Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dleboeuf
New Contributor II

FortiGates unable to connect to FAZ after upgrade

Hello,

 

I recently upgraded a customers FAZ-200F from version 6.4.9 to version 7.0.10 and now none of the FortiGates will connect. All of the FortiGates are on version 7.0.12 which looks to be supported by FAZ on 7.0.10 per the matrix.

 

The FAZ had support expire on it so I cannot contact support at the moment unfortunately which is why I am coming here.

 

When I run log fortianalyzer test-connectivity on the FortiGate I get 'Failed to get FAZ's status. Invalid error number (0).(0)' which looks like it's pointing to a certificate error. I verified the FGTs and FAZ have matching certificates. I tried importing the local FAZ cert onto a FGT with no luck.

 

When I run 'diagnose debug app oftpd 255' on the FAZ I get the following output:

2023-12-19 13:43:57 [OFTP_SSL_CTX_dft:1237 10.112.15.50] dft-idx=0 inited=1.
2023-12-19 13:43:57 [__create_ssl_context:1663 10.112.15.50] SSL socket[72] pid[29164] ssl[0x18427b0] SSL_new() success.
2023-12-19 13:43:57 [__SSL_info_callback:299] before SSL initialization
2023-12-19 13:43:57 [__SSL_info_callback:299] before SSL initialization
2023-12-19 13:43:57 [server_sni_cb:1252] server_sni_cb(): sni='0x11e47f0/fortinet-ca2.fortinet.com'
2023-12-19 13:43:57 [server_sni_cb:1266] -- SSL server got SNI: 'fortinet-ca2.fortinet.com', SSL_CTX located: 0x120fda0, idx=0
2023-12-19 13:43:57 [__SSL_info_callback:299] SSLv3/TLS read client hello
2023-12-19 13:43:57 [__SSL_info_callback:299] SSLv3/TLS write server hello
2023-12-19 13:43:57 [__SSL_info_callback:299] SSLv3/TLS write change cipher spec
2023-12-19 13:43:57 [__SSL_info_callback:299] TLSv1.3 write encrypted extensions
2023-12-19 13:43:57 [__SSL_info_callback:299] SSLv3/TLS write certificate request
2023-12-19 13:43:57 [__SSL_info_callback:299] SSLv3/TLS write certificate
2023-12-19 13:43:57 [__SSL_info_callback:299] TLSv1.3 write server certificate verify
2023-12-19 13:43:57 [__SSL_info_callback:299] SSLv3/TLS write finished
2023-12-19 13:43:57 [__SSL_info_callback:299] TLSv1.3 early data
2023-12-19 13:43:57 [__SSL_info_callback:330] TLSv1.3 early data
2023-12-19 13:43:57 [OFTP_try_accept_SSL_connection:1843 10.112.15.50] SSL accept failed
2023-12-19 13:43:57 [OFTP_ssl_shutdown:1976 10.112.15.50] SSL pid[29164] ssl[0x16e2910] shuting down sockfd[28] ip[10.112.15.50] connected[1]
2023-12-19 13:43:57 [OFTP_ssl_shutdown:1989 10.112.15.50] SSL_shutdown Error. SSL_get_error[1]
2023-12-19 13:43:57 [OFTP_ssl_shutdown:1992] Error error:140E0197:SSL routines:SSL_shutdown:shutdown while in init
2023-12-19 13:43:57 [oftpd_close_session:847 10.112.15.50] Client connection closed. Reason 14(SSL setup failure)

 

Everything looks to be going okay until this error '2023-12-19 13:43:57 [OFTP_try_accept_SSL_connection:1843 10.112.15.50] SSL accept failed.' 

 

Does anyone have any tips on what I could check/verify regarding this? I have gone through multiple KBs with no luck. I can't seem to find anything online regarding that OFTP error I am seeing in the deubgs.

 

Thanks!

1 Solution
dleboeuf
New Contributor II

It ended being MTU, I didn't see that part in the KB.

 

I lowered the FAZ MTU to 1400 and all of my FGTs connected, weird. MTUs have always been set to default before the upgrade so not sure what happened.

View solution in original post

10 REPLIES 10
dleboeuf
New Contributor II

I saw the MTU step last night which resolved my issue.

 

Did something change from 6.4.9 to 7.0 that would have affected MTU?


Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors