Description |
This article describes one of the main reasons for changes made to the profile not syncing to the FortiExtender. |
Scope | FortiEdge Cloud. |
Solution |
FortiExtender is using profile VZ-5G-511F:
The administrator modifies the profile and removes protocols ping, HTTP, and SSH from the 'Allow Access' for the LTE1 interface:
The administrator syncs the profile changes to the FortiExtender, but the changes done on the profile don't sync to FortiExtender as it still shows protocols ping, HTT,P and SSH from the 'Allow Access' for the LTE1 interface:
Ideally, any changes made to the global profile (in this case, VZ-5G-511F) should sync to all FortiExtenders using the profile. However, changes are not syncing because override settings have been applied. This occurred when changes were made locally on the FortiExtender through FortiEdge Cloud at any point in the past, rather than pushing updates from the global profile.
Once override settings are applied, global profile changes no longer take effect on that FortiExtender.
To fix the issue, follow these steps:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.