Courseiva
Security ProfileshardMultiple ChoiceObjective-mapped

FortiSandbox Server Not Configured: Diagnose and Fix

An administrator integrates FortiGate with FortiSandbox for advanced threat detection. The FortiGate is configured to send files to FortiSandbox for analysis. Despite correct configuration, files are not being submitted. The administrator runs 'diagnose debug application fortisandbox -1' and sees 'no server configured'. What is the issue?

Quick Answer

The answer is that the FortiSandbox server IP address is not configured on the FortiGate. This is correct because the debug output “no server configured” explicitly indicates that the FortiGate has no IP address defined for the FortiSandbox appliance, even if other integration settings like scanning profiles or API keys appear present. On the Fortinet NSE 4 Network Security Professional exam, this scenario tests your understanding that FortiSandbox integration requires a two-step setup: enabling the feature under Security Fabric and, crucially, specifying the server’s IP address and credentials. A common trap is assuming that simply enabling the FortiSandbox feature or configuring file-filter profiles is sufficient, but without the server IP, the FortiGate cannot establish a connection to submit files. Remember the memory tip: “No IP, no trip” — if the server address is missing, files will never leave the FortiGate for analysis.

⚠ Common exam trap

Many exam-takers assume the issue is a firewall policy or license problem, but the debug output's exact wording 'no server configured' directly points to a missing server IP configuration, which is a common oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The FortiSandbox server IP address is not configured on the FortiGate

The debug output 'no server configured' explicitly indicates that the FortiGate does not have a FortiSandbox server IP address defined in its configuration. Without the server IP configured under 'config system fortisandbox', the FortiGate cannot establish a connection or submit files, regardless of other settings. This is a prerequisite step before any file submission can occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The FortiSandbox license has expired

    Why it's wrong here

    An expired license might show a different error, not 'no server configured'.

  • Firewall policies are blocking communication to the FortiSandbox server

    Why it's wrong here

    While possible, the debug output specifically says 'no server configured', which is a configuration issue, not connectivity.

  • The FortiSandbox server IP address is not configured on the FortiGate

    Why this is correct

    The debug message clearly states 'no server configured', meaning the FortiSandbox server definition is missing.

  • The antivirus profile is not configured to submit files to FortiSandbox

    Why it's wrong here

    The antivirus profile has a 'fortisandbox' option, but without a server, it won't work. However, the debug indicates server not configured, not profile issue.

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to integrate with FortiSandbox to analyze suspicious files detected by antivirus. The administrator configures the FortiSandbox settings under Security Fabric. However, files are not being sent to FortiSandbox. The antivirus profile is set to 'flow-based' inspection. What could be the reason?

medium
  • A.The antivirus profile is set to 'Monitor' instead of 'Block'.
  • B.The firewall policy is using NAT, which interferes with FortiSandbox connectivity.
  • C.The FortiGate does not have a valid FortiSandbox license.
  • D.Flow-based inspection does not support FortiSandbox integration; proxy-based inspection is required.
JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.