FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
stroia
Staff
Staff
Article Id 343504
Description

This article discusses a variety of issues that can be encountered when attempting to register a new device to FortiCloud using the FortiGate, including the 'FortiCloud registration failed' error message that can occur. Currently supported devices include the FortiGate, FortiAP, and FortiSwitch.

Scope FortiGate, FortiSwitch, FortiAP.
Solution

Fortinet devices must be registered to FortiCloud before technical support can be provided. With that in mind, refer to the following guides for performing device registration via the FortiGate GUI for the three supported products:

Registering FortiGate 

Registering FortiSwitch 

Registering FortiAP 

 

If the registration attempt fails then refer to the below list for common issues during the registration process and how they can be resolved:

 

When trying to register a FortiAP/FortiSwitch through the FortiGate, the Register button is grayed out/inactive.

  • If the list of devices to be registered includes one or more inactive devices (i.e. red status; not connected to the FortiGate), then the Register button is expected to be grayed out.
    • Go back to the Managed FortiAP or Managed FortiSwitches page and remove the inactive entries from the selection, then retry the registration process. It is only possible to register devices using the FortiGate that are actively connected for management.
  •  

FAP Register Button Greyed Out.png

 

  • If the Registration field states 'Fetching registration information' for a long period, followed by 'Failed to fetch registration information', then the issue is related to network connectivity.
    • Check if the FortiGate can resolve FortiGuard FQDNs using DNS, such as globalupdate.fortinet.net (anycast FortiGuard) or update.fortiguard.net (unicast FortiGuard). The following documentation lists the FQDNs and IP addresses associated with FortiCloud/FortiGuard services:

Anycast and unicast services

Technical Tip: IP address and port used for FortiCloud

    • If DNS is resolving correctly, then confirm that basic network connectivity to FortiGuard is also working (e.g. send ICMP pings to FortiGuard using 'exec ping <destination>').

 FSW Register Button Greyed Out - Fetching Registration.png

 

FSW Register Button Greyed Out - Failed to fetch Registration.png

 

Note:

In past versions, it was not possible to register FortiAPs if they were managed by a non-management VDOM on the FortiGate (the register button will be grayed out/unavailable).

 

After selecting the Register button and providing FortiCloud credentials, the registration still fails.

  • If the device being registered is an F-series FortiAP (such as a FortiAP-231F) then check the installed FortiAP firmware version.
  • If the device is already registered to another FortiCloud account, then this can also cause registration to fail.
  • It has been observed in the past that the GUI method for FortiCloud registration may fail for FortiSwitches. Try performing the registration via the CLI to see if a license agreement needs to be acknowledged, as per the following KB article: Troubleshooting Tip: Error 'FortiCloud Registration Failed' when registering FortiSwitches from Fort...
  • If web traffic coming out from the FortiGate is sent to a third-party device/infrastructure for inspection or proxy, it could be necessary bypass the third party infrastructure sending the registration request directly to FortiCloud. For example, adding an SD-WAN rule on top of the rule steering the http/https traffic as explained here using the Internet Service called Fortinet-Fortiguard and configuring the FortiGate to steer FortiGuard traffic according to SD-WAN rules as explained here.

Note:

it is not possible to register new devices using the FortiGate GUI if the email address being used is associated with multiple FortiCloud accounts. In cases like these, it is necessary to register the device directly on the FortiCloud website.

  • There may be connectivity/communication issues between FortiGuard/FortiCloud and the FortiGate handling device registration. Check out the following KB article for guidance on troubleshooting FortiCloud connectivity issues, and reach out to Fortinet TAC in the event that these troubleshooting steps do not identify/resolve the issue: Troubleshooting Tip: FortiCloud connection failure

 

Related articles:

Technical Tip: How to register FortiSwitch to FortiCloud from GUI

Troubleshooting Tip: FortiSwitch Registration Status is displayed as 'not registered' after FortiGat...