Hello Forum,
I try to upgrade the Fortimanager adom root from 5.6 to 6.0 and i get this error...
Here the diagnose debug service cdb 255.
xxxxxx0001 # Request:
{ "client": "gui SysAllAdoms:3397", "id": 1, "method": "exec", "params": [{ "target start": 2, "url": "\/pm\/config\/adom\/root\/_upgrade"}], "session": 10205}
Chkperm Response:
{ "id": 1, "result": [{ "status": { "code": 0, "message": "OK"}, "url": "\/pm\/config\/adom\/root\/_upgrade"}], "session": 10205}
Response:
{ "id": 1, "result": [{ "data": { "task": 93246}, "status": { "code": 0, "message": "OK"}, "url": "\/pm\/config\/adom\/root\/_upgrade"}]}
copy vpn certificate ca.root_CA2(soid=1173) to dparent=1467,
copy user tacacs+.xxxxx01(soid=1174) to dparent=1467,
copy user tacacs+.xxxxx02(soid=1175) to dparent=1467,
copy user local.guest(soid=355) to dparent=1467,
copy user group.SSO_Guest_Users(soid=356) to dparent=1467,
copy user group.Guest-group(soid=357) to dparent=1467,
copy user group.tacacs_admin(soid=1176) to dparent=1467,
copy match.1(soid=1177) to dparent=1176,
--> commit copy match.1(soid=1177) to dparent=1176, fail: err=-2,user group match is not a member. svrname:xxxxx01 members:xxxxx01 xxxxx02 name:xxxxx01 xxxxx02 member:xxxxx01 xxxxx02
======= Dump sentry and dentry======
1177 ---> 1177
id: 1 ---> 1
server-name: xxxxx01 ---> xxxxx01
group-name: FGTadmin ---> FGTadmin
===================================
copy match.1(soid=1177) to dparent=1176, :fail.
copy user group.tacacs_admin(soid=1176) to dparent=1467, :fail.
derlfwmmpc0001 # diagnose debug disable
There are no devices in the root adom no other adoms configured.....
I have no idea to find the issue. Tactacs Servers configured for login. But the upgrade will be done with admin User
Someone an idea ? I´m lost in the moment. I check Fortimanager config in the cli but user group not found only admin group.
hm upgrading an adom here each time threw weird errors.
I suggest checking or even (if possible) delete that usergroupin your adom and then try again.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hello sw2090,
i have no User group defined.... what i found is that there was a Bug Report ID 607672 with the Problem.
We use 6.0.9 of FortiManager, the Bug is listed as fixed ..... the problem continues ... mmh.
Regards Uwe
did you solve it in the end?
when this happens for me i try to find it for like an hour and then just open a support ticket, usually Fortinet support is able to fix these things quite quickly.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.