FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Lovepreet_Dhillon
Article Id 272420
Description This article describes how to identify and troubleshoot a known-issue when attempting to register F-series FortiAPs (such as the FortiAP-231F, FortiAP-433F, etc.,) to FortiCloud using the FortiGate.
Solution

While registering the FortiAP from the FortiGate GUI, it fails with the error message: 'FortiCloud registration failed'.

 

Output of GUI attempt:

AP-edited.png

 

Registration attempt from the CLI:

 

diagnose debug application forticldd -1
diagnose debug enable
diagnose forticare direct-registration product-registration -N <FAP/FSW-serialnumber> -a <username> -p <password> -T "<country>" -R "reseller" -e 1

 

Example:

 

diagnose forticare direct-registration product-registration -N FP231******* -a testuser -p testpassword -T "CA" -R "Unknown" -e 1


Output:

 

Account info:
contract_number=[] account_id=[username] password=[***]<----- Password will be in plain text.
reseller_id=X reseller=[*******]
first_name=[] last_name=[] company=[]
title=[] address=[] city=[]
state=[] state_code=[] country_code=0
post_code=[] phone=[] fax=[]
industry=[] industry_id=0 orgsize=[] orgsize_id=0
version=0 SN=[FP***********] existing=1
Prepare to register product into this account.
Do you want to continue? (y/n)y

 

Cannot get signature from FortiSwitch/FortiAP FP433FT********
fds_request_registration_result:592: Failed to make request
Registration failed

 

In this scenario, the issue is caused by a known-issue on the F-series FortiAPs where they do not provide a digital signature to the FortiGate that is necessary for the FortiCloud registration process. For reference, the Issue ID is #767095.

 

Solution:

Known Issue #767095 has been resolved for F-series FortiAPs as of v6.4.8, v7.0.3, and all later revisions. Upgrade the FortiAP to a fixed version, then retry the registration process.

 

If the issue persists after upgrading the F-series FortiAP then there may be additional connectivity issues between the FortiGate performing the registration and FortiCloud. Refer to the following KB article for troubleshooting suggestions: Troubleshooting steps for FortiGate FortiCloud connection failure issues

 

Workaround:

If upgrading the F-Series FortiAPs is not an option, or if FortiGate-based registration is not working, then consider registering the FortiAP to FortiCloud directly (https://support.fortinet.com/) using the Serial Number or the Cloud Key located on the bottom of the unit.