Re: SNMP interface index conflict after FortiManager upgrade from 5.4 to 5.6
I ran into this when upgrading FMG from 5.4.2 to 5.4.3. TAC was unable to reproduce, and as far as I know no bug report issued. I was able to work-around the issue by
1) Retrieve the configs for the firewalls inside FMG
2) Perform a re-install against all VDOMs on those firewalls
3) Will probably need to re-install on other firewalls as well, since FMG wants to have all FGTs use the same SNMP index for all interfaces of the same name.
That re-synced the SNMP index IDs to a value that worked on both sides. I had to do this for a bunch of firewalls, but after doing it once, it did solve the issue permanently for that firewall. We now run FMG 5.6.3 and have not seen the issue recur.
Ps. What version of 5.4 did you upgrade from? Sounds like you basically skipped over the 5.4 patch release where this issue occurred, and are running into it now. TAC informed me in 5.4.3 there is intended change in behavior to sync SNMP index IDs, and typically it should be adding 100 to the existing value. E.g, if local FGT had index ID of 11 for "port1" that FMG would want to change that to an index ID of 111 to avoid conflict.