FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
vraev
Staff
Staff
Article Id 405132
Description

 

This article describes basic troubleshooting steps to undertake when 'Remote Access' is not working from the FortiManager.

 

Scope

 

FortiManager 7.4.2+.

 

Solution

 

Connections diagram:

 

diagram.png

 

The following options are needed on the FortiManager side:

 

config system admin setting
   set fgt-gui-proxy enable
   set fgt-gui-proxy-port 8082
end

config system admin profile
   edit "YourAdminProfile"
     set fgt-gui-proxy enable
   next
end

 

They can also be configured in the GUI:

 

2025-08-07 11_45_12-FortiManager - weepy-fmg-esx47 - System Settings - Settings — Mozilla Firefox.png

 

And:

 

2025-08-07 11_38_28-FortiManager - weepy-fmg-esx47 - System Settings - Admin Profiles — Mozilla Fire.png

 

Additionally:

  • The remote access port (TCP 8082 by default) should be allowed on the way from the workstation to the FortiManager.
  • No deep inspection or other implicit SSL proxy on the way.
  • FGFM tunnel established and up between FortiManager and the FortiGate.

 

Note: The default ports and explanation about them can be found in Incoming ports..

 

Example of operation.

'Right-click' a FortiGate in Device Manager and select Remote access from the context menu:

 

2025-08-07 11_59_32-FortiManager - weepy-fmg-esx47 - Device Manager - Device & Groups - Table View —.png

 

This opens a new browser tab redirecting to the FortiManager address and FortiGate GUI proxy port:

 

2025-08-07 12_01_16-Mozilla Firefox.png

 

Note: Some browsers may restrict the pop-up redirect. Make sure to allow it in the browser settings if needed.

 

Related document: 

Remote access to FortiOS GUI from FortiManager 7.4.2