Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rsmayer
New Contributor

FM 5.0.10 / FortiOS 5.0.10: Pollicy push fails due to realtime log upload setting.

Fortigate is currently set to upload logs to fortianalyzer in realtime:

md-fg-01 (global) # config log fortianalyzer setting md-fg-01 (setting) # show config log fortianalyzer setting     set status enable     set server 135.22.72.15     set upload-option realtime end

 

However FortiManager does not recognize this fact and always tries to set the upload-option to realtime and then fails to recognize that it's set.  Here a push log:

 

------- Start to retry -------- md-fg-01 $  config global md-fg-01 (global) $  config log fortianalyzer setting md-fg-01 (setting) $  set upload-option realtime md-fg-01 (setting) $  end md-fg-01 (global) $  end ---> generating verification report (global: log fortianalyzer setting:upload-option)     remote original:     to be installed: realtime <--- done generating verification report install failed

 

[ul]
  •  I have Retrieved the config to make sure FM is in sync. Subsequent pushes still fail.   
  • I have tried turning off realtime upload in FM and pushing (that works.  Then turning realtime back on and pushing again - that fails.[/ul]

    Any suggestions.?

     

    Rich Mayer

    LGS Innovations

  • Rich Mayer LGS Innovations
    Rich Mayer LGS Innovations
    13 REPLIES 13
    rsmayer
    New Contributor

    Simon,

    Update:  I now have the problem on another 200b.   Also I upgraded FGT to 5.0.11 and the problem still exists.   Note, however, that pushing the same policy to a 200b that is still running 5.0.9 works w/o issue.

     

    Rich Mayer LGS Innovations
    Rich Mayer LGS Innovations
    scao_FTNT
    Staff
    Staff

    Hi, Rich, thanks for the update, we actually still not yet reproduce this issue even using the same 200B hardware as yours, and we are still working on this issue,

     

    and if possible, we may need you to open a ticket, see if we can get remote access to your env?

     

    Thanks

     

    simon

    rsmayer
    New Contributor

    I just opened a ticket (# 1339435).   I would be happy let you web ex in and see / diagnose.

    Rich Mayer LGS Innovations
    Rich Mayer LGS Innovations
    scao_FTNT
    Staff
    Staff

    thanks, I will follow up that ticket

     

    Simon

    Labels
    Top Kudoed Authors