| Description | This article describes the behavior observed when an external connector (IP Address Threat Feed) fails to fetch data when the server-identity-checks option is enabled in the policy configuration. |
| Scope | FortiOS v7.4, FortiOS v7.6. |
| Solution |
An issue has been observed where FortiGate is unable to fetch data from the configured external connector when server-identity-checks is set to basic or full, particularly when:
config firewall address
config firewall policy
This behavior occurs because the server certificate’s identity could not be verified against the FQDN specified in the external resource configuration. When server-identity-check is set to basic or full, the connection to the external feed fails, and the FortiGate logs the following SSL error.
diagnose debug application forticron -1 diagnose debug console timestamp enable diagnose debug enable 2025-10-14 13:26:51 __update_ext()-282: Updating EXT 'Test_Block_List' with HTTP
This issue has been fixed in the following builds:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.