Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
imartinez
New Contributor

SSL problems when applying policies

Hello

I´m quite new with fortimanager use.

 

I have a virtual Fortimanager running on version 5.6 with Fortigates also on version 5.6.

 

I had no problems by adding the fortigates to fortimanager, and aplying configuration from it. But the problem cames when I try to aply policies from Fortimanager to Fortigate. It says the following error and does not aply:

 

Device:pruebas VDOM:root Copy device global objects

Vdom copy failed: error 152 - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339)

Copy objects for vdom root "dynamic certificate local", "Fortinet_CA_SSLProxy", id=1268, FAIL - Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "strict", id=1417, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "scan", id=1457, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "web", id=1497, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall profile-group", "unfiltered", id=1537, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_0_scan_scan_", id=1721, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_1_strict_strict_", id=1729, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_2_unfiltered_unfiltered_", id=1737, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339) "firewall ssl-ssh-profile", "_3_web_web_", id=1745, FAIL - Mapping or default mapping not exist. detail: Local certificate "Fortinet_CA_SSLProxy" not exist in target device (SN:FGT51E5618001339)

 

 

The "Fortinet_CA_SSLProxy" is not present on new version of Fortigates, now it is called just "Fortinet_CA_SSL", but Fortimanager still looks for it. How can I configure Fortimanager to look for the correct certificate, or disable it to avoid this problem?

 

Thanks in advanced

3 REPLIES 3
chall_FTNT
Staff
Staff

We are definitely overdue for a KB article on this topic!

Starting in FOS 5.4, the factory default configuration of FortiGates does not include local certificate "Fortinet_CA_SSLProxy".  That certificate is only preserved if upgrading from earlier firmware.

 

Instead, the FortiManager should be configured to reference "Fortinet_CA_SSL" instead of "Fortinet_CA_SSLProxy" in SSH/SSL profiles & you need to make sure there is a dynamic mapping added pointing to the certficate on that FortiGate (see below)

 

Adding Dynamic Mapping for the Fortinet_CA_SSL certificate:

 

Step 1: Update Display Options in GUI if needed -Enable "Local Certificate" under "Dynamic Objects" (Policy & Object > Object Configuration > Tools > Display options > Local Certificate)

 

Step 2: Update Certificate -Go to Dynamic Objects > Local Certificates > select the Fortinet_SSLProxy > enable Per-Device Mapping > add the FortiGate in question and select the Local certificate

Chris Hall
Fortinet Technical Support
imartinez

Thanks for your help, the problem was solved!!

chall_FTNT

New KB Article: Installing Policy Package Fails -- 'Local certificate "Fortinet_CA_SSLProxy" not exist' http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD41585

Chris Hall
Fortinet Technical Support
Labels
Top Kudoed Authors