This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Fortigate 200D Active Response Operation Error

getting the active response operation error when trying to block IP's from within LEM.  its configured default with the ssh and user name and password i have confirmed is working and correct with putty.  the firewall is integrated using the other fortigate connector for logging.  however the block ip feature is particularly appealing to us.  there are 2 tty settings in the connector settings which one should i be using?  i am trying the default tty0 with no luck and getting:

com.trigeo.core.tools.toolcontroller.session.sessionexception: failed to open tool SSHTool malformed tool argument on open operation: ..... connection refused.

any help is greatly appreciated.

thanks!

PS. see attached.

  • That TTY field is only relevant if you're making a serial connection.  Assuming you have SSH selected, it shouldn't be an issue.  What you may need to do is trigger the action, then run a debug on the LEM and involve Support.