FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
farhanahmed
Staff
Staff
Article Id 324116

 

Description

The article describes how to troubleshoot when FortiManager is unable to authorize devices with the error message 'Failed to update device information'.

 

1.png

Scope FortiManager, FortiGate.
Solution

 

First method: 

  • On FortiGate under Security Fabric -> Fabric Connectors -> Central Management -> Edit, select OK. A pop-up should appear to verify the serial number of FortiManager, verify it, and then try to authorize the FortiGate in FortiManager.
  • If the pop-up does not appear, try to force the central-management authorization using the command below, then try to authorize the device again in FortiManager:


exe central-mgmt register-device <FMG SN#> <FGT admin password>

  • If it still fails, try to use other suggested methods.

 

Second method:

  1. Disable the central-management connector on FortiGate -> Security Fabric -> Fabric Connectors -> Central Management.

  2. Delete the device from the FortiManager Unauthorized list.
                                       
    3.png
  3. Enable the central-management connector again on the FortiGate -> Security Fabric -> Fabric Connectors -> Central Management, then select OK.

    4.png                                                  
  4. A pop-up will appear to verify the serial number of FortiManager. Select Accept.
                                                               
    5.png                                                             
  5. The FortiGate appears again in the FortiManager Unauthorized list with a 'green up' arrow, which then can be authorized to the required ADOM.
                                                                       
    6.png7.png

 

Third method:

If following the second method at point 4, this error will be shown:
  

FGT_Error.png

 

Probably in FortiManager, the device will appear to authorize, but with the Serial Number of another unit of the FGCP Cluster, the device with the highest priority, but not the current primary (in a scenario with the FGCP override option disabled).

 

In that scenario is necessary repeat the point 1 and 2 of the second method, but after that is necessary try to add the FortiGate cluster from the FortiManager under the desired ADOM, selecting: Add Device -> Discover Device, Enter the IP of the Cluster of the interface with 'FMG-Access' option activated, activate the option: 'Use Legacy Device Login' and try to add it.

 

Note that the third method cannot be used with FortiManager Cloud; in that case, follow the Option 4 provided in this article:

Technical Tip: How to add FortiGate with its current config to FortiManager when 'set fgfm-deny-unkn... 

 

If the issue persists:

  • And the FortiGate is deployed as a VM. Try to reimport the license file. This process will regenerate the certificates.
  • If it is not resolved using the above steps, contact Fortinet Support TAC, providing:
    • FortiGate and FortiManager backup (with any backup passwords).
    • FortiGate and FortiManager debugs of the demons managing the FGFM tunnel.
    • Traffic captures.

There are instructions regarding how to collect debugs and traffic captures: Troubleshooting Tip: How to troubleshoot connectivity issues between FortiGate and FortiManager.