Description This article explains how to block access to some Google
accounts and services while allowing access to accounts in the domains
in the exception list. Note:The device should be in 'Proxy-based'
Inspection mode. SSL (Deep) Inspection is Ma...
Description This article describes how to check the Internet Service
Database for specific IP addresses.Solution Below is the command that
can be used to search ISDB for specific IP addresses: diagnose
internet-service match Example: diagnose
inte...
DescriptionThis article describes how to configure per-VDOM
administrator accounts to only allow administrative access to specific
VDOMs. For example per-VDOM administrators will allow both Company A and
Company B to manage their respective VDOMs wit...
DescriptionThis article describes how in FortiOS v6 onwards security
Profiles can be configured globally across multiple VDOMs, some or all
profiles may be commonly-shared across VDOMSSolutionGlobal profiles are
configured under Global > Security Pro...
Hi NGG You can run debug commands on both FGT and check the traffic flow
on src and dst fortigate devices diag debug reset diag debug en diag
debug console timestamp enable diag debug flow filter clear diag debug
flow filter addr diag debug flow filt...
Hi Ydaew Can you configure your 3389 rule and then run below commands on
FGT for 443 traffic and share: Putty 1: di de reset di de di diag debug
console timestamp enable diag debug flow filter clear diag debug flow
filter addr X.X.X.X <<------[Replac...
Hi Beeradmin Great that you found and fix the issue. Below is the link
you can keep handy for IPSEC troubleshooting in case you need anytime in
future
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Troubleshooting-IPsec-VPNs/ta-p/195955
Th...
Hi Ydaew Please share screenshot of the VIP configured for server A and
server B traffic on FGT Just to confirm the requirement, you want the
traffic hitting FW for External IP , port 3389 should be forwarded to
server B you want the traffic hitting ...
Hi Xenitel Let us know if you are using HA mgmt interface to access the
device or some other way?If HA mgmt interface, you need reserved mgmt
interface IP to access both
devicehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Reserved-Mana...