FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
JBarrera
Staff
Staff
Article Id 282020
Description
This article describes how to troubleshoot the log Message 'Unable to connect to FDS servers'.

Scope FortiWeb.
Solution

Important: Check the connectivity to the FortiWeb(s) and if there are still issues connecting to the FDS server:

  1. Ensure that FortiWeb can access the Internet using TCP Port 443, DNS, and disable SSL inspection on the FortiWeb appliance.
  2. Ensure the time zone set on the FortiWeb is correct.
  3. Test connectivity for the FortiGuard Services by executing the following commands:


execute ping service.fortiguard.net
execute traceroute service.fortiguard.net
execute ping fds1.fortinet.com
execute traceroute fds1.fortinet.com
diagnose network route list
diagnose network ip list

diagnose system update info

 

Verify if the latest error is caused by connectivity/update failure.

 

  1. If the 3rd step is OK, but the problem persists, collect the information below and create a ticket for the TAC Engineers: Support.

 

diagnose system update log
diagnose system update servers
get system autoupdate tunneling

execute ping update.fortiguard.net

show system autoupdate over

 

diagnose debug application fds 7

diagnose debug application updated 7
diagnose debug enable
execute update-now

 

Wait 2-3 minutes, then disable the debug.

 

diagnose debug reset

diagnose debug disable