Hello, I am using fortinac-f version 7.2.5. I added my existing firewall as l3 device. I have access point devices under it. yesterday I replaced my existing firewall with a different model. since yesterday, when I add my username and password to the cli line from the credentials section in the interface, I get an error. the access point devices I saw before are no longer visible. although I press the clear known host button, nothing changes.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
the error persists.
As I know, what is shown in that article is for older versions of FNAC that didn't have the option of custom ports configurations from GUI, now that is available so the CLI command is not needed anymore.
I searched internally and there is no reported issue related to using custom SSH ports. Is there any port forwarding configured in between FGT-FNAC or any SSH inspection rule in any firewall in between?
I did a test with FNAC 7.2.5 and FGT 7.2.6 (VM) and it can successfully validate credentials on port 2222, so we can assume that there is no problem with FNAC. It may be something in your network that cause this failure.
CLI output:
fnacf # execute ssh-known-hosts show nac
[10.1.2.1]:2222 ssh-ed25519 AAAAC3Nzxxxxxxxxxxxx
the error persists in the same way. i think the problem here is that there is still information from the old device
I solved the problem by changing the port. thanks for your help.
Thank you for the feedback. You changed it back to default (22), can you tell was this a FGT limitation or a FNAC issue?
I gave a different port number, I think it's a bug in fortinac. When I give the default port (22) or any other port, there is no problem. However, the problem occurs when I use port 2222, which I used on the device I replaced.
I had exaclty the same behaviour, but changing ssh port to 22 didn't solved. On my fortinac, the problem was on the HTTPS disabled and the API connector ( model configuration ) can't connect the Fortigate.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.