- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unable to add FortiGate to FortiManager
Hi all,
I am attempting to build a Fortinet Lab. I have a FortiGate version 7.6.1 and FortiManager 7.6.2. Both devices are using trial licenses.
When attempting to add the FortiGate to the Manager, I am getting a "probe failed" error.
On the FortiGate I have FMG-Access selected, I configured the ENC-algorithm to default
On the FortiManager I configured ENC-algorithm to low and fgfm-ssl-protocol sslv3
When attempting to add the FortiGate to the FortiManager from the FortiGate Security Fabric -> Fabric Connectors I get the below error
Any assistance will be greatly appreciated
Solved! Go to Solution.
- Labels:
-
FortiGate
-
FortiManager
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @k-lee ,
Which is the current firmware version of FortiManager ? If you are running in v7.2.5 you can perform the following changes :
config system global
set fgfm-peercert-withoutsn enable
end
Reference article >> https://docs.fortinet.com/index.php/document/fortimanager/7.2.5/release-notes/519207
Regards,
ametkola
- « Previous
-
- 1
- 2
- Next »
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
any solution or step by step guide to fix this issue in Fortimager 7.6.2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I’m trying to make it work too and received same error. I was using FM and FG trial version v7.4 and then v7.6
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am also trying this with FMG 7.4.6 and FGT 7.4.6 and not having any success. I created a local CA server and new certificates for the FMG and FGT to use. Talking to Fortisupport, they will not confirm deny, or help while using a trial license. Which is understandable.
I have mine to a point where it gives the OP error then says it has registered to FMG and to then authorise in FMG. The FGT never appears. The debug logs also show success on the certificates and the connection but also a fail on using TLSv1.3. The trial has limited encryption ability so this is likely the issue.
I am inclined to assume it will not work without the 'set fgfm-peercert-withoutsn enable', as they removed this from newer versions their is no point trying. Save your time and sanity.

- « Previous
-
- 1
- 2
- Next »