Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sridharsre
New Contributor II

FortiManager: After firewalls failover, I got "Config Status: Conflict"

Hello All,

 

After the failover happened for one of the firewalls, the device's config status went to Conflict. tried to install configuration also, but still shows "Conflict".

 

Kindly help me.

 

Thanks in advance !!!

 

Best Regards,

Sridhar S

Warmest Regards, Sri Sre
Warmest Regards, Sri Sre
9 REPLIES 9
scao_FTNT
Staff
Staff

Hi, Sridhar, is install OK or failed? not sure if you can provide install log?

 

what is the FMG version and FOS version?

 

conflict is for when FMG detect local device db has config change + remote FGT has config change at same time

 

Thanks

 

Simon

sridharsre

Hi Simon,

 

yes there was a change in local fortigate firewall (added new virtual interface).

 

How to import that configuration changes to Fortimanager, like policies ?

 

Thanks in advance !!!

 

Regards,

Sridhar S

 

 

Warmest Regards, Sri Sre
Warmest Regards, Sri Sre
sridharsre

Hi Simon,  

Fortimanager VM64 Firmware Version: v5.2.1-build0662 141212 (GA)

yes there was a change in local fortigate firewall (added new virtual interface). How to import that configuration changes to Fortimanager, like policies ?   Thanks in advance !!!   Regards,

Sridhar S

Warmest Regards, Sri Sre
Warmest Regards, Sri Sre
scao_FTNT

there are basically 2 kind of config changes

 

1. non-policy config, like admin, admin profile, route etc, and this config, if changed on FGT, will auto update to FMG, but your FMG version is old, and if auto update not triggered (for example, you may see FMG shows out-of-sync config status after config change on FGT), you can do a manual retrieve on FMG, in FMG device manager, per device revision history page

 

2. policy related config, like policy, policy used address etc, if you are using FMG to manage FGT config, and do config change on FMG and install to FGT, and then if you have policy change on FGT, you may have to retrieve change back to FMG and then import to FMG policy db to sync between FMG package db and remote FGT. FMG device manager, device right click menu has an import function, to let you import policy config from device db (which auto update or retrieve from FGT) to ADOM level policy db, either overwrite existing package or for a new package

 

Thanks

 

Simon

sridharsre

Hi Simon,

 

Thanks much for your reply.

 

The first one is my scenario. you mean to say, if I do changes firewall locally, I have to manually retrieve to FortiManager ? Does not update automatically ?

 

If the manually update is only solution, how to perform it, since I tried install config.

 

Thanks in advance !!!

 

Regards,

Sridhar S

 

 

Warmest Regards, Sri Sre
Warmest Regards, Sri Sre
scao_FTNT

pls check attached pic for the manual retrieve

 

Thanks

 

Simon

sridharsre

Hi Simon,

 

Thanks for your reply.

 

As I tried, I got the following error pop-up: "Can not communicate with Remote Device (tunnel is down)"

 

Thanks in advance !!!

 

Regards,

Sridhar S

Warmest Regards, Sri Sre
Warmest Regards, Sri Sre
scao_FTNT

i c, this issue might be caused by your https://forum.fortinet.com/tm.aspx?m=134126

 

can you open a ticket and send me the ticket ID? I will follow up your ticket for your case

 

Thanks

 

Simon

sridharsre

Hi Simon,

 

Thanks for your reply.

 

I will raise a ticket and will let you know.

 

Regards,

Sri

Warmest Regards, Sri Sre
Warmest Regards, Sri Sre
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors