FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nradia_FTNT
Staff
Staff
Article Id 241314
Description

This article describes that after upgrading to 7.2.1 firmware on FortiManager, the following error messages can be seen :

 

system" level="alert" vd="root" logdesc="Admin login failed" sn="0" user="admin" ui="fgfm(x.x.x.x)" action="login" status="failed"

msg="Administrator admin login failed from fgfm(x.x.x.x) because of invalid password" (Where x.x.x.x is the IP address in question), and how to fix it.

Scope

FortiManager 6.X and 7.X, FortiGate 6.X and 7.X.

Solution

The device is shown as down in the FortiManager.

To resolve an invalid password issue when the Fortimanger authorizes the communication:

 

According to the error message, FortiGate's credentials were wrong on the FortiManager.

 

Firmware version is 7.2.1.

 

- The 'Edit' button was greyed out and it is not possible to change credentials in GUI:

 

nradia_FTNT_0-1672666304783.png

 

nradia_FTNT_1-1672666392096.png

 

- The FGFM connection was reinitiated on the FortiGate side by disabling (then select 'OK') and then enabling  and saving FortiManager Fabric Connector (Screenshot 3) in Security Fabric -> Fabric Connectors -> FortiManager:

 

nradia_FTNT_2-1672666447753.png

 

 

- The tunnel became in 'Up' state after, but the Authorization window on the FortiGate was unable to open the FortiMAnager authorization panel (destination unreachable).

 

- The FGFM credentials was changed manually from CLI in FortiManager by the following commands:

 

# execute device replace user <device_name> <username>

# execute device replace pw <device_name> <password>

 

- After re-authorizing the FortiGate, there are no more error messages related to passwords.

 

nradia_FTNT_3-1672666489592.png