Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Rub_aprendicia
New Contributor II

ERROR FortiManager Sync Configuration Status & Policy Package Status

 

Greetings everyone,

 

I am opening this case because I have set up a virtual lab with a FortiManager that manages three FortiGates, ALL with TRIAL licenses. The entire lab is virtual, using the following versions:

  • FMG_VM64_KVM-v7.6.1.M-build3344-FORTINET.out.kvm
  • FGT_VM64_KVM-v7.6.2.F-build3462-FORTINET.out.kvm

The FortiGates are registered using the following command in FortiManager:

 

config sys global

     set fgfm-peercert-withoutsn enable

end

 

 

The Issue

After registering the devices, the problem arises when pushing configurations or policies to the FortiGate, as it always results in an error. As shown in the images below:

Rub_aprendicia_0-1741603116832.png

 

Install OK / Verify FAIL

When expanding the error message from the FortiManager UI:

Rub_aprendicia_1-1741603116848.png

 

 

Checking the Install Log reveals that the issue occurs because FortiManager attempts to modify (delete) the WebFilter profile "monitor-all", as shown in the following image:

Rub_aprendicia_2-1741603116863.png

 

 

CLI Test on FortiGate
The issue is that FortiGate does not allow the deletion of this default profile. Running the command directly on the FortiGate CLI results in the same error:

   FW-CENTRAL (profile) # delete monitor-all

Can not delete a static table entry

Command fail. Return code -61

 

 Important Observation

Even though this error occurs, the configurations and policies ARE actually applied on the FortiGate.

 

 Troubleshooting Attempts

  • Downgraded FortiGate to version 7.6.0, as I have confirmed that FortiManager 7.6.1 and FortiGate 7.6.2 may have compatibility issues. However, a similar (but not identical) issue occurred with 7.6.0.

Searched for similar issues and found an open discussion in the Fortinet forum:

https://community.fortinet.com/t5/Support-Forum/set-banned-cipher-prevents-pushing-the-device-config...

 

Thanks for your help!!!

1 Solution
Rub_aprendicia
New Contributor II

Hi again,

 

we can avoid the verify check (results in error) in ADVANDEC - MISC -> DISABLE VERIFY CHECK.

"verify installation" -> default ON -> change to OFF

 

Best Regards

View solution in original post

5 REPLIES 5
Anthony_E
Community Manager
Community Manager

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

Could you please open a ticket with our TAC?: https://support.fortinet.com/welcome

 

Regards,


Thanks,

Anthony-Fortinet Community Team.
Rub_aprendicia
New Contributor II

thanks for your help

 

Best Regards,

Rub_aprendicia
New Contributor II

Hi again,

 

we can avoid the verify check (results in error) in ADVANDEC - MISC -> DISABLE VERIFY CHECK.

"verify installation" -> default ON -> change to OFF

 

Best Regards

Jean-Philippe_P
Moderator
Moderator

Hello Rub_aprendicia,

 

Glad that you had the solution, and thanks for sharing it!

 

Have a good day :)

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors