Skip to main content
Dan_Eng52
Explorer III
September 26, 2024
Question

FortiSwitch not Applying Configuration from FortiGate

  • September 26, 2024
  • 5 replies
  • 5017 views

Hi all, 

 

I am having issues syncing configuration to my managed FortiSwitch devices. Currently, I am running FortiOS 7.4.4 and FortiSwitchOS 7.4.2 and when issuing a execute switch-controller get-sync-status all I get the below status, MAC and REST API login error. 

 

FGT01 # execute switch-controller get-sync-status all
Managed-devices in current vdom root:

FortiLink interface : fortilink
SWITCH-ID (SERIAL) STATUS CONFIG MAC-SYNC HTTP-UPGRADE
Switch-A (SN12345667785654) Up Error Error -

[1]
command: https://10.10.10.1:443/api/v2/login
payload:
result : REST API login failed with error 60
Switch-B (SN41233434554657) Up Error Error -

[1]
command: https://10.10.10.2:443/api/v2/login
payload:
result : REST API login failed with error 60

 

I have another setup in a different location running the same version except the only different is that the tunnel-mode is set to compatible and I have no configuration sync issues: 


config switch-controller system     set tunnel-mode compatible end       

 

Investigating this it seems as though this is a fix that people have identified and an issue that is apparent in the FortiOS 7.4.4 and 7.4.5 versions. It is also documented that this is still not fixed in FortiOS 7.4.5 and want to know if this is has been resolved in 7.6.0? I will likely be upgrading to this version because the below issue has been resolved:

 

On the System > Firmware & Registration page, after upgrading the version 7.4.2, the FortiSwitch shows as not registered in the GUI.

Regards, 

Dan.

 

5 replies

Dan_Eng52
Dan_Eng52Author
Explorer III
September 26, 2024

@Anthony_E Is this something you can perhaps confirm in the backend? I've reviewed FortiOS release notes for 7.6.0 but cannot see the above resolved so will need to leave the tunnel mode set to compatible. 

Regards, 

Dan. 

Anthony_E
Staff
Staff
September 26, 2024

Hi Dan,

 

Let me find someone who can help :)!

 

Regards,

Best Regards
Anthony_E
Staff
Staff
September 26, 2024

@sachitdas_FTNT, you are the FSW expert :)!

Do you have an idea?

Best Regards
sachitdas_FTNT
Staff
Staff
September 26, 2024
RickCogley
Explorer
September 28, 2024

This happened to me when I followed the recommendation in "security rating", setting tunnel mode to `strict`. Reverting to `compatible` fixed the sync problem for me, running 7.4.5 on the fortigates and 7.4.3 on the fortiswitches. 

RickCogley
Explorer
September 28, 2024

Huh, interesting. Another problem I found after I applied various improvements from the security ratings was, devices went blank in the port list. Anecdotal I guess, but now they are back... I wonder if this strict versus compatible setting also impacts this?