Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dan_Eng52
Contributor

FortiSwitch not Applying Configuration from FortiGate

Hi all, 

 

I am having issues syncing configuration to my managed FortiSwitch devices. Currently, I am running FortiOS 7.4.4 and FortiSwitchOS 7.4.2 and when issuing a execute switch-controller get-sync-status all I get the below status, MAC and REST API login error. 

 

FGT01 # execute switch-controller get-sync-status all
Managed-devices in current vdom root:

FortiLink interface : fortilink
SWITCH-ID (SERIAL) STATUS CONFIG MAC-SYNC HTTP-UPGRADE
Switch-A (SN12345667785654) Up Error Error -

[1]
command: https://10.10.10.1:443/api/v2/login
payload:
result : REST API login failed with error 60
Switch-B (SN41233434554657) Up Error Error -

[1]
command: https://10.10.10.2:443/api/v2/login
payload:
result : REST API login failed with error 60

 

I have another setup in a different location running the same version except the only different is that the tunnel-mode is set to compatible and I have no configuration sync issues: 


config switch-controller system
    set tunnel-mode compatible
end       

 

Investigating this it seems as though this is a fix that people have identified and an issue that is apparent in the FortiOS 7.4.4 and 7.4.5 versions. It is also documented that this is still not fixed in FortiOS 7.4.5 and want to know if this is has been resolved in 7.6.0? I will likely be upgrading to this version because the below issue has been resolved:

 

On the System > Firmware & Registration page, after upgrading the version 7.4.2, the FortiSwitch shows as not registered in the GUI.

Regards, 

Dan.

 

7 REPLIES 7
Dan_Eng52
Contributor

@Anthony_E Is this something you can perhaps confirm in the backend? I've reviewed FortiOS release notes for 7.6.0 but cannot see the above resolved so will need to leave the tunnel mode set to compatible. 

Regards, 

Dan. 

Anthony_E
Community Manager
Community Manager

Hi Dan,

 

Let me find someone who can help :)!

 

Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

@sachitdas_FTNT, you are the FSW expert :)!

Do you have an idea?

Anthony-Fortinet Community Team.
sachitdas_FTNT

could you please refer this if it helps? https://community.fortinet.com/t5/FortiSwitch/Troubleshooting-Tip-REST-API-login-failed-with-error-6...

 

Regards,
Sachit Das
ETAC Engineer
Wifi-Switching – International Support
RickCogley
New Contributor II

This happened to me when I followed the recommendation in "security rating", setting tunnel mode to `strict`. Reverting to `compatible` fixed the sync problem for me, running 7.4.5 on the fortigates and 7.4.3 on the fortiswitches. 

RickCogley

Huh, interesting. Another problem I found after I applied various improvements from the security ratings was, devices went blank in the port list. Anecdotal I guess, but now they are back... I wonder if this strict versus compatible setting also impacts this? 

marlana80

This also happened to me when I was applying Strict tunnel-mode per Security Ratings. The weird thing is that I had 8 pairs of FortiGate 40Fs and FortiSwitch 124Es, and it worked fine on 3 on them but affected the other 5. FortiSwitch TAC told me it was an issue with some hardware batches, and to set tunnel-mode to Moderate.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors