- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Security Fabric stuck "connecting" - Management IP contains illegal characters
Hi all,
I hope you're well.
I am having issues connecting our branch firewalls to our fabric root FortiGate. All the configuration is correct as prior to upgrading all firewalls to 7.4.7 this was working just fine. Post upgrade to 7.4.7, we found that the set group-name "NAME" command was stripped from the security fabric configuration. This configuration was re-applied, and we can now see communication between the branch firewalls and fabric root on port 8013 however when running a sniffer, I get the below:
It seems as though that when it tries to validate it doesn't like the admin port that is configured which is not a default port. I have tried setting this to "Use Admin Port" as well as "Specify" but am still having the same issue. I am not sure as to what else I can change, changing the management port is not possible but I feel it would display the same behaviour no matter what this was set to.
Has anyone come across this issue before and have any ideas on how to resolve?
Many thanks,
Dan.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Anthony_E can you please assist in finding a possible solution? Many thanks, Dan.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Dan_Eng52,
Please note that Anthony is a Technical Writer and has no Technical knowledge (as for me).
Can you tell me if that helps:
If the Security Fabric is stuck on "connecting" and the management IP contains illegal characters, follow these steps to resolve the issue:
- Verify IP Address Format: Ensure that the management IP address is correctly formatted. It should only contain numbers and periods (e.g., 192.168.1.1).
- Check Configuration:
- Access the FortiGate and FortiNAC configuration settings.
- Verify that the management IP address is correctly entered without any illegal characters. - Correct Illegal Characters: If illegal characters are present, correct the IP address to a valid format.
- Restart Services: After correcting the IP address, restart the necessary services on both FortiGate and FortiNAC to apply the changes.
- Monitor Logs: Check the system logs for any errors or warnings related to the IP address configuration.
- Test Connectivity: Once changes are made, test the connectivity between FortiGate and FortiNAC to ensure the Security Fabric is functioning correctly. If the issue persists after following these steps, further investigation into the network configuration and settings may be required.
Hope it can help you otherwise I will seek assistance to help you.
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Dan
Can you share the output?
show full config sys global | grep management
You can hide the IP (but keep visible any extra character, if any).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi AEK,
Please see output below:
I'm not quite sure why it is complaining about illegal characters, it wasn't doing this prior to upgrading to 7.4.7 so I am hoping this is not a bug that has been introduced.
Let me know your thoughts.
Thanks,
Dan.
