FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jiyong
Staff
Staff
Article Id 258594
Description This article describes the troubleshooting process when FortiToken activation failure.
Scope Fortigate.
Solution

Problem : 

 

internal_sever_error.png

 

Debugging :

 

diagnose debug application forticldd -1
diagnose debug enable

ftm_cfg_import_license[324]:import license 0000-0000-0000-0000-0000
is_trial_tokens_available[55]:No trial tokens are available.
ftm_fc_command[539]:forticare [globalftm.fortinet.net:443] unreachable


Debug logs that occur as above occur when communication with Fortiguard fails.

It is possible to check if the FortiGate communicates normally with Fortiguard below.

 

1) The 'Unable to connect to FortiGuard servers' error message can be seen in places:

System -> FortiGuard -> FortiGuard Updates.

 

2) Use following CLI commands:

 

exec ping service.fortiguard.net
exec ping update.fortiguard.net
exec ping guard.fortinet.net

 

3) Change FortiGuard settings:

 

config system fortiguard
    set fortiguard-anycast disable <-----
    set protocol udp <-----
    set port 8888 or 53 <-----

 

It is possible to make normal communication with Fortiguard, and receive them normally when 'import free trial tokens' are created.

 

internal_sever_error2.png

Related article:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-connect-to-FortiGuard-serv...

Contributors