Tunnel interface configuration:
FGT(HUB1)# show config system interface edit "HUB1" set vdom "root" set ip 10.10.3.1 255.255.255.255 set allowaccess ping fgfm <----- FortiManager access should be enabled. set type tunnel set remote-ip 10.10.3.253 255.255.255.0 set snmp-index 15 set interface "port1" next end
FortiGate default central management configuration:
FGT (central-management) # show full config system central-management set mode normal set type fortiguard <----- Change this value to 'fortimanager' but do not save the change. set schedule-config-restore enable set schedule-script-restore enable set allow-push-configuration enable set allow-push-firmware enable set allow-remote-firmware-upgrade enable set allow-monitor enable set local-cert '' set vdom "root" set fmg-update-port 8890 set enc-algorithm high end
FGT (central-management) # set type fortimanager
FGT (central-management) # show full config system central-management set mode normal set type fortimanager set schedule-config-restore enable set schedule-script-restore enable set allow-push-configuration enable set allow-push-firmware enable set allow-remote-firmware-upgrade enable set allow-monitor enable unset serial-number unset fmg set fmg-source-ip 0.0.0.0 <----- The fmg -source-ip must be present on FortiGate and allowed within the IPsec set fmg-source-ip6 :: set local-cert '' unset ca-cert set vdom "root" set fmg-update-port 8890 set include-default-servers enable set enc-algorithm high set interface-select-method auto <----- Change this to 'specify' and it will unlock the interface field.
end
config system central-management set type fortimanager
set serial-number XXXXXXXXX <----- Provide FortiManager Serial Number. set fmg-source-ip 10.10.3.1 set interface-select-method specify set interface "HUB1" end
To verify the connection status:
diagnose fdsm central-mgmt-status Connection status: Up Registration status: Registered Serial: FGVM02TMXXXXXXXX
Related articles:
Technical Tip: Routing Challenges When Accessing FortiManager using IPSec Tunnel
Technical Tip: Functionality of 'set interface-select-method' for local-traffic with SD-WAN |