Troubleshooting Tip: FGCP Active-Active Certificate + Proxy inspection + UTM access issue
| Description | This article explains the reason for having issues accessing some HTTPS websites when FortiGate is deployed in FGCP Active-Active mode on firmware v7.4 onward.
When performing WAD debug on the secondary unit (refer to this KB article Technical Tip: Using the 'diagnose wad debug' command to troubleshoot Explicit Web Proxy related issues on WAD debugging), the following error would be observed:
This indicates that HTTPS traffic is load-balanced to the secondary unit and CIC check failed because unable to reach internet via heartbeat link. The issue is still under investigation. |
| Scope | FortiGate. |
| Solution | The following options can be used to work around the issue:
|
