FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jfelix09
Staff
Staff
Article Id 265174
Description

This article describes how to check if FortiGate fails to register a FortiAP/FortiSwitch that it is not under the same FortiCloud account.

Scope

FortiGate, FortiAP, FortiSwitch, FortiCloud.

Solution

Execute the following commands in the CLI:

 

diagnose debug application forticldd -1

diagnose debug enable

 

Try to Register one Device (FortiAP) under WiFi Controller -> Managed FortiAPs -> Register -> FortiCloud Account or via the CLI:

 

diagnose forticare direct-registration product-registration -N <FortiAP Serial Num.> -a <FortiCloud username> -p <password> -T <country> -R <reseller> -e 1

 

Stop the debugs:

 

diagnose debug reset

 

The end of the output will present a specific error when the FortiCloud account used to register the FortiAP/FortiSwitch is not the same as the account that the FortiGate is registered to. Note that the FortiGate serial number in this example has been redacted and replaced with '<FGTSERIALNUMBER>':

 

[omitted]

[105] fds_print_msg: SerialNumber=<FGTSERIALNUMBER>

[105] fds_print_msg: ContractItem=<CONTRACTNUMBER>

[omitted]

[113] fds_print_msg: ... [omitted] ... <Result>error</Result><Error>"<FGTSERIALNUMBER>" does not belong the specified account.</Error>

[omitted]

========Forticare response error========
"<FGTSERIALNUMBER>" does not belong the specified account.
[sic]
Registration failed

 

To resolve this issue and allow the FortiGate to register the FortiAP/FortiSwitch device, both devices must be registered to the same FortiCloud account.

It is possible to de-register the FortiGate from the original account and transfer it to the new account used for the FortiAP/FortiSwitch, though this does require direct access to both accounts (see: Technical Tip: FortiCloud account and FortiGate Cloud account transfer from GUI).

 

Alternatively, a ticket can be opened with Fortinet Customer Service to request the transfer of the FortiGate serial number from the original account to the new account. Note that this process requires the original account holder to approve the transfer request.

 

The FortiAP/FortiSwitch can be directly registered to FortiCloud via the Fortinet Support Site.