Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
k-lee
New Contributor

Unable to add FortiGate to FortiManager

Hi all,

 

I am attempting to build a Fortinet Lab. I have a FortiGate version 7.6.1 and FortiManager 7.6.2. Both devices are using trial licenses. 

 

When attempting to add the FortiGate to the Manager, I am getting a "probe failed" error. 

 

On the FortiGate I have FMG-Access selected, I configured the ENC-algorithm to default

image.png

 

On the FortiManager I configured ENC-algorithm to low and fgfm-ssl-protocol sslv3

 

When attempting to add the FortiGate to the FortiManager from the FortiGate Security Fabric -> Fabric Connectors I get the below error

image.png

 

Any assistance will be greatly appreciated

 
 
1 Solution
ametkola
Staff
Staff

Hello @k-lee ,

 

Which is the current firmware version of FortiManager ? If you are running in v7.2.5 you can perform the following changes :

config system global
set fgfm-peercert-withoutsn enable
end

 

Reference article >> https://docs.fortinet.com/index.php/document/fortimanager/7.2.5/release-notes/519207

 

Regards,

ametkola

 

View solution in original post

12 REPLIES 12
Liebe4Alle
New Contributor

any solution or step by step guide to fix this issue in Fortimager 7.6.2

Rsilva86

I’m trying to make it work too and received same error. I was using FM and FG trial version v7.4 and then v7.6

jsunsaid
New Contributor

I am also trying this with FMG 7.4.6 and FGT 7.4.6 and not having any success. I created a local CA server and new certificates for the FMG and FGT to use. Talking to Fortisupport, they will not confirm deny, or help while using a trial license. Which is understandable.

 

I have mine to a point where it gives the OP error then says it has registered to FMG and to then authorise in FMG. The FGT never appears. The debug logs also show success on the certificates and the connection but also a fail on using TLSv1.3. The trial has limited encryption ability so this is likely the issue.

 

I am inclined to assume it will not work without the 'set fgfm-peercert-withoutsn enable', as they removed this from newer versions their is no point trying. Save your time and sanity.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors