Created on
11-24-2023
08:47 AM
Edited on
11-12-2024
12:14 AM
By
Jean-Philippe_P
| Description |
This article describes how to prevent the following logs from appearing under Log & Report -> Events -> System Events:
Message: Attempted to join FortiCloud Log Description: FortiGate Cloud auto-join attempted
Message: FortiCloud service activation failed Log Description: FortiGate Cloud activation failed
|
| Scope | FortiGate v7 and later. |
| Solution |
A large number of 'Attempted to join FortiCloud' and 'FortiCloud service activation failed' messages may be seen under Log & Report -> Events -> System Events, or an event log may show the following messages:
date=2023-09-15 time=15:39:20 eventtime=1695455160407625415 tz="+0500" logid="0100022952" type="event" subtype="system" level="warning" vd="root" logdesc="FortiCloud activation failed" user="auto-join" action="login" msg="FortiCloud service activation failed" date=2023-09-15 time=15:39:19 eventtime=1695455159985569156 tz="+0500" logid="0100022949" type="event" subtype="system" level="notice" vd="root" logdesc="FortiCloud auto-join attempted" user="auto-join" action="login" msg="Attempted to join FortiCloud"
FortiOS v7.0.12, v7.2.5 and later:
date=2024-11-11 time=15:44:51 eventtime=1731368688840861580 tz="-0800" logid="0100022952" type="event" subtype="system" level="warning" vd="root" logdesc="FortiGate Cloud activation failed" user="auto-join" action="login" msg="FortiCloud service activation failed"
These messages indicate that FortiGate is configured to automatically join the remote logging and central-management service FortiGate Cloud, but the connection attempt was not successful.
Usually, this occurs because the device is not currently deployed in any FortiGate Cloud account, or the FortiGate is unable to contact the FortiGate Cloud service.
A device with auto-join enabled and central-management type ‘fortiguard’ will attempt to contact the FortiGate Cloud service when it boots and periodically thereafter. If FortiGate Cloud is not activated for the device, auto-join will fail. If FortiGate Cloud shows the device in 'FortiGate Cloud Deployed' but the auto-join events still show activation failed, likely the device is not able to connect to FortiGate Cloud.
config system fortiguard set source-ip <source ip> end
config log fortiguard setting set source-ip <source ip> end
If the device is not intended to use FortiGate Cloud:
config system fortiguard set auto-join-forticloud disable end
config system central-management set type none end
Once the device is joined to FortiGate Cloud successfully or auto-join is disabled, repetitive 'FortiCloud service activation failed' events will cease. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.