202122 - Address Group Not Found on FortiGate
Agent error code #202122 indicates that the address group named on the knoc does not exist on the target FortiGate.
Common causes include:
- A typo in the address group name. Names are case-sensitive
- The group exists on a different FortiGate from the one targeted
- The group exists in a different VDOM
- The group was created but the change was never installed to the device
- The name refers to an address object rather than an address group
Steps to Resolve
Confirm the Group Exists
- On the FortiGate, go to Policy & Objects > Addresses
- Switch to the Address Groups tab
- Confirm a group with the configured name exists, matching case exactly
Confirm the VDOM
If the FortiGate has VDOMs enabled, address groups are per-VDOM. A group in root is not visible from another VDOM. Confirm the knoc targets the VDOM that holds the group.
Install Pending Changes
A group created in FortiManager exists there but not on the device until the change is installed.
- In FortiManager, go to Device Manager and check for pending changes on the device
- Install the policy package so the group reaches the FortiGate
Confirm It Is a Group, Not an Object
Knocknoc adds members to an address group. Pointing the knoc at a single address object produces this code. Create a group and add the object to it if needed.
Run the Knoc Validator
Open the knoc and run Validate. The agent lists the address groups it can see and suggests a value for the field.