Courseiva
Security Profiles →hardMultiple Choice

FortiSandbox Server Not Configured: Diagnose and Fix

An administrator integrates FortiGate with FortiSandbox for advanced threat detection. The FortiGate is configured to send files to FortiSandbox for analysis. Despite correct configuration, files are not being submitted. The administrator runs 'diagnose debug application fortisandbox -1' and sees 'no server configured'. What is the issue?

Quick Answer

The answer is that the FortiSandbox server IP address is not configured on the FortiGate. This is correct because the debug output “no server configured” explicitly indicates that the FortiGate has no IP address defined for the FortiSandbox appliance, even if other integration settings like scanning profiles or API keys appear present. On the Fortinet NSE 4 Network Security Professional exam, this scenario tests your understanding that FortiSandbox integration requires a two-step setup: enabling the feature under Security Fabric and, crucially, specifying the server’s IP address and credentials. A common trap is assuming that simply enabling the FortiSandbox feature or configuring file-filter profiles is sufficient, but without the server IP, the FortiGate cannot establish a connection to submit files. Remember the memory tip: “No IP, no trip” — if the server address is missing, files will never leave the FortiGate for analysis.

⚠ Common exam trap

Many exam-takers assume the issue is a firewall policy or license problem, but the debug output's exact wording 'no server configured' directly points to a missing server IP configuration, which is a common oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiSandbox server IP address is not configured on the FortiGate

The debug output 'no server configured' explicitly indicates that the FortiGate does not have a FortiSandbox server IP address defined in its configuration. Without the server IP configured under 'config system fortisandbox', the FortiGate cannot establish a connection or submit files, regardless of other settings. This is a prerequisite step before any file submission can occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The FortiSandbox license has expired

    Why it's wrong here

    An expired FortiSandbox licence blocks file submission, but it would not produce the 'no server configured' debug output; that message means no FortiSandbox server object is bound to the profile. Licensing is the right check when submissions fail with authentication or quota errors after the server is reachable.

  • ✗

    Firewall policies are blocking communication to the FortiSandbox server

    Why it's wrong here

    'No server configured' indicates the FortiSandbox server object or binding is absent, not a blocked path; policy denial would surface as connection failures, not this message. It is tempting because firewall policies do govern reachability, and checking them is correct when the server is configured yet unreachable.

  • ✓

    The FortiSandbox server IP address is not configured on the FortiGate

    Why this is correct

    The debug output "no server configured" directly indicates the FortiGate lacks the FortiSandbox appliance's IP address, so file submission cannot initiate. Without that address, the FortiGate has no destination to send files to, regardless of other settings. Configuring the FortiSandbox server IP under the relevant security fabric or sandbox settings resolves the failure.

  • ✗

    The antivirus profile is not configured to submit files to FortiSandbox

    Why it's wrong here

    The debug output names a missing server binding, so FortiGate has no FortiSandbox address to submit to; profile submission settings cannot compensate. It is tempting because antivirus profiles do control file submission, and that configuration is the correct fix when a server is bound but files are still withheld.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to integrate with FortiSandbox to analyze suspicious files detected by antivirus. The administrator configures the FortiSandbox settings under Security Fabric. However, files are not being sent to FortiSandbox. The antivirus profile is set to 'flow-based' inspection. What could be the reason?

medium
  • A.The antivirus profile is set to 'Monitor' instead of 'Block'.
  • B.The firewall policy is using NAT, which interferes with FortiSandbox connectivity.
  • C.The FortiGate does not have a valid FortiSandbox license.
  • ✓ D.Flow-based inspection does not support FortiSandbox integration; proxy-based inspection is required.
JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.