FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
dgrigoriciuc
Staff
Staff
Article Id 191873

Description

 

This article describes how FortiManager can indicate whether the FortiGate's configuration file has been modified and is no longer synchronized with the FortiManager device configuration. It can also indicate other various conditions, as indicated below.
 
Scope
 
All supported versions of FortiManager.
 
Solution

dev_status.png
 
Within the Device Manager, the following 'Config Status' conditions are displayed:
 
  • Synchronized cond: OK in CLI. The latest Revision History entry (whether an Install or Retrieve) is aligned with the config on the FortiGate.
    • get sys mgmt csum collected after the final Revision History entry, matches what is on the FortiGate.
    • The Refresh Device button is now only available in the right-click context menu of the device table.
    • It still performs a real-time get sys mgmt csum validation.
  • Modified: configuration has changed on the device database and is pending an Install or Retrieve to put it back in Synchronised status.
  • Auto-Updated: configuration was changed directly on the FortiGate, and the changes were automatically updated to the device database.
  • Out of sync: The latest Revision, whether an Install or a retrieval. does not match the configuration on the FortiGate.
    A change was made directly on the FortiGate, which has not been retrieved.
  • Unknown: FortiManager is unable to determine the synchronization status because the FortiGate is not reachable or a non-system template is modified.
  • Conflict: The managed device returned an error during the last Install, or the Install Verification has failed.

 

Within Device Manager, the following "Policy Package Status" conditions are displayed:

  • Synchronized: On the last Install, the Policy Package and related/used ADOM objects were successfully copied to the Device database.
  • Imported: Policies and objects were imported from the Device database to the ADOM database, and the associated Package was not modified or installed since then.
  • Never installed: No Policy Package is assigned to the device, or the device was added to a Policy Package, but was not installed yet.
  • Modified: The Policy Package assigned to the device or an object associated with this Policy Package was modified.
  • Conflict: Policy or associated ADOM object was modified at Device DB. Usually, the object was modified directly on the FortiGate and auto-updated.
  • Unknown: Config Retrieve, or Auto-Retrieve was performed.

 

Use the following setting:

 

config system dm
    set force-remote-diff enable
end

 

Then always use the 'Install Policy Package & Device Settings' option.

 

Related documents:

Policy package installation targets

Technical Tip: How to fix synchronization issue in FortiManager

Technical Tip: FortiManager data configuration and synchronization procedures