Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gmoors
New Contributor

(forticlient) Can't register endpoint anymore

Can someone help me with this one?

After installing some 20 forticlients on Windows machines I now can't hook it to the fortigate anymore.

When I want to install the forticlient software I download the Windows executable from the firewall itself.

During previous installations the software attached itself to the firewall but now I have to attach it myself and then I get the following error message: see attachment

 

I've also read the following thread (http://kb.fortinet.com/kb/documentLink.do?externalID=FD37300) and did the recommendation but apparently changing this setting won't help.

3 REPLIES 3
emnoc
Esteemed Contributor III

You might want to double check any layer3 access and ensure the fortigate is enable and has the license for the FClient

 

If you have registrations problem check your local logs or debug on the fortigate. I'm assuming you have not exceed the  license seat accounts on the fortigate ?

 

Here's a quick short burp on register KAs for forticlients. If you have any client that traffic internal routers or firewall  and DO NOT reister locally keep in mind the tcp/port#.

http://socpuppet.blogspot...clent-registering.html

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
weatherman

Starting with FC 5.4 they changed the registration port to 8013.  FG firmware 5.0 & 5.2 listen on 8010.  With this client and firmware combination you'll have to register manually by tagging the port number. e.g. 192.168.10.1:8010

Firmware 5.4+ will listen on 8013.

 

Release notes are your friend.

http://docs.fortinet.com/uploaded/files/2608/forticlient-5.4.0-windows-release-notes.pdf

 

emnoc
Esteemed Contributor III

Good point that's easily missed. If in doubt , always tcpdump/wireshark port 8010 or 8013.

 

In the register dialog ( forticlient ) input block you can specify the  fortigate address  x.x.x.x:8010 and have the device registered at that manual address and port#.

 

ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors