Description | This article describes an issue where IP Address Threat Feed connection may fail with Error 'Server not reachable' when server-identity-check is enabled(basic or full). |
Scope | FortiGate v7.4.5, v7.4.6, v7.4.7, v7.4.8, v7.6.1, v7.6.2, v7.6.3. |
Solution |
When configuring an IP Address Threat Feed with server-identity-check set to basic or full, the feed connection fails with the error 'Server not reachable'. This occurs even if the CA certificate has been properly imported into the FortiGate. config system external-resource The following errors may appear in Forticron debug logs, which indicate an SSL certificate verification failure during the handshake, where the Forticron daemon is unable to validate the server’s certificate, resulting in a failed connection attempt: diagnose debug app forticron 0xf00 http_request_make()-2236: HTTP request: https GET /files-auth-need/Domain-auth.txt HTTP/1.1 __update_ext()-282: Updating EXT 'ip' with HTTP
These timelines for firmware release are estimates and may be subject to change. Workaround:
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.