Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw2090
Honored Contributor

FortiManager deployment problems after FGT Upgrade to 7.0.14

I did the following:

 

- upgraded FMG to 7.0.11 while the FGT still were on 7.0.13 => everything still worked fine afterwards

- upgraded the FGT to 7.0.14 during the next night (scheduled) => since then FGT keep losing the connection to FMG when I deploy policy package or device config. Results in the deployment timing out after some time. 

During a TAC session it helped to reboot FMG (and perform fsck on it with that) and then retrieving config of FGT and then deploy it. After this deploying of policy package worked fine until now.

Now just deployed the device config only on a FGT and it got disconnected from FMG again...

 

However they come back after some time...

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
19 REPLIES 19
sw2090
Honored Contributor

and both certificate in FMG and CAs on FGT are Fortinet Factory so cannot be modified by the user.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

We narrowed that down with TAC. It looks like if it is mainly an issue with FGT100F on 7.0.14 and FMG >= 7.0.11. Even upgrading FMG to 7.2 did not prevent it from happening. Its still escalated to the developers and pending a bugfix.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

it narrowed down to be an issue that only (at least on our side) affects the FGT100 Series. The issue never ever occured on FGT60 or FGT300 we also have.

Also the FMG Developer team has narrowed that down to be an issue on the FGT side (it is because the FGTs CAs are the culprit) and handed it over the the FGT Developer team now...

Also I got a Firmware Image from the developers that does some more debugging to get them more information. We'll see. 

Will be on vacation until April 15th now but will keep you updated as Fortinet also has admitted that we are not their only customers that have this issue.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

this is still going on here. Meanwhile Fortinet TAC admittted that it is a FGT and not a FMG Issue and it affects 7.0,7.2 and also 7.4. Got this from an EMEA TAC FAZ/FMG Manager!

Our Issue also does not only affect us but also other customers. 

It has escalated to Management level and also the development teams.

We're still waiting for a fix.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
AEK

Thanks for sharing, @sw2090 

Has the bug id been published?

Any advice so far for those who have FMG and want to update FG from 7.0.13 to higher patch?

AEK
AEK
sw2090
Honored Contributor

unfortunately I haven't gotten any bug id yet. But my tickets are in state "pending bugfix" and have an "E" marker for escalation. 

The only adivice I coud currently give would be not to upgrade until this is fixed.

 

Btw. forgot to mention before: it got way worse with the last upgrade of FMG (v7.2.5). Since that my FGT remained offline and did not come back online even after downgrading FMG back to 7.2.4.

(but also affects FMG 7.0 - TAC upgraded our FMG to 7.2 some time during all this...)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

I meanwhile also assume it is not  a certificate issue as reported before. I saw a FGT throwing the exact same certificate error in FGFM debug log but the reason it did not come online in FMG was that the FGT IP in FMG was wrong in this single case.

I also have gotten an interim build of 7.0.14 for FGT100F that has more debugging capabilities. It even provides me with shell access to the os itself. But even that does not give me enough information to find the culprit.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

I have to admit that TAC did provide me the bug it but I've overseen it in the ticket :\

Here it is;

 

1004231 - 1460: After upgrading FGT from 7.0.13 to 7.0.14, start loosing FMG connections because of fatal unknown CA

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
AEK

Thanks for the update.

So you have the $1M FOS version (shell access). Try take full advantage of it :)

AEK
AEK
sw2090
Honored Contributor

yeah and I got it for free :)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors