FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
stroia
Staff
Staff
Article Id 343504
Description

This article discusses a variety of issues that can be encountered when attempting to register a new device to FortiCloud using the FortiGate, including the 'FortiCloud registration failed' error message that can occur. Currently supported devices include the FortiGate, FortiAP, and FortiSwitch.

Scope FortiGate, FortiSwitch, FortiAP.
Solution

Please note that Fortinet devices need to be registered on FortiCloud prior to receiving technical support. 

 

Registering FortiGate. Refer to the following guides for registering devices through the FortiGate GUI for the three supported products:

Registering FortiSwitch 

Registering FortiAP 

 

If the registration attempt fails, then refer to the below list for common issues during the registration process and how they can be resolved:

 

Common error:  'FortiCloud registration failed'.

 

When trying to register a FortiAP/FortiSwitch through the FortiGate, the Register button is grayed out/inactive.

  • If the list of devices to be registered includes one or more inactive devices (i.e. red status; not connected to the FortiGate), then the Register button is expected to be grayed out.
    • Go back to the Managed FortiAP or Managed FortiSwitches page and remove the inactive entries from the selection, then retry the registration process. It is only possible to register devices using the FortiGate that are actively connected for management.

 

FAP Register Button Greyed Out.png

 

 To fix the issue, from the FortiGate side, it is possible to run the below command:

 

config system fortiguard
set fortiguard-anycast disable // set fortiguard fortinet
end

 

  • If the Registration field states 'Fetching registration information' for a long period, followed by 'Failed to fetch registration information', then the issue is related to network connectivity. 
  • Check if the FortiGate can resolve FortiGuard FQDNs using DNS, such as globalupdate.fortinet.net (anycast FortiGuard) or update.fortiguard.net (unicast FortiGuard). The following documentation lists the FQDNs and IP addresses associated with FortiCloud/FortiGuard services:

Anycast and unicast services

Technical Tip: IP address and port used for FortiCloud

 

  • If DNS is resolving correctly, then confirm that basic network connectivity to FortiGuard is also working (e.g. send ICMP pings to FortiGuard using 'exec ping <destination>').

 

exec ping fds1.fortinet.com
exe ping service.fortiguard.net
exe ping update.fortiguard.net
exe ping support.fortinet.com

 

FSW Register Button Greyed Out - Fetching Registration.png

 

FSW Register Button Greyed Out - Failed to fetch Registration.png

 

Example:

 
 
KB 1.jpg

Note:

In earlier versions, registering FortiAPs was not possible if they were managed by a non-management VDOM on the FortiGate (the register button would appear grayed out or unavailable).

 

  • This issue (#944465) was resolved as of v7.2.6, v7.4.2, and all later revisions

Refer to the following KB article for more information: Technical Tip: How to Resolve FortiCloud Registration Failures for FortiSwitch or FortiAP via FortiG...

 

After selecting the Register button and entering FortiCloud credentials, the registration process continues to fail.

  • If the device being registered is an F-series FortiAP (such as a FortiAP-231F) then check the installed FortiAP firmware version.
  • If the device is already registered to another FortiCloud account, then this can also cause registration to fail.
  • It has been observed in the past that the GUI method for FortiCloud registration may fail for FortiSwitches. Try performing the registration via the CLI to see if a license agreement needs to be acknowledged, as per the following KB article: Troubleshooting Tip: Error 'FortiCloud Registration Failed' when registering FortiSwitches from Fort...
  • If web traffic coming out from the FortiGate is sent to a third-party device/infrastructure for inspection or proxy, it could be necessary bypass the third party infrastructure sending the registration request directly to FortiCloud. For example, adding an SD-WAN rule on top of the rule steering the http/https traffic as explained here using the Internet Service called Fortinet-Fortiguard and configuring the FortiGate to steer FortiGuard traffic according to SD-WAN rules as explained here.

Note:

it is not possible to register new devices using the FortiGate GUI if the email address being used is associated with multiple FortiCloud accounts. In cases like these, it is necessary to register the device directly on the FortiCloud website.

 

  • There may be connectivity/communication issues between FortiGuard/FortiCloud and the FortiGate handling device registration. Check out the following KB article for guidance on troubleshooting FortiCloud connectivity issues, and reach out to Fortinet TAC if these troubleshooting steps do not identify/resolve the issue: Troubleshooting Tip: FortiCloud connection failure

 

Related articles:

Technical Tip: How to register FortiSwitch to FortiCloud from GUI

Troubleshooting Tip: FortiSwitch Registration Status is displayed as 'not registered' after FortiGat...