Skip to main content
DAvidR7
New Member
March 31, 2026
Question

Lab with Fortianalyzer and Fortigate 7.4

  • March 31, 2026
  • 5 replies
  • 292 views

Hello,

 

I'm trying to do a lab with a trial version of fortianalizer (7.4.10) and fortigate (7.4.11) and I can't do the connection. When setting the IP of the analizer on the logging settings on the fortigate I get "no connection".

They are on the same network, already enable the fgfm on the interface. Can ping both analizer from fortigate and vice versa. 

 

The config that I have on Fortigate:

config log fortianalyzer setting
    set status enable
    set server "192.168.0.102"
    set certificate-verification disable
    set ssl-min-proto-version TLSv1

end
 
The config that I have on Analizer:
config system global
    set adom-status enable
    set enc-algorithm low
    set global-ssl-protocol tlsv1.0
    set hostname "FAZ-01"
    set oftp-ssl-protocol tlsv1.0
    set ssl-low-encryption enable
    set timezone 91
    set usg enable
end

 

Log from analizer:

T2211:oftps.c:1923 :192.168.0.203] SSL clienthello incoming on sockfd[20]
[T2211:oftps.c:1252 :192.168.0.203] dft-idx=0 inited=1.
[T2211:oftps.c:1758 :192.168.0.203] SSL socket[20] pid[1539] ssl[0x7f7618023030] SSL_new() success.
[T2211:oftps.c:302] before SSL initialization
[T2211:oftps.c:302] before SSL initialization
[T2211:oftps.c:1267] server_sni_cb(): sni='(nil)/n/a'
[T2211:oftps.c:1273] no SNI, switch to compatible SSL_CTX 1.
[T2211:oftps.c:323] SSL Alert write: fatal handshake failure
[T2211:oftps.c:333] error
[T2211:oftps.c:352] Error error:0A0000C1:SSL routines::no shared ciphe
[T2211:oftps.c:1957 :192.168.0.203] SSL accept failed. SSL_accept()=-1 SSL_get_error()=5
[T2211:oftps.c:2110 :192.168.0.203] SSL pid[1539] ssl[0x7f7618023030] shuting down sockfd[20] ip[192.168.0.203] connected[1]
[T2211:oftps.c:2123 :192.168.0.203] SSL_shutdown Error. SSL_get_error[1]
[T2211:oftps.c:2126] Error error:0A000197:SSL routines::shutdown while in init
[T2207:main.c:906 :192.168.0.203] Client connection closed. Reason 14(SSL setup failure)

 

Any tips?

5 replies

Anthony_E
Staff
Staff
March 31, 2026

Hi,

 

The advice i can provide is to update the both units with the exact same FortiOS.

Could you please try and let us know?

 

Regards,

Best Regards
DAvidR7
DAvidR7Author
New Member
March 31, 2026

Hello Anthony_E,

 

Thanks for the fast reply, they are on the lastest version from 7.4 branch.

 

Best Regards,

David

Anthony_E
Staff
Staff
March 31, 2026

Hi David,

 

Could you try to upgrade them with 7.6?

https://docs.fortinet.com/product/fortigate/7.6

https://docs.fortinet.com/product/fortianalyzer/7.6

 

 

Regards,

Best Regards
farhanahmed
Staff
Staff
April 1, 2026

@DAvidR7  

I see from the log that FAZ received the client hello but does not have the SNI in it: 

server_sni_cb(): sni='(nil)/n/a'

DAvidR7
DAvidR7Author
New Member
May 11, 2026

Hello  farhanahmed,

I reseted the lab, fortigate version 7.6.11 and analyzer 7.6.6. All default settings and trial license.

I have the same issue, and with or without set reliable en.

[T10244:oftps.c:2189 :192.168.0.102] SSL accept failed. SSL_accept()=-1 SSL_get_error()=5
[T10244:oftps.c:2342 :192.168.0.102] SSL pid[10221] ssl[0x7f0af0020e20] shuting down sockfd[21] ip[192.168.0.102] connected[1]
[T10244:oftps.c:2355 :192.168.0.102] SSL_shutdown Error. SSL_get_error[1]
[T10244:oftps.c:2358] Error error:0A000197:SSL routines::shutdown while in init
[T10239:main.c:937 :192.168.0.102] Client connection closed. Reason 14(SSL setup failure)
[T10243:oftps.c:2148 :192.168.0.102] SSL clienthello incoming on sockfd[21]
[T10243:oftps.c:1436 :192.168.0.102] dft-idx=0 inited=1.
[T10243:oftps.c:1927 :192.168.0.102] SSL socket[21] pid[10221] ssl[0x7f0afc02a8e0] SSL_new() success.
[T10243:oftps.c:329] before SSL initialization
[T10243:oftps.c:329] before SSL initialization
[T10243:oftps.c:350] SSL Alert write: fatal protocol version
[T10243:oftps.c:360] error
[T10243:oftps.c:379] Error error:0A000102:SSL routines::unsupported protocol
[T10243:oftps.c:2189 :192.168.0.102] SSL accept failed. SSL_accept()=-1 SSL_get_error()=5
[T10243:oftps.c:2342 :192.168.0.102] SSL pid[10221] ssl[0x7f0afc02a8e0] shuting down sockfd[21] ip[192.168.0.102] connected[1]
[T10243:oftps.c:2355 :192.168.0.102] SSL_shutdown Error. SSL_get_error[1]
[T10243:oftps.c:2358] Error error:0A000197:SSL routines::shutdown while in init
[T10238:main.c:937 :192.168.0.102] Client connection closed. Reason 14(SSL setup failure)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.