202120 - ADOM Not Found on FortiManager
Agent error code #202120 indicates that the ADOM configured on the knoc does not exist on FortiManager, or the administrator the agent authenticates as cannot see it.
Common causes include:
- A typo in the ADOM field of the Knocknoc backend configuration. ADOM names are case-sensitive
- The administrator account is restricted to a different set of ADOMs
- The ADOM was renamed or deleted after the knoc was configured
- FortiManager is not running in ADOM mode, so the name has no meaning
Steps to Resolve
Confirm the ADOM Name
- In FortiManager, open the ADOM selector at the top of the interface
- Note the exact name of the ADOM holding the target devices
- Enter it in the ADOM field of the Knocknoc backend configuration, matching case exactly
The default ADOM on a FortiManager that has not been subdivided is usually root.
Confirm the Administrator's ADOM Access
- In FortiManager, go to System Settings > Administrators
- Open the account Knocknoc authenticates as
- Check its Administrative Domain setting. An account limited to specific ADOMs cannot see the others at all
Confirm ADOM Mode Is Enabled
- Go to System Settings > Advanced > Advanced Settings
- Check whether ADOM mode is enabled
- With ADOMs disabled, use
rootas the ADOM name
Run the Knoc Validator
The Fortinet backend can check its own configuration. Open the knoc and run Validate to have the agent list the ADOMs it can actually see, with a suggested value for the field.