Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ckteur
New Contributor II

Unable to connect on gates after backup restored

Hello,

 

I have restored an archive on cluster of 2 gates from the master gate, but now it's unable to connect (GUI, CLI, console ..) with anyone local account on them .....

 

This cluster is in production and all the traffic is ok  ;  On Fortimanager, members are ok and synchronized , the state (active-passive) is ok ; I can push new configuration from FM to Gates etc...  

 

All to be seems ok but impossible to connect on gates !

 

I have tried to push a retrieve since FM but same result.

 

Any idea please ??

For information, the maintaner function is disabled.

 

 

Thanks

11 REPLIES 11
ckteur
New Contributor II

I tried on port console (The device is not with me but in Datacenter ; the console port is connected on perle box to emulate the local connection; all other equipment on my perimeter are connected with perle and no problem. My gates too before the restore ) but same problem ...

Debbie_FTNT
Staff
Staff

Hey ckteur,

so, to summarize:

- you have a FortiGate 600D cluster in 6.4.14

- maintainer is disabled

- no matter what admin credentials you try, authentication fails (on both nodes?), via GUI, CLI and console as well

- accessing the device from FortiManager fails as well

Is that correct?

In that case, there isn't really a way to regain access, I'm sorry to say; if the FortiGate deems the password incorrect, and does not let you proceed, then usually the way to get in is via maintainer, but that's disabled.

The only thing I can suggest:

- take the most recent configuration backup you have (you can grab it from FortiManager)

- edit the file and find a local admin entry (Ideally 'admin')

- remove the line 'set password ENC xxxxxxx' completely.

- shut down the secondary

- reboot the primary, and interrupt boot via console

- format, and reload firmware via tftp

- upload the modified config backup

-> you can log in with the admin name, and no password (so 'admin' and no password, for example)

- power on the secondary, interrupt boot

- format and reload firmware via tftp

- let secondary come up, connect via console to provide basic HA config

- let the cluster reform

 

Then set admin passwords again as desired, ensure FortiManager has the correct credentials as well, and get the config back to what it should be.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors