Skip to main content
himanshusince1989
Explorer
January 18, 2025
Solved

Time not syncing in Fortigate Firewall

  • January 18, 2025
  • 17 replies
  • 4607 views

I am using Fortigate 100G in HA and running Firmware 7.2.9. The issues I am facing is the interface is able to reach the NTP Server.

 

NTP Server : 192.168.1.10

FGT MGMT : 192.168.1.4

 

I have added a MGMT interface under dedicated management interface, which changes the MGMT interface in different vdom and getting removed in interface GUI. I want to get the time through management interface. I have configured NTP with below config

 

set ntpsync enable
set type custom
set syncinterval 1
config ntpserver
edit 1
set server "192.168.1.10"

once I try to add command "set source ip" it is showing below error "192.168.1.4 does not match any interface ip in vdom root." , as Management interface is removed from root vdom

 

So my question here is can we configured ntp on dedicated management interface vdom, or how can we achive.

 

Also I am referring to below docs in which we can set the interface under ntp server-->edit 1, but I cannot see it in my firewall.

 

https://docs.fortinet.com/document/fortiproxy/7.2.9/cli-reference/98620/config-system-ntp

 

fgt.PNG

Best answer by dingjerry_FTNT

Hi @himanshusince1989 ,

 

Actually, I remember that you want to use the mgmt interface as the OOB access to the Primary and Secondary FGTs.

 

So:

 

1) Disable the dedicated management interface:

config system dedicated-mgmt

    set status disable

end

2) Configure HA dedicated management interface:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Reserved-Management-Interface/ta-p/190132

 

Search for "For v6.4.x and newer versions" section.

 

3) Enable the "ha-direct" setting in the HA configuration.  

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Allow-NTP-synchronization-when-HA-cluster/ta-p/307206

 

You don't need to set the source-ip setting in the NTP configurations.

17 replies

funkylicious
SuperUser
SuperUser
January 18, 2025

Hi,

Take a look at this doc, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Access-NTP-Server-Connected-directly-with-Non/ta-p/295479 .

Also, the link you are using is for FortiProxy and not FortiGate, couple of differences in CLI but the same principle, https://docs.fortinet.com/document/fortigate/7.2.9/cli-reference/105110478 

"jack of all trades, master of none"
dingjerry_FTNT
Staff
Staff
January 18, 2025

Hi @funkylicious ,

 

@himanshusince1989 his scenario is different than the one in the doc link you provided.

 

Also, FGT and FortiProxy are very similar.  For NTP configuration, they are almost identical.

 

dingjerry_FTNT
Staff
Staff
January 18, 2025

Hi @himanshusince1989 ,

 

I assume that your dedicated management interface is mgmt.

Do you use it anywhere, i.e., the HA management interface?

 

If possible, please provide the FGT config.

 

himanshusince1989
Explorer
January 18, 2025

Hello, Thanks for yor response here.

You are assuming it Right, the mgmt interface is used for dedicated managemnt interface, which is now not visible under interface configuration, also I cannot see the MGMT interface in HA Management interface as well...

dingjerry_FTNT
Staff
Staff
January 18, 2025

Hi @himanshusince1989 ,

 

Please try the following to see whether it will work for you:

 

config system ntp

config ntpserver
edit 1

set interface-select-method specify

set interface mgmt

end

end

Then no need to specify the source-ip setting.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!