Hello,
When I connect to our FortiGate 100D via SSH I am not able to edit 'config system modem', and I get the following error returned:
FG100D********* # config system modem
command parse error before 'modem'
Command fail. Return code 1
If I run 'show system ?' the modem option is not listed:
FG100D********* # show system
3g-modem Configure 3G modem.
accprofile Configure system admin access group.
***/SNIP/***
ipv6-neighbor-cache Configure IPv6 neighbor cache table.
ipv6-tunnel Configure IPv6/IPv4 in IPv6 tunnel.
monitors Configure system monitors.
nat64 Configure NAT64.
network-visibility Configure network visibility settings.
ntp Configure system NTP information.
object-tag Configure object tags.
****/SNIP/****
If I then connect to the same firewall using telnet instead of SSH, the commands work as expected:
FG100D********* # config system modem
FG100D********* (modem) #
and the modem field is listed:
FG100D********* # config system
3g-modem Configure 3G modem.
accprofile Configure system admin access group.
****/SNIP/****
ipv6-neighbor-cache Configure IPv6 neighbor cache table.
ipv6-tunnel Configure IPv6/IPv4 in IPv6 tunnel.
modem Configure MODEM.
monitors Configure system monitors.
nat64 Configure NAT64.
network-visibility Configure network visibility settings.
ntp Configure system NTP information.
object-tag Configure object tags.
****/SNIP/****
The commands are also available through the 'CLI Console' in the web GUI, my guess is that it uses a TELNET session in the backend to make that connection.
I have raised a support ticket with FortiNet (1457401), but I thought I would post this here incase someone has seen it before.
Regards,
Tim
hi,
welcome to the forums.
Thanks for posting this. FTNT will certainly have a look into this.
Which version of FortiOS do you use?
Hi Ede,
We are running v5.0,build0292 (GA Patch 9).
Additionally, we have two firewalls, both 100D's running the same firmware version and this is repeatable on both firewalls.
Tim
Would you consider upgrading to 5.0.12 (via 5.0.10 first)? It would be interesting whether this bug is already fixed or not.
Hi Ede,
I upgraded to 5.2.2 this afternoon and the problem still exists. I'll give the support number a call on Monday.
Tim
I'm curious does the diag sys modem commands error out also?
PCNSE
NSE
StrongSwan
Yeah that works:
The modem state is 3, poll rate is <unpolled>.
The modem is active.
And the diag sys modem external-modem option works too:
NDCHAFW01 # diag sys modem external-modem
External modem vendor: Sierra
External modem vendor id: 0f3d
External modem model : AC320U
External modem product id: 68aa
Morning,
Fortinet support have got back to me regarding this problem and it appears to be a bug:
Hi, I was able to reproduce the issue with your config. When enabled dedicated-mgmt, we can't access the modem via ssh but telnet is possible config system dedicated-mgmt set status enable set interface "mgmt" set default-gateway 10.10.2.3 end I am not sure this is by design so will need to contact engineering and get back to you. In the mean time, please use telnet or disable this dedicated-mgmt. Note that: When disable this setting you will need to re-add IP for the 'mgmt' interface. Please let me know if you have any question Thanks, Viet
I'll wait and see if the engineering team get back to me.
Tim
In the mean time, please use telnet or disable this dedicated-mgmt.
Ouch, not good;)
PCNSE
NSE
StrongSwan
User | Count |
---|---|
2559 | |
1357 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.