Skip to main content

202122 - Address Group Not Found on FortiGate

Uploading...Agent error code #202122 indicates that the address group named on the knoc does not exist on the target FortiGate.

Common causes include:

    A typo in the address group name. Names are case-sensitive The group exists on a different FortiGate from the one targeted The group exists in a different VDOM The group was created but the change was never installed to the device The name refers to an address object rather than an address group

    Steps to Resolve

    Confirm the Group Exists

      On the FortiGate, go to Policy & Objects > Addresses Switch to the Address Groups tab Confirm a group with the configured name exists, matching case exactly

      Confirm the VDOM

      If the FortiGate has VDOMs enabled, address groups are per-VDOM. A group in root is not visible from another VDOM. Confirm the knoc targets the VDOM that holds the group.

      Install Pending Changes

      A group created in FortiManager exists there but not on the device until the change is installed.

        In FortiManager, go to Device Manager and check for pending changes on the device Install the policy package so the group reaches the FortiGate

        Confirm It Is a Group, Not an Object

        Knocknoc adds members to an address group. Pointing the knoc at a single address object produces this code. Create a group and add the object to it if needed.

        Run the Knoc Validator

        Open the knoc and run Validate. The agent lists the address groups it can see and suggests a value for the field.