Hi all,
I am having issues syncing configuration to my managed FortiSwitch devices. Currently, I am running FortiOS 7.4.4 and FortiSwitchOS 7.4.2 and when issuing a execute switch-controller get-sync-status all I get the below status, MAC and REST API login error.
FGT01 # execute switch-controller get-sync-status all
Managed-devices in current vdom root:
FortiLink interface : fortilink
SWITCH-ID (SERIAL) STATUS CONFIG MAC-SYNC HTTP-UPGRADE
Switch-A (SN12345667785654) Up Error Error -
[1]
command: https://10.10.10.1:443/api/v2/login
payload:
result : REST API login failed with error 60
Switch-B (SN41233434554657) Up Error Error -
[1]
command: https://10.10.10.2:443/api/v2/login
payload:
result : REST API login failed with error 60
I have another setup in a different location running the same version except the only different is that the tunnel-mode is set to compatible and I have no configuration sync issues:
config switch-controller system set tunnel-mode compatible end
Investigating this it seems as though this is a fix that people have identified and an issue that is apparent in the FortiOS 7.4.4 and 7.4.5 versions. It is also documented that this is still not fixed in FortiOS 7.4.5 and want to know if this is has been resolved in 7.6.0? I will likely be upgrading to this version because the below issue has been resolved:
On the System > Firmware & Registration page, after upgrading the version 7.4.2, the FortiSwitch shows as not registered in the GUI.
Regards,
Dan.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
@Anthony_E Is this something you can perhaps confirm in the backend? I've reviewed FortiOS release notes for 7.6.0 but cannot see the above resolved so will need to leave the tunnel mode set to compatible.
Regards,
Dan.
Hi Dan,
Let me find someone who can help :)!
Regards,
could you please refer this if it helps? https://community.fortinet.com/t5/FortiSwitch/Troubleshooting-Tip-REST-API-login-failed-with-error-6...
This happened to me when I followed the recommendation in "security rating", setting tunnel mode to `strict`. Reverting to `compatible` fixed the sync problem for me, running 7.4.5 on the fortigates and 7.4.3 on the fortiswitches.
Huh, interesting. Another problem I found after I applied various improvements from the security ratings was, devices went blank in the port list. Anecdotal I guess, but now they are back... I wonder if this strict versus compatible setting also impacts this?
Created on 10-15-2024 01:16 PM Edited on 10-15-2024 01:24 PM
This also happened to me when I was applying Strict tunnel-mode per Security Ratings. The weird thing is that I had 8 pairs of FortiGate 40Fs and FortiSwitch 124Es, and it worked fine on 3 on them but affected the other 5. FortiSwitch TAC told me it was an issue with some hardware batches, and to set tunnel-mode to Moderate.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.