202003 - Fortinet TLS/SSL Certificate Error
Uploading..Agent error code #202003 indicates that the agent could not establish a secure connection to the Fortinet device because of a TLS/SSL certificate problem. The connection was rejected before any authentication or API request could take place.
This error is distinct from connection failures (#202000), which indicate the device is not reachable at all. Error #202003 means the device is reachable but the TLS handshake failed due to a certificate issue.
Common causes include:
Steps to Resolve
Enable the Insecure Option (Self-Signed Certificates)
If the Fortinet device uses a self-signed certificate or a certificate from an untrusted CA:
This tells the agent to skip certificate verification. This is common in lab environments and internal deployments where FortiGate or FortiManager uses the factory-default self-signed certificate.
Verify the Certificate (Trusted CA)
If you expect the device to have a valid certificate from a trusted CA:
Install the CA Certificate on the Agent Host
If the device uses a certificate from an internal or private CA:
Still Having Issues?
We can help you out, contact us at support@knocknoc.io.