Fortinet white logo
Fortinet white logo

Examples

Troubleshooting

Troubleshooting

Use the following FortiPAM CLI commands to check the connection status.

  1. In the CLI console on the FortiPAM server, use the following commands to show the reverse connections:
     diagnose debug enable
     diagnose test application wad 21600 
     Set diagnosis process: type=rev-connector index=0 pid=1237
     dignose test application wad 622
     cert CAS
     wss=0x7f2315b33930 cert->name=fortipam_cert5.pem
     SSL CA store: Opened
      [1] C = CA, ST = BC, L = Burnaby, O = Fortinet, OU = FortiPAM, CN = QA
      remote client connections
      1, src_addr=207.102.138.19:53900, dst_addr=10.0.1.15:8443, ctrl/ssled=1/1, gwy=PAM94-RVS-GW-Burnaby-Lab, cn=fortipam_gw3, ka_tm=1, ka/req/rsp/pending/ka_left=1/121/121/0/6
      2, src_addr=204.101.161.19:7608, dst_addr=10.0.1.15:8443, ctrl/ssled=1/1, gwy=FGT131-RVS-GW-Burnaby-Lab, cn=fortipam_gw5, ka_tm=1, ka/req/rsp/pending/ka_left=1/120/120/0/6				 
      3, src_addr=204.101.161.19:58632, dst_addr=10.0.1.15:8443, ctrl/ssled=1/1, gwy=PAM97-RVS-GW-Burnaby-Lab, cn=fortipam_gw4, ka_tm=1, ka/req/rsp/pending/ka_left=1/100/100/0/6				
      rmt stats: err_max_len=14, err_type=14, err_internal=0, data-act=18, ctrl_failure=0, dev_id_err=0	
  2. On the reverse gateway (FortiPAM), use the following commands:
     diagnose de enable
     diagnose test application wad 21600
     Set diagnosis process: type=rev-connector index=0 pid=1664
     diagnose test application wad 623
     1 port=0x7f76b9c56600, state=3, act=1, reconn_tm=0 server=pam_gcp159, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/103/103/0/6)src=10.59.112.97:58632, dst=34.95.41.159:8443
     2 port=0x7f76b9c56258, state=3, act=1, reconn_tm=0 server=pam_gcp, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/103/103/0/6)src=10.59.112.97:35460, dst=34.118.146.233:8443
     Total reconnects=0
  3. On the reverse gateway (FortiGate), use the following commands:
     diagnose de enable 
     diagnose test application wad 21300
     Set diagnosis process: type=reverse-connector index=0 pid=2685
     diagnose test application wad 622
     1 port=0x7ffbe18dc4c8, state=3, act=1, reconn_tm=0 server=pam78, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/22622/22598/0/2)src=10.59.112.131:2672, dst=10.59.112.133:8443
     2 port=0x7ffbe18dc890, state=3, act=1, reconn_tm=0 server=gcp159, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/8709/8707/0/4)src=10.59.112.131:7608, dst=34.95.41.159:8443				 
     Total reconnects=29

Troubleshooting

Troubleshooting

Use the following FortiPAM CLI commands to check the connection status.

  1. In the CLI console on the FortiPAM server, use the following commands to show the reverse connections:
     diagnose debug enable
     diagnose test application wad 21600 
     Set diagnosis process: type=rev-connector index=0 pid=1237
     dignose test application wad 622
     cert CAS
     wss=0x7f2315b33930 cert->name=fortipam_cert5.pem
     SSL CA store: Opened
      [1] C = CA, ST = BC, L = Burnaby, O = Fortinet, OU = FortiPAM, CN = QA
      remote client connections
      1, src_addr=207.102.138.19:53900, dst_addr=10.0.1.15:8443, ctrl/ssled=1/1, gwy=PAM94-RVS-GW-Burnaby-Lab, cn=fortipam_gw3, ka_tm=1, ka/req/rsp/pending/ka_left=1/121/121/0/6
      2, src_addr=204.101.161.19:7608, dst_addr=10.0.1.15:8443, ctrl/ssled=1/1, gwy=FGT131-RVS-GW-Burnaby-Lab, cn=fortipam_gw5, ka_tm=1, ka/req/rsp/pending/ka_left=1/120/120/0/6				 
      3, src_addr=204.101.161.19:58632, dst_addr=10.0.1.15:8443, ctrl/ssled=1/1, gwy=PAM97-RVS-GW-Burnaby-Lab, cn=fortipam_gw4, ka_tm=1, ka/req/rsp/pending/ka_left=1/100/100/0/6				
      rmt stats: err_max_len=14, err_type=14, err_internal=0, data-act=18, ctrl_failure=0, dev_id_err=0	
  2. On the reverse gateway (FortiPAM), use the following commands:
     diagnose de enable
     diagnose test application wad 21600
     Set diagnosis process: type=rev-connector index=0 pid=1664
     diagnose test application wad 623
     1 port=0x7f76b9c56600, state=3, act=1, reconn_tm=0 server=pam_gcp159, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/103/103/0/6)src=10.59.112.97:58632, dst=34.95.41.159:8443
     2 port=0x7f76b9c56258, state=3, act=1, reconn_tm=0 server=pam_gcp, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/103/103/0/6)src=10.59.112.97:35460, dst=34.118.146.233:8443
     Total reconnects=0
  3. On the reverse gateway (FortiGate), use the following commands:
     diagnose de enable 
     diagnose test application wad 21300
     Set diagnosis process: type=reverse-connector index=0 pid=2685
     diagnose test application wad 622
     1 port=0x7ffbe18dc4c8, state=3, act=1, reconn_tm=0 server=pam78, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/22622/22598/0/2)src=10.59.112.131:2672, dst=10.59.112.133:8443
     2 port=0x7ffbe18dc890, state=3, act=1, reconn_tm=0 server=gcp159, n_fails=0, reconn_tm_cnt=0, ka_tm=1, ka/req/resp/pending/tm_left(1/8709/8707/0/4)src=10.59.112.131:7608, dst=34.95.41.159:8443				 
     Total reconnects=29