AnsweredHot!SD WAN issue

Author
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
2019/07/14 05:42:43 (permalink)
0

SD WAN issue

I was trying to do SD WAN cofiguration in fortinet VM(6.0) in gns3 before going live in production. But i cant add members to SDWAN, it shows error FAILED DEPENDENCY. What could be the reason?. I also checked whether the interface adding is there in any policy. I can add one interface to SDWAN,when adding second one it shows failed dependency error.
#1
hubertzw
Gold Member
  • Total Posts : 192
  • Scores: 5
  • Reward points: 0
  • Joined: 2018/04/16 13:29:04
  • Status: offline
Re: SD WAN issue 2019/07/15 04:24:13 (permalink)
0
Check routing and firewall policies, VPN, etc.
#2
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
Re: SD WAN issue 2019/07/15 05:49:21 (permalink)
0
i checked that..interfaces are not linked in any of those sections(ipv4 policy,vpn,routing etc) Iam configuring it from scratch..
#3
Toshi Esumi
Expert Member
  • Total Posts : 1623
  • Scores: 137
  • Reward points: 0
  • Joined: 2014/11/06 09:56:42
  • Status: offline
Re: SD WAN issue 2019/07/15 09:05:17 (permalink)
0
Get in CLI and "show | grep -f INTERFACE_NAME"
If it doesn't show anything other than the interface config, you might need to reboot it.
#4
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
Re: SD WAN issue 2019/07/17 05:54:11 (permalink)
0
I also checked by rebooting, issue is still there.
 
post edited by jensthms - 2019/07/17 06:04:58

Attached Image(s)

#5
hubertzw
Gold Member
  • Total Posts : 192
  • Scores: 5
  • Reward points: 0
  • Joined: 2018/04/16 13:29:04
  • Status: offline
Re: SD WAN issue 2019/07/17 08:28:45 (permalink)
0
Try to save the settings without gateway IPs
#6
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
Re: SD WAN issue 2019/07/17 11:40:09 (permalink)
0
Checked without gateway..same error failed dependency.
#7
Dave Hall
Expert Member
  • Total Posts : 1458
  • Scores: 160
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: SD WAN issue 2019/07/17 13:34:39 (permalink) ☄ Helpfulby hubertzw 2019/07/17 16:21:38
5 (1)
Try diagnose sys cmdb refcnt show system.interface.name <interface name>

NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#8
emnoc
Expert Member
  • Total Posts : 5209
  • Scores: 339
  • Reward points: 0
  • Joined: 2008/03/20 13:30:33
  • Location: AUSTIN TX AREA
  • Status: offline
Re: SD WAN issue 2019/07/17 15:05:40 (permalink)
0
Like others mention you have something tied to the member. Policy, dhcp,prober,etc........This one problem in SDWAN, you should ALWAYS deploy the firewall with SDWAN and one member regardless if you foresee you adding a 2nd or 3rd member later on..
 
Ken Felix

PCNSE,  NSE , Forcepoint ,  StrongSwan Specialist
#9
hubertzw
Gold Member
  • Total Posts : 192
  • Scores: 5
  • Reward points: 0
  • Joined: 2018/04/16 13:29:04
  • Status: offline
Re: SD WAN issue 2019/07/17 16:16:43 (permalink)
0
emnoc
Like others mention you have something tied to the member. Policy, dhcp,prober,etc........This one problem in SDWAN, you should ALWAYS deploy the firewall with SDWAN and one member regardless if you foresee you adding a 2nd or 3rd member later on..



Interesting, is there any official recommendation or good practice from Fortinet?
#10
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
Re: SD WAN issue 2019/07/18 01:12:16 (permalink)
0
I also checked whether it is referenced anywhere but cant find anything.

Attached Image(s)

#11
Leen
New Member
  • Total Posts : 12
  • Scores: 2
  • Reward points: 0
  • Joined: 2007/05/08 05:48:09
  • Status: offline
Re: SD WAN issue 2019/07/18 04:49:34 (permalink)
0
backup your fortigate and use a text editor to scan through the backup text file.
items to look for
- port 9 HA enabled
- ntp setup on interface
- user that has the interface on it's gui defined
#12
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
Re: SD WAN issue 2019/07/18 06:38:25 (permalink)
0
I also checked the above things. But same issue. Attaching the config file below.
#13
Dave Hall
Expert Member
  • Total Posts : 1458
  • Scores: 160
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: SD WAN issue 2019/07/18 07:43:43 (permalink) ☼ Best Answerby jensthms 2019/07/18 09:14:22
5 (1)
Possible suggestion:
Add port2 to the SDWAN by itself and save that cfg then load an unencrypted backup copy into a text editor and add port3 to the SDWAN members.  Load that back into the fgt vm - try to monitor the console output while it is booting and/or perform diagnose debug config-error-log read at the CLI after you gain access the console.
 
The above method is ugly in my opinion, but may work.  I recall an old bug from the 4.3/5.0 days where just doing something in the GUI causes certain interfaces to "become dependence".  That said, as a suggestion it maybe remotely possible that this problem is browser related - try using a different browser.
 
 
 

NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#14
jensthms
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/11/03 00:07:10
  • Status: offline
Re: SD WAN issue 2019/07/18 09:19:15 (permalink)
0
Thank you Dave, it worked at last . Followed your steps and also used chrome this time, now settings got saved. Earlier i was using firefox. Thank you guys for all your suggestions.
#15
Jump to:
© 2019 APG vNext Commercial Version 5.5