Courseiva

Why FortiGate Shows 'Connection Refused' for FortiAnalyzer

A FortiGate administrator needs to integrate with FortiAnalyzer for centralized logging. After configuring the FortiAnalyzer IP and enabling logging, the FortiGate shows 'connection status: disconnected'. What is the most likely cause?

⚠ Common exam trap

Candidates often assume a configuration or protocol mismatch (like HTTPS or firmware version) is the cause, when the fundamental issue is simple network reachability—FortiGate cannot connect to FortiAnalyzer without a valid route.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate does not have a route to the FortiAnalyzer.

The most likely cause is that the FortiGate does not have a route to the FortiAnalyzer. Even with the correct IP and logging enabled, the FortiGate must be able to reach the FortiAnalyzer over the network; without a valid route, the TCP connection (typically on port 514 for syslog or port 443/541 for FortiGate-FortiAnalyzer protocol) will fail, resulting in a 'disconnected' status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiGate is in transparent mode.

    Why it's wrong here

    Transparent mode does not prevent a FortiGate from sending logs. In Layer 2 mode, the FortiGate still has a management IP and can route its own management traffic, including log uploads, via a default gateway. Log forwarding failures in transparent mode would more likely stem from missing routes or firewall policies affecting the FortiGate's management path, so this is not the direct cause.

  • ✗

    The FortiAnalyzer firmware version is newer than the FortiGate's.

    Why it's wrong here

    A FortiAnalyzer running a newer firmware than the FortiGate is generally compatible because FortiAnalyzer is designed to accept logs from multiple FortiGate versions. Firmware incompatibility problems typically occur when the FortiGate is newer than the FortiAnalyzer, not the other way around. Thus this alone would not prevent the integration.

  • ✗

    The administrator forgot to enable HTTPS for log upload.

    Why it's wrong here

    The FortiGate-to-FortiAnalyzer connection can use either syslog (UDP/TCP 514) or the native FortiAnalyzer protocol over HTTPS. If HTTPS is not enabled, the connection can still use syslog to forward logs. Forgetting to enable HTTPS would only block the encrypted upload method, but it would not stop all log delivery, so it cannot be the sole cause.

  • ✓

    The FortiGate does not have a route to the FortiAnalyzer.

    Why this is correct

    Without a valid matching route to the FortiAnalyzer's IP address, the FortiGate cannot establish the TCP/HTTPS connection needed for log forwarding. The packet will be dropped, and the FortiGate will report communication failures or timeouts. This is a direct and necessary condition for successful integration, making it the correct explanation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.