Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kruzpe
New Contributor

Device level settings changed

Hi everyone.

I have been working with fortimanager for a few days, right now I have a problem when a try to send the policy packages to the fortigates.

The problem is that one of the interface´s settings  that I´ve configured is different between what the fortiManager tries to send and I dont now why.

 

 

1 Solution
saifin
New Contributor II

Hi,

 

I believe you have a config conflict in interface mapping.

I can help you here if you could let me know, where exactly the error comes in?

While trying to synchronize the policy packages from fortimanager to remote fortigate, could you see any error such as "zone validation failed"?

 If possible please share the screenshot or let me exactly know at what stage the error occurs.

Also I would like to know the fortigate and and fortimanager version as well.

 

Thanks,

Saifin Thomas

Regards,

Saifin Thomas

View solution in original post

Regards, Saifin Thomas
4 REPLIES 4
saifin
New Contributor II

Hi,

 

I believe you have a config conflict in interface mapping.

I can help you here if you could let me know, where exactly the error comes in?

While trying to synchronize the policy packages from fortimanager to remote fortigate, could you see any error such as "zone validation failed"?

 If possible please share the screenshot or let me exactly know at what stage the error occurs.

Also I would like to know the fortigate and and fortimanager version as well.

 

Thanks,

Saifin Thomas

Regards,

Saifin Thomas

Regards, Saifin Thomas
Kruzpe
New Contributor

There is not an error actually.

 

The device level settings and the config status remains in "sync" state, the problem comes when I modified the policy package and try to send to the fortigate.

 

This is what i have in the interface settings.

Settings interface

 

This is what the FortiManager tries to send, the FortiManager always modify the interface´s settings named "Tienda" changed the address range for all managed devices.

Install preview

 

FrotiManager: 6.2.2

Fortigates: 6.2.2

saifin
New Contributor II

Hi,

 

I understood that, your fortimanager is trying to push wrong config to your remote fortigate! Correct me if i am wrong.

In this case, Please do retrieve your fortigate configuration to fortimanager device database and then import those configs to ADOM database. If so, your fortimanager database will be updated with fortigate configurations and it won't try to push the config to fortigate again.

This happens when fortimanager identifies any config changes in remote fortigate during the checksum validation.

 

**Please do post here if you have any concerns regarding steps which need to be followed to achieve this.**

 

 

 

Thanks,

Saifin Thomas

Regards,

Saifin Thomas

Regards, Saifin Thomas
Kruzpe
New Contributor

Hi.

 

This is what I did.

1.- First I did a retrieve

2.- then import the settings from the fortigate to the fortimanager

 

but keep trying to send the same wrong configuration

 

I also made modifications directly on the fortigate but  fortimanager does not respect the changes m...

 

I don't know if I'm importing the settings correctly but if I look at the database view the configurations are good.

[ul]
  • Image1
  • Image2[/ul]

    Thanks

     

  • Labels
    Top Kudoed Authors