FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
jasonhong
Staff & Editor
Staff & Editor
Article Id 227470
Description

 

This article describes how to resolve the FortiAnalyzer map server connectivity issue.

 

Scope

 

FortiAnalyzer.

 

Solution

 

  1. When editing a device in FortiAnalyzer Device Manager, an error message 'Cannot connect to the map server' will be shown if FortiAnalyzer does not have proper Internet access and DNS resolution.

 

editdevice.png

 

  1. FortiAnalyzer requires external connectivity over TCP port 443 (HTTPS) along with proper DNS resolution in order to communicate with the map server domain.

    The user may use the Google DNS temporarily and verify if FortiAnalyzer can resolve the DNS.

     

    config system dns

        set primary 8.8.8.8

    end

     

     

  2. Once Fortianalyzer has proper Internet access as well as the correct DNS resolution, validate it by pinging the map server domain.

     

    execute ping mapserver.fortinet.com
    execute ping maps.googleapis.com

     

  3. Once FortiAnalyzer can successfully resolve the map server domain, the device location should be updated accordingly.

    If the device location is yet to be updated, the user may reboot the FortiAnalyzer and verify the result again.

     

    mapfix.png

     

    Troubleshooting info:

     


    execute tac report

    diagnose system geoip info
    diagnose system geoip-city info
    diagnose system geoip-city ip 8.8.8.8