Skip to content
Notifications
Clear all

Any gotchas in Fortinet's self-service sign-up?

34 Posts
33 Users
0 Reactions
15 Views
(@harpera)
Estimable Member
Joined: 2 months ago
Posts: 214
 

The SSL certificate error due to time skew is indeed a frequent first boot issue. Beyond the browser's rejection, it can also break the FortiGuard service activation, making the device appear to have connectivity issues when it's purely a TLS handshake failure.

Your point about the `/admin` path requiring an initial visit to the root is correct, but the underlying reason is often the browser's treatment of the self-signed certificate. The security exception is typically tied to the exact URL, so ` https://192.168.1.99` and ` https://192.168.1.99/admin` are seen as different origins. Clearing the HSTS policy for the IP can sometimes bypass that two step process.

The double email dispatch for the license is consistent. The first is an automated system notification, while the second is the actual mail queue with the attachment. The gap can extend to 30 minutes if their systems are under load, so waiting for both is necessary before declaring the process failed.


— Harper


   
ReplyQuote
(@devops_journeyman)
Reputable Member
Joined: 5 months ago
Posts: 216
 

Right, the time skew issue goes deeper than just the browser warning. If the FortiGuard connection fails during initial setup, it can silently block the license validation later on. The system won't tell you the license is rejected due to an expired cert, it just hangs.

I've had to manually set the date via the CLI console before even trying the web GUI, just to get a clean start. The command is `exec date YYYYMMDDHHMM.ss`, and syncing to your hypervisor's time is a good temporary fix until NTP kicks in.

Clearing the HSTS policy is a good trick, but it's another step that feels like we're working around the product instead of with it.



   
ReplyQuote
(@devops_barbarian)
Honorable Member
Joined: 5 months ago
Posts: 439
 

Setting the date via CLI is the only reliable fix. I've had the NTP service fail to start because the system time was so far off it broke the service's own certificate check.

The real issue is their reliance on FortiGuard for everything. If that initial handshake fails, half the features are silently disabled. You won't know until you try to update AV signatures and get a generic connection error.


Don't panic, have a rollback plan.


   
ReplyQuote
(@data_pipeline_guy)
Reputable Member
Joined: 6 months ago
Posts: 388
 

Been there. The admin path one still gets me, but my gripe is the hypervisor part they don't tell you. If you're on VMware, forget LSI Logic SAS for the disk. Use Paravirtual. The "official" compatibility list is wrong and your disk I/O will be garbage. Doubles your commit times.


SQL is enough


   
ReplyQuote
Page 3 / 3