Hello,
I have restored an archive on cluster of 2 gates from the master gate, but now it's unable to connect (GUI, CLI, console ..) with anyone local account on them .....
This cluster is in production and all the traffic is ok ; On Fortimanager, members are ok and synchronized , the state (active-passive) is ok ; I can push new configuration from FM to Gates etc...
All to be seems ok but impossible to connect on gates !
I have tried to push a retrieve since FM but same result.
Any idea please ??
For information, the maintaner function is disabled.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I tried on port console (The device is not with me but in Datacenter ; the console port is connected on perle box to emulate the local connection; all other equipment on my perimeter are connected with perle and no problem. My gates too before the restore ) but same problem ...
Hey ckteur,
so, to summarize:
- you have a FortiGate 600D cluster in 6.4.14
- maintainer is disabled
- no matter what admin credentials you try, authentication fails (on both nodes?), via GUI, CLI and console as well
- accessing the device from FortiManager fails as well
Is that correct?
In that case, there isn't really a way to regain access, I'm sorry to say; if the FortiGate deems the password incorrect, and does not let you proceed, then usually the way to get in is via maintainer, but that's disabled.
The only thing I can suggest:
- take the most recent configuration backup you have (you can grab it from FortiManager)
- edit the file and find a local admin entry (Ideally 'admin')
- remove the line 'set password ENC xxxxxxx' completely.
- shut down the secondary
- reboot the primary, and interrupt boot via console
- format, and reload firmware via tftp
- upload the modified config backup
-> you can log in with the admin name, and no password (so 'admin' and no password, for example)
- power on the secondary, interrupt boot
- format and reload firmware via tftp
- let secondary come up, connect via console to provide basic HA config
- let the cluster reform
Then set admin passwords again as desired, ensure FortiManager has the correct credentials as well, and get the config back to what it should be.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1667 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.