Created on 12-10-2024 07:00 AM Edited on 12-10-2024 07:31 AM By Jean-Philippe_P
This article describes a workaround to resolve the issue where the 'Install Preview' on a FortiManager always shows the 'Certificate Fingerprint' configuration instead of the actual changes made.
FortiManager, FortiClient EMS, FortiGate.
When the certificate is updated on the EMS server, it is updated on the FortiGate. FortiManager retrieves this data and updates its Device Database.
To apply changes, Configure any settings on the FortiManager. Then, push the configuration to the target FortiGate. Before completing the installation, select 'Install Preview'. Instead of reflecting the changes made, the preview will display the 'certificate fingerprint' configuration.
Resolution:
In the FortiManager, navigate to Device Manager -> Device & Groups -> The target FortiGate -> CLI Configurations -> Endpoint-Control -> fctems.
Navigate to Fabric View -> Fabric Connectors -> fct ems-1 -> Advanced -> Certificate-fingerprint.
Copy the certificate fingerprint from 'Device Manager -> Device & Groups -> Target FortiGate -> CLI Configurations -> Endpoint-Control -> fctems' and paste it to 'Fabric View -> Fabric Connectors -> fct ems-1 -> Advanced -> Certificate-fingerprint'.
Note:
FortiManager does not support importing fctems. It just always copies the ADOM database config to the device level.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.