Created on 02-17-2022 02:06 AM Edited on 02-29-2024 05:26 AM By Jean-Philippe_P
Description | This article describes how to resolve the below error while checking the connectivity with the analyzer: 'failed to get faz's status. invalid error number (0).(0)'.
This error is seen when a certificate is missing on FortiGate. |
Scope |
FortiGate and FortiAnalyzer. |
Solution |
Verify basic connectivity is fine by Ping, traceroute, and telnet.
However, while checking the connectivity with the analyzer by the below command, it gives the error:
exec log fortianalyzer test-connectivity
It is necessary to check the certificate on the FortiGate. Make sure the certificate with the CN='fortinet-ca2 is present.
If it is not present, try downloading the cert from the FortiAnalyzer and importing it on FortiGate.
Ensure it is added in external CA. Once it is added, reset the daemon on FortiAnalyzer and FortiGate by using the below command:
diag test app oftpd 99" <----- FortiAnalyzer.
Successful sending of logs:
FortiAnalyzer Host Name: FAZVM64
If none of the above suggestions help to establish connectivity between FortiGate-FortiAnalyzer, a few more steps that can help achieve the resolution of this problem are added below:
config log fortianalyzer setting set certificate-verification disable end
config system interface edit <name_of_interface> set mtu-override enable set mtu <value> <----- The value of the MTU can be reduced. end
As each infrastructure is unique from the other, there might be a chance that the same solution does not apply to every network. In this case, create a ticket with TAC support to troubleshoot the issue further. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.