Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ricvil
New Contributor II

Fortigate-50G unable to be properly managed by Fortimanager

I am a little bit lost here so any guidance is greatly appreciated.

 

I am able to add the Fortigate-50G to our Fortimanager 7.6 but since the 50G only comes with version 7.0.17 firmware it gives errors when trying to push configs or policies.   I see the rejected commands in the log, and when I try them on the Fortigate CLI, it is clear they do not exist.

 

I tried this under the default 7.6 ADOM, and also under a freshly created ADOM with the lowest possible value of 7.2.  I cannot create an ADOM with 7.0 so how is this supposed to work?

 

Please advise.  Thanks. 

1 Solution
cmartinez1

Hi.

 

Check the FortiManager v7.4.6 Release Note - known-issues.

https://docs.fortinet.com/document/fortimanager/7.4.6/release-notes/454729/known-issues

1119299

Installation fails due to syntax compatibility issues between FortiManager and FortiGate version 7.2.10. Specifically, the issue occurs when FortiManager attempts to unset the servercert in the vpn ssl settings.

 

Or open a ticket to Fortinet Support.

Regards,

View solution in original post

7 REPLIES 7
dingjerry_FTNT

Hi @ricvil ,

 

If you have to manage FGT 50G in FMG, and FGT 50G has a special firmware available with 7.0 only, why not use FMG 7.4.6 instead of FMG 7.6?

 

 

Regards,

Jerry
ricvil

Thank you for the suggestion, but 7.4 is no longer available on the AWS Marketplace for some reason.  I am only able to spin up the 7.6 version:

https://aws.amazon.com/marketplace/search/results?searchTerms=fortimanager

 

Does anybody know why?  I can't really run this VM out of our office.  I have to run it in AWS.

Tauri
New Contributor III

You can donwload FirmWare from FortiNet support. I also verified supported models for 7.4.6 AWS.

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e80cad0b-bd9d-11ef-9411-ae1fcf...


https://support.fortinet.com/Download/FirmwareImages.aspx

System Engineer
System Engineer
Tauri
New Contributor III

Hi! Try to use FortiManager 7.4.6, because it supports ADOM version 7.0. That way you can push configs and policies.

Have a nice day!

System Engineer
System Engineer
ricvil
New Contributor II

I tried to use FortiManager 7.4.6 by installing it in our Lab instead of AWS.  I created a 7.0 ADOM since the FortiGate-50G can only go up to 7.0.17.   The same error happens.  I first retrieve the config so that both FortiManager and FortiGate are in-sync.  Then I try a minor change like a secondary DNS and try to push it down.  It fails when it tries to perform the following:

 

FortiGate-50G-Lab $  config vpn ssl settings

command parse error before 'settings'

Command fail. Return code 1

FortiGate-50G-Lab $  set servercert ''

FortiGate-50G-Lab $  end

 

If I connect via CLI, I can confirm that command "config vpn ssl settings" does not exist, so the question is how do I prevent FortiManager trying to push that "ssl settings" config down.  I have no idea where that is.  The FortiGate is freshly opened up from the box and is at factory settings, and the FortiManager was freshly installed just to test this.

 

Any help in finding where to disable this would be greatly appreciated.  Thanks.

 

cmartinez1

Hi.

 

Check the FortiManager v7.4.6 Release Note - known-issues.

https://docs.fortinet.com/document/fortimanager/7.4.6/release-notes/454729/known-issues

1119299

Installation fails due to syntax compatibility issues between FortiManager and FortiGate version 7.2.10. Specifically, the issue occurs when FortiManager attempts to unset the servercert in the vpn ssl settings.

 

Or open a ticket to Fortinet Support.

Regards,

ricvil
New Contributor II

Thank you.  This is useful even though it describes a different version.  The 50G can only go up to 7.0.17.

 

I did end up opening multiple tickets and finally a Fortimanager engineer confirmed this was scheduled to be fixed on the next update.  I will mark this answer as the accepted solution as it is close enough.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors