Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Yassinonce
New Contributor

Can't reach the forticare.fortinet.com to license my FortiGate VM.

Hi,

I have an issue with the evaluation license of my new FortiGate v7.4.1 VM, I am trying to license my new FortiGate and I am using my account credentials to connect to the forticare server but it fails, I did some troubleshooting and I notice that I can't ping the forticare.fortinet.com but instead the service.fortiguard.net and update.fortiguard.net were pinged successfully. can you please assist me with this problem.

10 REPLIES 10
ndumaj
Staff
Staff

Hello,

What is the error you are facing?
If you are failing to authenticate then it might be an issue with the user credentials.
-BR-

- Happy to help, hit like and accept the solution -
Yassinonce

The error says "Error Communicating with FortiCare". the credentials are correct and the routing also is set and I can ping the google DNS but I still can't reach the FortiCare server.

 

Edit: in the console  I got also the error "curl forticare failed, 28"

ndumaj
Staff
Staff

Hi,
Ensure that you dont have network access issue:
exec ping fds1.fortinet.com

exec ping directregistration.fortinet.com

exec ping globalftm.fortinet.net

execute ping directregistration.fortinet.com

If the DNS is not able to resolve to these domains, it would not be possible for FortiGate to communicate with FortiGuard servers. If the current DNS is not working, you can try to change to another DNS to see if that works.


Also try to perform telnet forticare.fortinet.com 443
Please review the following article:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Getting-license-invalid-error-when/t...

-BR-

- Happy to help, hit like and accept the solution -
Yassinonce

Hi Mr. Ndumaj,

I performed all the pings you suggested and also the telnet test and all of them was successful, I visited the article you mentioned and there is a test to show the default auth-cert, I executed the command  and I got "self-sign" instead of "Fortinet_Factory". Could this be the problem ?

ndumaj
Staff
Staff

Hello Yassinonce,

Well the cert also might be the problem.
FGT is the client and Forticare is the web server, Forticare is presenting the server certificate then FGT should be able to validate that cert with his own certificate(root CA) if it not able to validate ssl handshake will fail and cant establish the ssl connection.
You can see more details about the SSL handshake on a PCAP.

-BR-

- Happy to help, hit like and accept the solution -
Yassinonce

Hi,

 

What is the solution in this case ?

ndumaj
Staff
Staff

Hi,
Try to set Fortinet_Factory :
config sys global
set auth-cert Fortinet_Factory
next
end

-BR-

- Happy to help, hit like and accept the solution -
Yassinonce

Hi again,

I changed the default auth-cert to Fortinet_Factory, but the problem still persists. I ran Wireshark  and I noticed the TLS handshake failed in the last phase of it which means that the VM can't verify the fortiguard server certificate, but I still don't know why even if I changed the authe-cert.

ndumaj
Staff
Staff

hi,
Please can you also review this guide:
https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/441460/permanent-trial-mode-...

-BR-

- Happy to help, hit like and accept the solution -
Top Kudoed Authors