FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kumarh
Staff
Staff
Article Id 279168
Description

This article describes the scenario where FortiGate is showing inactive in the FortiGate Cloud.

 

MicrosoftTeams-image (4).png

Scope FortiGate.
Solution
  1. If the device is in HA cluster, then it is expected that the secondary device will show inactive. Because the management tunnel can only be up for the primary device.
  2. If the device is not in an HA cluster or a secondary device, it will show as 'active'.

  3. Take the GUI access of the inactive FortiGate and verify whether the FortiGuard server is reachable. If not, make sure that the FortiGuard server is reachable from inactive G.


Note: Fortigate Cloud communicates with FortiGate when Management Connectivity is up. For Management connectivity, FortiGate should be able to communicate with FortiGuard Server.

 

  1. It is possible to try to change the FortiGuard configuration to make the FortiGuard server reachable or change the DNS Server if they are internal servers. It is also possible to refer following link to troubleshoot FortiGuard Server Reachability: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-Services-are-Unreachable/ta-p/1...
  2. Once the FortiGuard server is reachable, it is possible to verify the status of FortiGate in FortiGate Cloud. The device will show active.

 

MicrosoftTeams-image (3).png

Contributors