Description | This article describes the reason the FortiSwitch shows offline due to an NTP issue noticed after the upgrade. |
Scope | FortiSwitch with v7.6.0 or v7.4.0 and above. |
Solution |
Issue: It is noticed when FortiSwitch in FortiLink mode is upgraded or possibly also noticed after reboot.
Behavior during the issue:
Reason: The FortiSwitch time is not in sync with the current time. NTP is not reachable.
Observation:
show system ntp
config system ntp
diag sniffer packet any "port 123"
diagnose debug flow filter addr <ntp-server-Ip-address>
Solution:
config firewall policy
Note: A more granular policy can be created to allow specific traffic.
The option is available under the FortiLink interface -> Advanced -> NTP server.
The below screenshot is provided from the FortiLink interface (FortiGate).
Note: It is necessary to reboot the FortiSwitch after the NTP config changes.
From CLI this config is available under the DHCP server:
show full system dhcp server edit 15 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.