Hello
I´m quite new with fortimanager use.
I have a virtual Fortimanager running on version 5.6 with Fortigates also on version 5.6.
I had no problems by adding the fortigates to fortimanager, and aplying configuration from it. But the problem cames when I try to aply policies from Fortimanager to Fortigate. It says the following error and does not aply:
Device:pruebas VDOM:root Copy device global objects
Vdom copy failed: error 152 - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339)
Copy objects for vdom root "dynamic certificate local", "Fortinet_CA_SSLProxy", id=1268, FAIL - Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "strict", id=1417, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "scan", id=1457, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "web", id=1497, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "unfiltered", id=1537, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_0_scan_scan_", id=1721, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_1_strict_strict_", id=1729, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_2_unfiltered_unfiltered_", id=1737, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_3_web_web_", id=1745, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339)
The "Fortinet_CA_SSLProxy" is not present on new version of Fortigates, now it is called just "Fortinet_CA_SSL", but Fortimanager still looks for it. How can I configure Fortimanager to look for the correct certificate, or disable it to avoid this problem?
Thanks in advanced
We are definitely overdue for a KB article on this topic!
Starting in FOS 5.4, the factory default configuration of FortiGates does not include local certificate "Fortinet_CA_SSLProxy". That certificate is only preserved if upgrading from earlier firmware.
Instead, the FortiManager should be configured to reference "Fortinet_CA_SSL" instead of "Fortinet_CA_SSLProxy" in SSH/SSL profiles & you need to make sure there is a dynamic mapping added pointing to the certficate on that FortiGate (see below)
Adding Dynamic Mapping for the Fortinet_CA_SSL certificate:
Step 1: Update Display Options in GUI if needed -Enable "Local Certificate" under "Dynamic Objects" (Policy & Object > Object Configuration > Tools > Display options > Local Certificate)
Step 2: Update Certificate -Go to Dynamic Objects > Local Certificates > select the Fortinet_SSLProxy > enable Per-Device Mapping > add the FortiGate in question and select the Local certificate
Thanks for your help, the problem was solved!!
New KB Article: Installing Policy Package Fails -- 'Local certificate "Fortinet_CA_SSLProxy" not exist' http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD41585
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.