Troubleshooting
Problem
Symptom
Can not delete a static table entry
Command fail. Return code -61
Cause
As part of a certificate bundled, update FortiGates can receive update for existing predefined certificates. In some cases, the certificate uses a new name, which ends up being considered 'new configuration' on the Firewalls.
This configuration entry cannot be deleted by an admin user.
As FortiGate is managed by FortiManager, the FortiGate attempts to notify FortiManager of this configuration changes by using 'auto-update'. Unfortunately 'auto-update' option is disabled on target FortiManager so FortiGate fails on that notification attempt.
If the FortiManager does not receive these updates, customer not only sees the FortiGate show up on the FortiManager as out-of-sync. They also observed that FortiManager attempts to delete the new certificate during the next installation attempt.
Diagnosing The Problem
# get system admin setting
Resolving The Problem
# config system admin setting
set auto-update enable
end
Related Information
Document Location
Worldwide
Product Synonym
FortiGate
FortiManager
Fortigate
Was this topic helpful?
Document Information
More support for:
IBM Support Services for Multivendor Network and Security
Component:
IBM Support Services for Multivendor Network and Security->Fortinet
Software version:
All Version(s)
Document number:
6457893
Modified date:
02 June 2021
UID
ibm16457893