Description This article describes an issue where web filter or any
other security profile is not applied to TLS traffic for proxy-based
policies Scope FortiGate. Solution The solution is to revert the profile
protocol options to the default and avoi...
Description This article describes the hidden command 'diagnose firewall
iprope flush' and how to re-populate the policy ruleset in case the
command was accidentally executed and all firewall rules were deleted.
This is important information that sho...
Description This article describes how to detect and resolve a WAD
memory leak that occurs with 'user-info' type processes. Scope FortiOS
7.0.8, 7.0.9. Solution The WAD process suffers a memory leak on FortiOS
7.0.8 and 7.0.9 in WAD processes with th...
Description This article describes how to detect and resolve a wad
memory leak in object ssl.fts.str.fstr_buffer_bytes. Scope FortiOS
7.0.8, 7.0.9. Solution The wad process has a memory leak on FortiOS
7.0.8 and 7.0.9 in the object ssl.fts.str.fstr_b...
Description This article describes that since FortiProxy version 7.0,
the FQDNs configured in the GUI tab 'URL match' or in the CLI option '#
config web-proxy url-match' will match top-down. This means that the
order in which the FDQNs are added will...
Hello, > A filter driver that has a low numerical altitude is loaded
into the I/O stack below a filter driver that has a higher numerical
value.source:
https://learn.microsoft.com/en-us/windows-hardware/drivers/ifs/load-order-groups-and-altitudes-for...
Hello, The official EOL list for all hardware and software releases can
be found in the support portal after logging in.
https://support.fortinet.com/Information/ProductLifeCycle.aspx Regards
Hello, It should be mentioned that the "diagnose firewall iprope flush"
command is a hidden command for reasons. It will wipe _all_ policies
from the fortigate and leave the iprope table empty. The FortigGate will
not have any rules anymore, neither ...
Hello, > The logs tells the block is because the webfilter is
categorizing whatsapp web as Social Networking. The FortiGuard Web
Filter Lookup categorizes it as Web Chat Per log file the interesting
parts aredstip=157.240.222.60 ratemethod=iphostname...
Hello, > 1. is it possible to use IPS with certificate inspection (and
not deep inspection) Yes. > and if so what im I losing using just cert
inspection. As mentioned by aahmadzada the FortiGate might not be able
to scan all content if it is TLS encr...