FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
cmaheu
Staff
Staff
Article Id 205928
Description

This article describes troubleshooting steps to take when an issue prevents the user from adding a server to the Server List in the Control Manager (NCM), presenting the following error:

'Error adding the server. The server cannot be added to the list.

 

Confirm that:

  • the IP address is reachable,
  • the server is not already on the list,
  • the server is running the same version as this management server,
  • the credentials used to access this Admin UI are also in the database on the server,'
Scope FortiNAC
Solution
  1. Verify the IP address is reachable from the Manager. Ensure ports TCP 22 (SSH) & 8443 (HTTPS) are not blocked between the manager and the servers.

 

Perform an SSH connectivity test

a. From the Manager CLI, enter: 'ssh root@<server ip address>'.

b. Login using the root password.

c. Once access is confirmed, enter: 'logout'.

If the attempt appears to hang (not prompted for a password), type Ctrl-C.

 

Double-check that all necessary TCP ports are open between the manager and servers (22,80,1050,5555,8443).

 

Note:
FortiNAC uses port 1050 for CORBA Management, and when a requester connects to this port, the appliance dynamically reassigns it to a port in the 30000-64000 range.

More information related to open ports can be found in the Administration Guide

 

  1. Verify the server is not already in the Server List in the Manager Dashboard.

  2. Verify the server is running the same version as the management server. This can be confirmed in the UI. Select the dropdown under the user icon in the upper right corner.
  3. Verify that the credentials used to access this Admin UI are also in the database on the server.  Log in to the server by using the same credentials as the Manager.  

     

  4. If the server is missing the Admin user record, add it to the Server UI. For instructions, see section Administrators of the Administration Guide

  5.  Versions F7.2.2, 9.4.3, 9.2.8, 9.1.10, and greater:

     

     

If further troubleshooting is required:

  1. Reproduce behavior.
  2. Collect logs from the Manager and all affected FortiNAC servers. See KB article Technical Tip: How to get a debug log report from FortiNAC-CA or FortiNAC-Manager for instructions.
  3. Open a support ticket and provide the following information:
  • FortiNAC code version (x.x.x.x).
  • Description of behavior.
  • Any changes before the behavior started.
  • Steps to reproduce the behavior.
  • Date and time of reproduction.
  • IP address and hostname of the Manager and affected FortiNAC servers.
  • Log files.

 

Related articles:

Troubleshooting Tip: FortiNAC Manager synchronization errors

Technical Tip: FortiNAC Control Manager function and Global objects

Technical Note: NCM communication issues with systems across WAN