| Description | This article describes how to fix the issue when it is not possible to set the region in FortiGate Cloud under 'Cloud Sandbox Setting' |
| Scope | FortiGate. |
| Solution |
How to configure: Inline Scanning with FortiGuard AI-Based Sandbox Service
Note: FortiGate Cloud is chosen instead of FortiSandbox Cloud.
execute forticloud-sandbox region Failed Command fail. Return code 5
Troubleshooting steps:
diag test application forticldd 1 diag test application forticldd 2 diag test application forticldd 3
diagnose debug application forticldd -1
FG # diagnose test application forticldd 3
Debug zone info:
[294] fds_svr_default_on_established: Cloud-sandbox-controller has connected to ip=173.243.139.121:443 (output ommitted) [320] fds_https_recv: received the header from server: 173.243.139.121:443, [HTTP/1.0 503 Service Unavailable [206] __ssl_data_ctx_free: Done
FG (fortiguard) # set sandbox-region Global
Sandbox region can only be set by 'exec forticloud-sandbox region'.
node_check_object fail! for sandbox-region Global
value parse error before 'Global'
Command fail. Return code -39
config system fortiguard
set fortiguard-anycast disable set update-server-location eu set webfilter-cache disable set sdns-server-ip "208.91.112.220" "173.243.140.53" "210.7.96.53" set sdns-options include-question-section end Despite the FortiGate communicating successfully with FortiGuard servers, still, the region cannot be set.
Solution: Change the configuration of FortiGuard as below:
config system fortiguard
If the issue is not resolved after this change, share the debugs mentioned above with Technical Support to investigate further. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.