FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
sjoshi
Staff
Staff
Article Id 406407
Description

 

This article describes an issue where RADIUS configurations on newly added FortiGate devices are removed after pushing a policy package from FortiManager.

 

Scope

 

FortiGate, FortiManager.

 

Solution

 

FortiGate is added in FortiManager, andthe  connection status is up:

 

1.PNG

 

Policy package assigned to the device:

 

1.PNG

 

Radius Config present on the FortiGate before policy package push:

 

1.PNG

 

The policy package is pushed by creating a new policy, and the installation preview logs clearly show that the RADIUS server configuration is being purged:

 

1.PNG

 

 

On the FortiGate, the RADIUS configuration is no longer visible as it has already been removed.

 

1.PNG

 

FortiManager purges the RADIUS server configuration because it is not referenced in any firewall policy. During a policy package installation, FortiManager is expected to remove radius configurations that have zero references.

 

The recommended approach is to create the RADIUS server configuration directly in FortiManager, include it in the relevant policy package, and then use the Install Wizard to deploy the package to the FortiGate.

 

1.PNG

 

1.PNG

 

When the policy package is pushed, FortiManager installs the RADIUS configuration, and this time the configuration is not purged.

 

1.PNG

 

After the policy package is installed, the RADIUS configuration is present on the FortiGate.

 

1.PNG

Contributors