Skip to main content
Rafaelkkksalgado
New Member
September 23, 2024
Question

Fortimanager VM connect fortigate error

  • September 23, 2024
  • 7 replies
  • 21682 views

Good afternoon!

Friends, I'm using two images in EVE-NG, one from fortigate v7.0.15 and the other from fortimanager v7.6.0 build3340 (Feature).

I connected to both with the forticloud trial.

I configured a management interface on both and another Lan interface (where I would connect between them)

They both ping each other and fortigate closes telnet on port 541.


I activated FMG-Access on the lan port on the fortigate where I will communicate with the fortimanager.

I reduced encryption in fortimanager, set low and also activated fgfm-ssl-protocol sslv3.


I put the Fortimanager IP in the fabric connector > Fortimanager, on premises.


I always get this error:

The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager. Could not connect to the FortiManager to retrieve its serial number.

I tried everything possible, I have no more ideas. Please Help .image.pngimage.png

7 replies

adambomb1219
SuperUser
SuperUser
September 23, 2024

Why 7.0?  

Rafaelkkksalgado
New Member
September 23, 2024
Because I read about this version having fewer limitations as it is a trial. :,( . But I tried with newer versions too. I had the same result.
Hsharma
Staff
Staff
September 23, 2024

Hello ,

 

Please check the compatibility tool between Fortigate and Fortimanager . They seems to be non-compatible version. Kindly try to make the version compatible to each other and see that helps.

 

Please use the link to check the compatibility between fortigate and fortimanager .

 

https://docs.fortinet.com/compatibility-tool/fortimanager

 

Thank You

 

Rafaelkkksalgado
New Member
September 23, 2024

You right! But i already test compatible versions. But i find the solution now. Need to run this on Fortimanager: config sys global
set fgfm-peercert-withoutsn enable


Thanks all.

ametkola
Staff
Staff
September 24, 2024

Hello  @Rafaelkkksalgado

 

The article below explains further regarding the error and the solution in this case:

https://community.fortinet.com/t5/FortiManager/Technical-Tip-Setup-custom-certificate-for-FGFM-protocol/ta-p/242730

 

Regards,

 

 

M_Tahir
New Member
March 24, 2025

https://community.fortinet.com/t5/FortiManager/Technical-Tip-Setup-custom-certificate-for-FGFM-protocol/ta-p/242730

I have followed this article so I am stuck on importing certificate in Fortinet firewall kindly anybody assists me it's urgent.

error is 
incorrect the certificate file formate CA/LOCAL/REMOTE  like this

 

daxrob
Staff
Staff
October 1, 2025

Hi,

it is much simpler. As stated in this RN: 
https://docs.fortinet.com/document/fortimanager/7.4.7/release-notes/519207#:~:text=Adding%20VM%20devices%20to%20FortiManager
You have just to enable the FGT-VM on FortiManager:

config system global

set fgfm-allow-vm enable

end

Then everything will works as usual.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.