Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
llewesc1
New Contributor III

Reboot Downstream FortiGate on Fabric via Automation

I am trying to reboot a downstream device in the fabric, but the automation stitch is not triggering.

 

The trigger is a weekly schedule at hour 3 (3am - see image below). For action, I've tried using the system action (included with v7.2 onward) as well as a CLI Script for the reboot.

 

Interesting points to note:

 

 

  • If I use the system action and click on the Test Automation Stitch, it reboots the downstream device.
  • If I use the CLI Script and click on the Test Automation Stitch, it reboots the root and downstream device.
  • Waiting for the trigger to reboot in either instance never occurs. 

Any help is appreciated.

 

All devices are running 7.6.3

Root device is a 600E

Downstream device is a 40F

 

I have followed the below, but this does not mention if it can be used for a downstream device in a fabric.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-Automation-Stitch-to-schedule-restar...

 

Trigger Reboot.png

1 Solution
llewesc1
New Contributor III

Working with TAC, we determined the issue was related to the time zone setting (System > System > Time zone). For the automation stitch to work, the downstream FortiGate time had to match the root.

 

So even if your root FortiGate is in Toronto (GMT-5) and your satellite is in Vancouver (GMT-8), the time zones still have to match, so that the actual time on the firewall match.

 

I would've thought there'd be mention of it under Schedule trigger and wasn't able to find documentation anywhere else citing this caveat. If someone reads this ands knows where to find it please post.

 

Another item worth mentioning, our root FortiGate is not configured to be an NTP server for the downstream devices.

 

- Thanks

View solution in original post

8 REPLIES 8
RosenlindPer
New Contributor II

Hi,

You can choose which device in the fabric that the stitch should be applied on, so just chose your downstream fortigate.

 

/PR

per@fortiknight.com
per@fortiknight.com
llewesc1

To clarify, the downstream device is selected. Recall, when using the system action and clicking on the Test Automation Stitch, it reboots the downstream device. I've opened a ticket with TAC.

RosenlindPer

For your TAC ticket, make sure you follow the steps here and attach the logs in the ticket.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-Security-Fabric-Issu...

 

Unless it solves the issue for you :)

/PR

per@fortiknight.com
per@fortiknight.com
llewesc1
New Contributor III

Working with TAC, we determined the issue was related to the time zone setting (System > System > Time zone). For the automation stitch to work, the downstream FortiGate time had to match the root.

 

So even if your root FortiGate is in Toronto (GMT-5) and your satellite is in Vancouver (GMT-8), the time zones still have to match, so that the actual time on the firewall match.

 

I would've thought there'd be mention of it under Schedule trigger and wasn't able to find documentation anywhere else citing this caveat. If someone reads this ands knows where to find it please post.

 

Another item worth mentioning, our root FortiGate is not configured to be an NTP server for the downstream devices.

 

- Thanks

RosenlindPer

So timezones have to match, it just doesn't trigger on the "root fortigates timezone"? 

per@fortiknight.com
per@fortiknight.com
llewesc1

Yes, the time zone (or just the time possibly) have to match. When trying with the root set to America/Toronto and the downstream set to America/Vancouver it would not trigger via the schedule. When we set the downstream to America/Toronto, it worked as scheduled.

RosenlindPer

Did you get any bugid on this one? 

 

per@fortiknight.com
per@fortiknight.com
llewesc1

They did not provide one.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors