- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiSwitch not Applying Configuration from FortiGate
Hi all,
I am having issues syncing configuration to my managed FortiSwitch devices. Currently, I am running FortiOS 7.4.4 and FortiSwitchOS 7.4.2 and when issuing a execute switch-controller get-sync-status all I get the below status, MAC and REST API login error.
FGT01 # execute switch-controller get-sync-status all
Managed-devices in current vdom root:
FortiLink interface : fortilink
SWITCH-ID (SERIAL) STATUS CONFIG MAC-SYNC HTTP-UPGRADE
Switch-A (SN12345667785654) Up Error Error -
[1]
command: https://10.10.10.1:443/api/v2/login
payload:
result : REST API login failed with error 60
Switch-B (SN41233434554657) Up Error Error -
[1]
command: https://10.10.10.2:443/api/v2/login
payload:
result : REST API login failed with error 60
I have another setup in a different location running the same version except the only different is that the tunnel-mode is set to compatible and I have no configuration sync issues:
config switch-controller system set tunnel-mode compatible end
Investigating this it seems as though this is a fix that people have identified and an issue that is apparent in the FortiOS 7.4.4 and 7.4.5 versions. It is also documented that this is still not fixed in FortiOS 7.4.5 and want to know if this is has been resolved in 7.6.0? I will likely be upgrading to this version because the below issue has been resolved:
On the System > Firmware & Registration page, after upgrading the version 7.4.2, the FortiSwitch shows as not registered in the GUI.
Regards,
Dan.
- Labels:
-
FortiGate
-
FortiSwitch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Anthony_E Is this something you can perhaps confirm in the backend? I've reviewed FortiOS release notes for 7.6.0 but cannot see the above resolved so will need to leave the tunnel mode set to compatible.
Regards,
Dan.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Dan,
Let me find someone who can help :)!
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
could you please refer this if it helps? https://community.fortinet.com/t5/FortiSwitch/Troubleshooting-Tip-REST-API-login-failed-with-error-6...
Sachit Das
ETAC Engineer
Wifi-Switching – International Support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This happened to me when I followed the recommendation in "security rating", setting tunnel mode to `strict`. Reverting to `compatible` fixed the sync problem for me, running 7.4.5 on the fortigates and 7.4.3 on the fortiswitches.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Huh, interesting. Another problem I found after I applied various improvements from the security ratings was, devices went blank in the port list. Anecdotal I guess, but now they are back... I wonder if this strict versus compatible setting also impacts this?
Created on ‎10-15-2024 01:16 PM Edited on ‎10-15-2024 01:24 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This also happened to me when I was applying Strict tunnel-mode per Security Ratings. The weird thing is that I had 8 pairs of FortiGate 40Fs and FortiSwitch 124Es, and it worked fine on 3 on them but affected the other 5. FortiSwitch TAC told me it was an issue with some hardware batches, and to set tunnel-mode to Moderate.
