FortiSandbox Server Not Configured: Diagnose and Fix
An administrator integrates FortiGate with FortiSandbox for advanced threat detection. The FortiGate is configured to send files to FortiSandbox for analysis. Despite correct configuration, files are not being submitted. The administrator runs 'diagnose debug application fortisandbox -1' and sees 'no server configured'. What is the issue?
Quick Answer
The answer is that the FortiSandbox server IP address is not configured on the FortiGate. This is correct because the debug output “no server configured” explicitly indicates that the FortiGate has no IP address defined for the FortiSandbox appliance, even if other integration settings like scanning profiles or API keys appear present. On the Fortinet NSE 4 Network Security Professional exam, this scenario tests your understanding that FortiSandbox integration requires a two-step setup: enabling the feature under Security Fabric and, crucially, specifying the server’s IP address and credentials. A common trap is assuming that simply enabling the FortiSandbox feature or configuring file-filter profiles is sufficient, but without the server IP, the FortiGate cannot establish a connection to submit files. Remember the memory tip: “No IP, no trip” — if the server address is missing, files will never leave the FortiGate for analysis.
⚠ Common exam trap
Many exam-takers assume the issue is a firewall policy or license problem, but the debug output's exact wording 'no server configured' directly points to a missing server IP configuration, which is a common oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiSandbox server IP address is not configured on the FortiGate
The debug output 'no server configured' explicitly indicates that the FortiGate does not have a FortiSandbox server IP address defined in its configuration. Without the server IP configured under 'config system fortisandbox', the FortiGate cannot establish a connection or submit files, regardless of other settings. This is a prerequisite step before any file submission can occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiSandbox license has expired
Why it's wrong here
An expired license might show a different error, not 'no server configured'.
- ✗
Firewall policies are blocking communication to the FortiSandbox server
Why it's wrong here
While possible, the debug output specifically says 'no server configured', which is a configuration issue, not connectivity.
- ✓
The FortiSandbox server IP address is not configured on the FortiGate
Why this is correct
The debug message clearly states 'no server configured', meaning the FortiSandbox server definition is missing.
- ✗
The antivirus profile is not configured to submit files to FortiSandbox
Why it's wrong here
The antivirus profile has a 'fortisandbox' option, but without a server, it won't work. However, the debug indicates server not configured, not profile issue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator wants to integrate with FortiSandbox to analyze suspicious files detected by antivirus. The administrator configures the FortiSandbox settings under Security Fabric. However, files are not being sent to FortiSandbox. The antivirus profile is set to 'flow-based' inspection. What could be the reason?
medium- A.The antivirus profile is set to 'Monitor' instead of 'Block'.
- B.The firewall policy is using NAT, which interferes with FortiSandbox connectivity.
- C.The FortiGate does not have a valid FortiSandbox license.
- ✓ D.Flow-based inspection does not support FortiSandbox integration; proxy-based inspection is required.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.