FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
chall_FTNT
Staff
Staff
Article Id 200107

 

Description

This article describes the issue when the FortiAnalyzer certificate does not reflect the correct serial number.

Scope FortiAnalyzer.
Solution

Earlier license files (from 2018 or earlier) for the FortiAnalyzer VMs did not include a certificate that reflected the actual serial number of the FortiAnalyzer. 

 

FAZ Serial_Number_Warning.png

 

This became a problem starting in FortiOS 6.2 when FortiGates started checking the serial number when establishing a secure connection (OFTP) with the FortiAnalyzer.

 

Miglogd debug on the FortiGate might show an error like:

 

<9061> _check_oftp_certificate()-248: checking sn:FAZ-VM0000014XXX vs cert sn:FAZ-VM0000000001

<9061> _check_oftp_certificate()-258: The certificate CN (FAZ-VM0000000001) doesn't match the Serial numbers sent by 172.17.x.y

 

Download a new copy of the license file from the support portal and apply the new license file to your FortiAnalyzer VM. 

 

This will update the certificate to match the serial number of this VM.

 

As a workaround, it is possible to disable checking of the serial number on the FortiGate:

config log fortianalyzer setting

    set certificate-verification disable

end

 

Related article: 

Troubleshooting Tip: ‘FortiAnalyzer Queued logs due to wrong FAZ_VM Serial on FGT (FAZ-VM0000000001)...