Skip to main content
mulbzh
Explorer
September 8, 2025
Question

need help to configure sandbox cloud

  • September 8, 2025
  • 5 replies
  • 908 views

Hello and sorry for my english,

 

I want to enable sanbox fortigate cloud, i have licence. When, i enable forti sandbox cloud, i have this message : unreachable or not authorized

 

I am witih multi VDOM, i enable sandbox on GLOBAL VDOM and this alert is on global VDOM. But when i active this functionnality on antivirus profile on external VDOM it seems working.

I found this command on documentation : 'diag test app forticldd 3' that say : 'Active APTServer status: unknown'

i can ping from global and root : service.fortiguard.net, update.fortiguard.net and guard.fortinet.net
i can ping APT server

 

i don't understand where it is blocking... maybe because it try to connect trough root VDOM because it is VDOM management

1 have 3 VDOM : external - root - internal

thanks for help

5 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
September 11, 2025

Hello mulbzh, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
September 12, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
mulbzh
mulbzhAuthor
Explorer
September 12, 2025

Ok thanks, i complete my post.

I have also trouble with 'central management', it can't connect i am sure about configuration. I configured to set external VDOM on interface for 'central management'.

And same as sanbox, when i ping to external IP use for sandbox or central management, i can see request in traffic log (i can see ping) but there no requests to this IP except ping. don't understand why

Jean-Philippe_P
Staff & Editor
Staff & Editor
September 15, 2025

Hello mulbzh,

 

I found this solution. Can you tell us if it helps, please?

 

To troubleshoot the issue of FortiSandbox Cloud showing as "unreachable or not authorized" in a multi-VDOM setup, follow these steps:

 

  1. Verify Licensing and Configuration:
    - Ensure that the FortiCloud premium license is active and that FortiSandbox Cloud entitlement is included in the contract.
    - Confirm that FortiGate is registered on the same account as the FortiCloud license.

  2. Check VDOM Configuration:
    - Since you are using a multi-VDOM setup, ensure that the correct VDOM is configured to handle the FortiSandbox Cloud traffic.
    - The management VDOM (Root VDOM) should have the correct routing and firewall policies to allow traffic to the Internet.

  3. Source IP Configuration:
    - Check the source IP configuration under `config system fortiguard` and `config log fortiguard setting`. Ensure that the source IP is correctly set to an IP that can reach the Internet.
    - If the source IP is set to an IP in the Root VDOM, ensure that the firewall policy in the external VDOM allows this IP to access the Internet.

  4. Routing and Firewall Policies:
    - Verify that the routing is correctly set up to allow traffic from the Root VDOM to the Internet.
    - Ensure that the firewall policies in the external VDOM allow traffic from the Root VDOM's source IP.

  5. Central Management Configuration:
    - For central management, ensure that the external VDOM is correctly configured to handle management traffic.
    - Verify that the firewall policies and routing in the external VDOM allow traffic to the central management servers.

  6. Diagnostics:
    - Use the command `diag test application forticldd 3` to check the status of the APT server. If the status is "unknown," it may indicate a connectivity issue.
    - Ensure that the APT server IPs are reachable from the command line using `exec ping` and `exec telnet`.

  7. Logs and Debugging:
    - Check the system event logs for any errors related to FortiSandbox or central management connectivity.
    - Use debugging commands like `diagnose debug application quarantine -1` and `diagnose debug enable` to gather more information.

 

By following these steps, you should be able to identify and resolve the connectivity issues with FortiSandbox Cloud and central management in your multi-VDOM setup.

Jean-Philippe - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!