FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vbandha
Staff
Staff
Article Id 274918
Description This article describes how to troubleshoot if it is not possible to get remote access to FortiGate from FortiGate Cloud.
Scope FortiGate v7.0+.
Solution

If the FortiGate is down under FortiCloud as shown in the image below:

 

MicrosoftTeams-image (5).png

 

  • Check the Region in FortiCloud as shown below:

 

2.png

 

  • Then on FortiGate, navigate to Security Fabric -> Fabric Connectors, 'double-click' 'FortiManager', check if FortiGate Cloud is selected here, and log in with the FortiCloud account linked to the FortiGate.
  • For v7.2.4 and above, navigate to Security Fabric -> Fabric Connectors -> Central Management. Make sure FortiGate Cloud is selected and the Account is activated. 
  • If the Connection status is 'Not Managed', refer to this article: Technical Tip: FortiGate Central Management: FortiGate Cloud connection status 'Not Managed'.
  • If the connection status is 'Down', refer to this article: Technical Tip: FortiGate Cloud shows management tunnel down.
  • Only the primary device in an HA pair will show up/active and the secondary will be down/inactive since the management tunnel can only be initiated from the primary.
  • Make sure the region visible here, matches the region on FortiGate Cloud as shown below:

 

3.png

 

  • If the region is not the same, then select logout next to the ‘Account’ option and log back in. Make sure to choose the correct region when logging in.
  • After that, check the FortiGate Cloud again and the remote access should be accessible.
  • If the issue persists, refer to this article: Troubleshooting Tip: FortiCloud connection failure to collect debugs. 

 

Also, users may encounter issues when trying to access remote FortiGate devices through FortiCloud. Ensure that the user logs into FortiCloud using a Master Account. Refer to this document to assign FortiGate Cloud access for sub-accounts Technical Tip: Remote Access For Sub Users Through FortiGate Cloud.

 

Note:

If the Remote Access feature is greyed out and disabled and the FortiGate device is without the FortiGate Cloud subscription, the device may be on old firmware and may have reached the end of support (EOS). Consider upgrading the device to v7.0, v7.2, v7.4, v7.6. The following message will be seen:

 

FortiGate_Cloud_EOS.png

 

Related articles: 

Troubleshooting Tip: FortiCloud connection failure

Technical Tip: FortiGate Cloud shows management tunnel down

Technical Tip: FortiGate Central Management: FortiGate Cloud connection status 'Not Managed'