Why FortiGate Shows 'Connection Refused' for FortiAnalyzer
A FortiGate administrator needs to integrate with FortiAnalyzer for centralized logging. After configuring the FortiAnalyzer IP and enabling logging, the FortiGate shows 'connection status: disconnected'. What is the most likely cause?
⚠ Common exam trap
Candidates often assume a configuration or protocol mismatch (like HTTPS or firmware version) is the cause, when the fundamental issue is simple network reachability—FortiGate cannot connect to FortiAnalyzer without a valid route.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate does not have a route to the FortiAnalyzer.
The most likely cause is that the FortiGate does not have a route to the FortiAnalyzer. Even with the correct IP and logging enabled, the FortiGate must be able to reach the FortiAnalyzer over the network; without a valid route, the TCP connection (typically on port 514 for syslog or port 443/541 for FortiGate-FortiAnalyzer protocol) will fail, resulting in a 'disconnected' status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiGate is in transparent mode.
Why it's wrong here
Transparent mode does not prevent a FortiGate from sending logs. In Layer 2 mode, the FortiGate still has a management IP and can route its own management traffic, including log uploads, via a default gateway. Log forwarding failures in transparent mode would more likely stem from missing routes or firewall policies affecting the FortiGate's management path, so this is not the direct cause.
- ✗
The FortiAnalyzer firmware version is newer than the FortiGate's.
Why it's wrong here
A FortiAnalyzer running a newer firmware than the FortiGate is generally compatible because FortiAnalyzer is designed to accept logs from multiple FortiGate versions. Firmware incompatibility problems typically occur when the FortiGate is newer than the FortiAnalyzer, not the other way around. Thus this alone would not prevent the integration.
- ✗
The administrator forgot to enable HTTPS for log upload.
Why it's wrong here
The FortiGate-to-FortiAnalyzer connection can use either syslog (UDP/TCP 514) or the native FortiAnalyzer protocol over HTTPS. If HTTPS is not enabled, the connection can still use syslog to forward logs. Forgetting to enable HTTPS would only block the encrypted upload method, but it would not stop all log delivery, so it cannot be the sole cause.
- ✓
The FortiGate does not have a route to the FortiAnalyzer.
Why this is correct
Without a valid matching route to the FortiAnalyzer's IP address, the FortiGate cannot establish the TCP/HTTPS connection needed for log forwarding. The packet will be dropped, and the FortiGate will report communication failures or timeouts. This is a direct and necessary condition for successful integration, making it the correct explanation.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.