FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
Hiromu
Staff
Staff
Article Id 424591
Description

This article describes the cause of an issue where it is not possible to configure an OSPF passive interface in certain versions.

Scope FortiManager v7.4.
Solution

Add an OSPF passive interface configuration from Device Manager -> Router -> OSPF -> Advanced Options, but the FortiGate configuration status does not change to Modified.

 

Test scenario:

Add only an OSPF passive interface configuration entry from Device Settings -> Router -> OSPF -> Advanced options.

 

image1.png

 

After, return to Device & Groups and confirm that the FortiGate configuration status does not show Modified.

 

image2.png

 

Root cause:

There are two places to configure OSPF passive interfaces, which leads to a mismatch in status reporting. The two locations are Device Manager -> FortiGate Dashboard -> Router -> OSPF -> Advanced options and Device Manager -> FortiGate Dashboard -> CLI Configurations -> Router -> OSPF.

 

Workaround:

Configure the passive interface when creating the OSPF interface, or configure it from the Device Manager -> FGT Dashboard -> CLI Configuration -> Router -> OSPF.

 

OSPF interfaces configuration:

 

image3.png

 

Navigate to Device Manager -> FortiGate Dashboard -> CLI Configuration -> Router -> OSPF:

 

image4.png

 

Starting from v7.4.7, the passive interface setting under Advanced options was removed because it conflicted with the passive interface setting within the OSPF interface configuration.