 7.6.7 and two FortiGates running FortiOS 7.4.11.

Under Security Profiles > SSL/SSH Inspection, we have an object named “SSL-EXCEPT” with set cert-probe-failure allow, and this profile is used in several firewall policies.

In FortiManager, the same object also has allow configured. However, whenever we make any change in FortiManager, it applies unset cert-probe-failure, which is preventing us from managing changes on these FortiGates through FortiManager.

How can we fix this?

2 replies

sjoshi
Staff
Staff
June 16, 2026

Hi ​@renanrdrigues 

What is the ADOM version on the FMG where FortiGate is added?

Since FortiGate is in v7.4 the default behavior of cert probe is block. Starting from 7.6 the default behavior is changed to allow and I believe this is causing the issue. Since the FMG is in 7.6 it is unset cert-probe-failure since default behavior itself is allow but once unset is done on FGT it will change it to block, hence I would suggest upgrading the FGT to 7.6 and test

Thanks, Salon
renanrdrigues
Explorer II
June 16, 2026

We cannot update the firmware at this time; we need to solve this with the current versions.

We currently have only one ADOM at version 7.6. If we create another ADOM at version 7.4, will this work? Or is there another way to resolve this?

sjoshi
Staff
Staff
June 16, 2026

yes, please create another ADOM of 7.4 and add the FGT on the new ADOM and that should fix the issue.

Thanks, Salon
New Member
June 25, 2026

Hi,

May I know if this has been fixed?

I encountered the same with FGT 7.4 and FortiManager 7.6
I tried to create an ADOM of 7.4 but still failed to deploy via the global database.

Thanks.

sjoshi
Staff
Staff
June 26, 2026

can you push it from the same adom instead of global database

Thanks, Salon