FortiEdgeCloud
Hosted cloud-based management platform for the Fortinet Secure LAN Edge (FortiSwitch and FortiAP), and FortiExtender 5G/LTE Gateways
AmmaIsha
Staff
Staff
Article Id 404254
Description

This article describes one of the main reasons for changes made to the profile not syncing to the FortiExtender.

Scope FortiEdge Cloud.
Solution

FortiExtender is using profile VZ-5G-511F:

 

AmmaIsha_0-1753901512099.png

 

The administrator modifies the profile and removes protocols ping, HTTP, and SSH from the 'Allow Access' for the LTE1 interface:

 

AmmaIsha_1-1753901512097.png

 

The administrator syncs the profile changes to the FortiExtender, but the changes done on the profile don't sync to FortiExtender as it still shows protocols ping, HTT,P and SSH from the 'Allow Access' for the LTE1 interface:

 

AmmaIsha_2-1753901512366.png

 

Ideally, any changes made to the global profile (in this case, VZ-5G-511F) should sync to all FortiExtenders using the profile. However, changes are not syncing because override settings have been applied. This occurred when changes were made locally on the FortiExtender through FortiEdge Cloud at any point in the past, rather than pushing updates from the global profile. 

 

Once override settings are applied, global profile changes no longer take effect on that FortiExtender.

 

To fix the issue, follow these steps:

  1. Create a new global profile.
  2. Swap the old global profile with the new one.
  3. Going forward, always make changes through the global profile instead of applying them locally on the FortiExtender.
Contributors