PCNSE
NSE
StrongSwan
Solved! Go to Solution.
Andy Bailey wrote:I've getting a "Failed to save some changes: Input value is invalid" message (showing in the attachment) when I try and modify a policy (for example add an anti-spam to an existing policy).
Hey,
I don't have that problem - works fine for me since Beta 3.
Can you run the following on a Command Line, while you try to modify a policy:
diag deb reset
diag deb ena
diag deb cli 8
... and post the output
Br,
Roman
romanr wrote:Andy Bailey wrote:I've getting a "Failed to save some changes: Input value is invalid" message (showing in the attachment) when I try and modify a policy (for example add an anti-spam to an existing policy).
Can you run the following on a Command Line, while you try to modify a policy:
diag deb reset
diag deb ena
diag deb cli 8
... and post the output
In addition, please enable "diag debug app httpsd -1" and include that output.
Andy Bailey wrote:I've attached the output your requested Roman and Jordan. Thanks for your help.
Nothing really obvious for me. I tried opening the policy and then clicking ok (no changes) and again (no changes) same result both times. I tried Edge instread of Firefox too- no changes there either.
The key lines seem to be:-
[httpsd 9510 - 1522869450 error] cmdb_commit_from_json[1426] -- error saving request object to CLI (-651) [httpsd 9510 - 1522869450 error] _api_cmdb_v2_config[1137] -- error editing object (nret=-651) [httpsd 9510 - 1522869450 error] api_return_http_result[516] -- API error -651 raised
Interestingly I can delete policies- I just tried deleting a couple of unused policies and that worked fine (highlighted from the "IPv4 Policy" list and then just delete.
Any other ideas?
Hi Andy, we've tried with several FGTs and were unable to reproduce your issue. Looks like it's specific to your config after upgrade. From your CLI debug output, the CLI is rejecting the change (any policy edit save) from the GUI.
0: config firewall policy 0: edit 15 0: set ssl-ssh-profile "SSL Certs-Block Untrusted\\Invalid" -651: end
Here are a few other things to try:
1. Can you use the CLI to edit a policy? You can use the above commands to see further error reported by the CLI
2. Can you use the GUI to create new Policy? if not, please also include CLI and httpsd debug message
3. Does this happen to any policy edit via the GUI? 4. Can you check if your interfaces are correctly upgraded?
5. Which FGT model are you using? if possible, can you share your full config with us? you can email me the config at thuynh@fortinet.com
Tri
Are the existing users in the same DN format
CN= OU= OU= DC= DC=
What's different between old and new, if you use ldapsearch or ldptree query do you see anything that pops out at you ?
Ken
PCNSE
NSE
StrongSwan
Thanks enmoc.
New_user is a clone of old_user. All the attributtes are the same but Exchange mailbo, that new user do not use.
Hello again.
I've installed wireshark in the network and I've monitored LDAP queries.
The problem reproduces with user that use a Exchange Mailbox and configure mobile devices to configure antivesync.
AD creates a subkey in the user "CN=ExchangeActiveSyncDevices" and user that contains this key fail in LDAP queries.
It seems Its a Fortigate 6.0.0 bug. Not in 5.6.4 and previous releases.
I'll open a support ticket to inform for this issue.
Thank you.
A new issue arose over this past weekend. The usage of a mix 802.11 WPA/OPEN for wireless VAP broke the WPA-authentication in my FWW51E. I ended up factory resetting my unit since I was effectively locked out of the wireless. I need to dive deeper but the system event logs showed nothing.
PCNSE
NSE
StrongSwan
Multiple SSIDs with WPA2-PSK and one Open SSID with an Captive Portal are running fine here.
Used hardware is an fortiwifi 30E with 6.0.0 and an fortiap-11c with 5.6.2.
NSE 4/5/7
That's good to know, I will have to go back and retry but my home wifi was broken and kids and wife was complaining of the minidlna server not working. So they couldn't get to the homeTV video network ;)
PCNSE
NSE
StrongSwan
Andy Bailey wrote:I've attached the output your requested Roman and Jordan. Thanks for your help.
Nothing really obvious for me. I tried opening the policy and then clicking ok (no changes) and again (no changes) same result both times. I tried Edge instread of Firefox too- no changes there either.
The key lines seem to be:-
[httpsd 9510 - 1522869450 error] cmdb_commit_from_json[1426] -- error saving request object to CLI (-651) [httpsd 9510 - 1522869450 error] _api_cmdb_v2_config[1137] -- error editing object (nret=-651) [httpsd 9510 - 1522869450 error] api_return_http_result[516] -- API error -651 raised
Interestingly I can delete policies- I just tried deleting a couple of unused policies and that worked fine (highlighted from the "IPv4 Policy" list and then just delete.
Any other ideas?
Hi Andy, we've tried with several FGTs and were unable to reproduce your issue. Looks like it's specific to your config after upgrade. From your CLI debug output, the CLI is rejecting the change (any policy edit save) from the GUI.
0: config firewall policy 0: edit 15 0: set ssl-ssh-profile "SSL Certs-Block Untrusted\\Invalid" -651: end
Here are a few other things to try:
1. Can you use the CLI to edit a policy? You can use the above commands to see further error reported by the CLI
2. Can you use the GUI to create new Policy? if not, please also include CLI and httpsd debug message
3. Does this happen to any policy edit via the GUI? 4. Can you check if your interfaces are correctly upgraded?
5. Which FGT model are you using? if possible, can you share your full config with us? you can email me the config at thuynh@fortinet.com
Tri
bug(s):
1. can not add additional MACs for device object
2. device type: Windows Device?????
BTW,
device detection still is very very bad....
FWF60D x2 FWF60C x3 FGT80C rev.2 FGT200B-POE FAP220B x3 FAP221B x2
FSW224B x1
I have found BUG ID 0480176: "sslvpn crash signal 11 and Forticlient users disconnect" The solution is wait for firmware 6.0.1 that will be delivered on May 28, 2018
Hi, I´ve recently installed FortiOS 6.0 (v6.0.0 build0076 (GA)) in two FG´s (200E & 100E), and the "Web Rating Overrides" doesn´t work again. In this version, Fortigates ignores the Web Rating Overrides configuration.
Any solution please? Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.