Does anybody have a quick to just temporary disable a FGT from FMG.? I'm not looking at unregistering. When we set the type to "none" we get the following message
" Please unregister-device from FortiManager first"
Any ideals or is this only controlled by the set allowacces fgfm?
Ken
PCNSE
NSE
StrongSwan
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
> set allowacces fgfm
This would prevent FGM from connecting.
Also:
To prevent FGT from attempting to contact FMG, you'd have to remove the FMG IP from the FGT.
To drop the current connection, you'd have to kill the fgfmd process on the FGT. Out of curiosity. Why do you want to do this? This is quite an unusual request.
We tried the set allowaccess and it did not work. I believe the FMG re-push the cfg but we didn't kill the fgfmd process
The reason why, v5.6.0 has strange issues that we want to re-evaluate by removing the FGT from management and then later re-connecting it.
Issues noted;
[ul]
This investigating these issues after an associate has upgraded the unit.
Ken
PCNSE
NSE
StrongSwan
pls try below workaround see if works for your case
on FGT, config a source IP from a different interface
conf sys central-management
set fmg-source-ip
wrong source IP will fail the tunnel setup between FMG and FGT
Thanks
Simon
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.