Created on
09-20-2023
08:16 AM
Edited on
04-14-2025
05:12 AM
By
Jean-Philippe_P
This article describes the steps to take to fix the problem with FortiSwitches in v7.4.0 that cannot be managed by FortiLAN Cloud.
FortiSwitch OS v7.4.0.
First, it is necessary to take into account that the FortiSwitches need a Management License. Remember that on Freemium, only 3 switches can be managed for free but it is necessary to have a valid license in order to manage more than 3. Take a look at this document to confirm: Licensing.
Check that FortiLAN Cloud has been enabled on FortiSwitch:
FSW # get system flan-cloud
interval : 3
name : fortiswitch-dispatch.forticloud.com
port : 443
status : enable
Check the current status of the connection to the FortiLAN Cloud manager:
FSW # get system flan-cloud-mgr connection-info
Service Name: : FortiLAN Cloud
User Account-ID : 0
Dispatch Service : IP= xx.xx.xx.xx
SSL verify Code : unspecified certificate verification error
Access Service : IP= xx.xx.xx.xx, Port= 443, Connected on: 2023-09-13 21:11:20
Bootstrap Service : hostname= portal, Port= 8000
Remote Assistance : Disabled.
State-Machine : State= FLAN_MGR_STATE_READY, Event= EV_READY_SSL_SESSION_DOWN
SSL Local End-Point : Interface: vlan230, IP: 10.28.230.40
SSL Tunnel Uptime : Days: 0 Hours: 0 Mins: 0 [Connected @2023-09-13 21:11:20]
SSL Tunnel stats : restart-count= 53112, Restart Reason= Error reading tunnel EP
Stats:
========
Switch Keep Alive Tx/Reply := 0 / 0
Manager Keep Alive Rx/Error := 0 / 0
Socks Req Rx/Last Stream-ID := 0 / 0
Reset Req Rx/last Stream-ID := 0 / 0
Goaway Req Rx := 0
Unknown Req Rx := 0
Syslog FD/Tx/Err := 10 / 0 / 0
Used SOCKS stream-id:
=======================
SID SockFd Proxy-Ports State Description
___________________________________________________________________
1 0 UNKNOWN:0<-->0 AUTH BOOTSTRAP
3 10 UDP:9514<-->0 AUTH SYSLOG DATA
Notice that the SSL verification Code shows an error: unspecified certificate verification error.
Perform a capture on the FortiSwitch to confirm an error on the SSL certificate:
FSW # diagnose debug disable
FSW # diagnose debug reset
FSW # diagnose debug application flan-mgr -1
FSW # diagnose debug console timestamp enable
FSW # diagnose debug enable
On the capture, it should display the following error:
2023-09-13 21:11:38 validate_file:303: [SID: -1] Unable to stat file =etc/cert/local/Fortinet_Factory2.cer
diagnose debug disable
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.