Description |
FortiAnalyzer certificate does not reflect correct serial number.
Earlier license files (from 2018 or earlier) for the FortiAnalyzer VMs did not include a certificate which reflected the actual serial number of the FortiAnalyzer.
This became a problem starting in FortiOS 6.2 when FortiGates starting checking the serial number when establishing a secure connection (OFTP) with the FortiAnalyzer.
Miglogd debug on the FortiGate might show an error like:
<9061> _check_oftp_certificate()-248: checking sn:FAZ-VM0000014XXX vs cert sn:FAZ-VM0000000001 <9061> _check_oftp_certificate()-258: The certificate CN (FAZ-VM0000000001) doesn't match the Serial numbers sent by 172.17.x.y |
Scope | |
Solution |
Download a new copy of the license file from the support portal and apply the new license file to your FortiAnalyzer VM.
This will update the certificate to match the serial number of this VM.
As a workaround, it is possible to disable checking of the serial number on the FortiGate: # config log fortianalyzer setting set certificate-verification disable end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.