Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw2090
SuperUser
SuperUser

FortiManager cannot roll out Policy package it imported from FortiGate before

hi,

 

I have the following Constellation:

 

One FGT100D that was in FMG in an Adom for 5.4 and got Polices and all from it fine.

Now that FGT has been upgraded (following the supported upgrade path) to Firmware 6.02. 

This worked fine. Now since I cannot rollout this FGT in the 5.4 adom anymore I have created a new adom for 6.0 and moved the FGT  over there. Since the new adom is empty I imported the policy package from the FortiGate whdh cworked fine. Thus there were some conflicts betweet FGT and FMG even though I followed the uprade path. FMG prompted me to solve them which I did.

Now if I try to roll that policy package out to the FortiGate it keeps failing but the log shows no definite error.

Log shows just this:

 

Starting log (Run on device) Start installing xxxx1 $ config system ntp xxxx1 (ntp) $ set syncinterval 60 xxxx1 (ntp) $ end xxxx1 $ config vpn certificate ca xxxx1 (ca) $ edit "xxxxxxxxx_CA2" xxxx1 (xxxxx_CA2) $ set ca "-----BEGIN CERTIFICATE----- xxxx1 (xxxxx_CA2) $ -----END CERTIFICATE-----" xxxx1 (xxxxx_CA2) $ set range global xxxx1 (xxxxx_CA2) $ next xxxx1 (ca) $ end xxxx1 $ config firewall address xxxx1 (address) $ edit "all" xxxxx1 (all) $ set uuid 2cd4f0da-3a72-51e9-7adb-cded3a23c736 xxxxx1 (all) $ next xxxxx1 (address) $ end ---> generating verification report (global: system ntp:syncinterval)  remote original:  to be installed: 60 ------- Start to retry -------- xxxx1 $ config system ntp xxxx1 (ntp) $ set syncinterval 60 xxxx1 (ntp) $ end ---> generating verification report (global: system ntp:syncinterval)  remote original:  to be installed: 60 install failed

 

I also rechecked on system ntp:syncinverval. Gui on the FortiGate says it is set to 60.

 

Does anyone have any advice on this?

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
2 REPLIES 2
chall_FTNT
Staff
Staff

It looks like the FortiManager does not believe 60 is the default value.  Occasionally the factory default values change.

The FortiGate is running 6.0.2.  Which patch release of FortiManager 6.0 is the FortiManager running?

Chris Hall
Fortinet Technical Support
sw2090

FMG is v6.0.3-build0255 181102 (GA)

 

Anyhow I had to roll that FGT back to 5.4.10 because I need it for production and cannot use it for testing anymore.

Since I had backups from before the upgrade that was no bigger problem.

I also moved it back into the 5.4 adom (it lost its interface mappings with that but those can easily be restored).

Rolling Policy Package out in to this FGT with 5.4.10 and in the 5.4 adom works fine now.

 

Anyhow we well have to upgrade all our FGT plus the adom to 5.6 (and maybe then on to 6.0) sine 5.4 is EOL.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors