Created on
‎11-27-2024
06:49 AM
Edited on
‎04-13-2025
10:53 PM
By
Jean-Philippe_P
Description | This article describes the impacts on the Security Fabric Topology when 'set configuration-sync' is set to local. |
Scope | FortiGate, FortiAnalyzer, and FortiManager. |
Solution |
In a network topology with a centralized FortiGate (root FortiGate) and downstream FortiGates (all devices are managed by FortiManager), a logging icon showing all is by design when Security Fabric is enabled.
If needed to centralize logging management through FortiManager, there is a setting to achieve it:
config system csf set configuration-sync local end
Below are the impacts on Security Fabric devices when 'set configuration-sync local' is configured on the downstream device:
On the downstream FortiGate:
On the FortiAnalyzer, the connection is UP, and the logs are stored:
On the FortiManager device, the device is UP and still can be managed by FortiManager:
Note: If this option 'configuration-sync' is not configured as 'local' on all downstream FortiGate, those Fabric Objects synchronized from the root FortiGate won't be modified.
In certain scenarios that the downstream non-root FortiGate receives the synchronized objects while the FortiManager is not aware of this change. In that case, FortiManager will attempt to delete these synchronized objects when pushing configuration to the FortiGate but will not be successful. The error will be as follows: ------- Start to retry -------- chewbacca-kvm62 $ config firewall address
This is actually the conflict between the Security Fabric synchronization and FortiManager as both attempt to push changes to non-root FortiGates. To avoid this scenario, it is necessary to configure 'configuration-sync' as 'local' while let the FortiManager manage the synchronization of all objects among all FortiGates in the same ADOM. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.