FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Adam_Shortt_FTNT
Staff & Editor
Staff & Editor
Article Id 357812
Description This article describes items that can be resolved without involving TAC.
Scope FortiGate.
Solution

Fortinet's Technical Assistance Center (TAC) is always ready and willing to assist users in need. However, some tasks are considered routine administrative duties and should first be attempted by a qualified administrator before engaging TAC, as often, these issues can be resolved faster using available documentation.

 

It is important to note that the following activities may require TAC support after initial actions are performed by the firewall administrator. Routine administrative duties that an administrator should be able to perform unassisted initially:

 

  1. New deployments, as well as network design requests. Administrators must attempt to set up the feature/environment beforehand.
    • TAC does not design/implement new network topologies on behalf of users (i.e., it is a 'break/fix' oriented team that resolves individual issues within existing environments).
    • If more in-depth technical consulting services are required (i.e., having a designated engineer assigned to design/deploy/optimize new network topologies), then consider engaging the services of the Fortinet Professional Services team (see also: FortiCare Professional Services).
  2. Firmware upgrades: Upgrade path, release notes (v7.6, v7.4, v7.2), Technical Tip: How to upgrade FortiGate firmware, Technical Tip: FortiGate HA upgrade procedure and the status during the upgrade

  3. Technical Tip: RMA: HQIP test (with built-in FortiOS diagnostic commands)

  4. Conserve mode: Technical Tip: Free up memory to avoid conserve mode, Technical Tip: Automation stitch for conserve mode
  5. Technical Tip: Procedure for HA manual synchronization

  6. Technical Tip: Correcting an out-of-sync HA cluster by modifying the primary unit configuration file...

  7. Technical Tip: FortiGate Initial Configuration

  8. Technical Tip: How to configure Whitelist firewall policy to exempt select hosts from scanning.

  9. Basic connectivity Troubleshooting: Troubleshooting Tip: First steps to troubleshoot connectivity problems to or through a FortiGate wit...

  10. Basic SSL VPN Troubleshooting: Troubleshooting Tip: Common SSL VPN problems and their solution
  11. Connection Troubleshooting: Troubleshooting Tip: SSL VPN Troubleshooting
  12. SSL VPN is no longer Available on 7.6.3. The process for migration to IPsec VPN is detailed in the migration guide
  13. Basic IPsec Troubleshooting: Troubleshooting Tip: Troubleshooting IPsec Site-to-Site Tunnel Connectivity

  14. Basic authentication troubleshooting Troubleshooting Tip: FortiGate LDAP troubleshooting and debug logs created by fnbamd, Troubleshooting Tip: RADIUS authentication troubleshooting, Troubleshooting Tip: How to troubleshoot SAML authentication

  15. Basic DHCP Troubleshooting: Technical Tip: Understanding DHCP Server and DHCP Relay functionality on FortiGate

  16. Basic DNS Troubleshooting: Technical Tip: FortiGate Troubleshooting DNS commands

  17. FortiGuard troubleshooting: Troubleshooting Tip: Unable to connect to FortiGuard serversTroubleshooting Tip: DNS rating error occurs (no available FortiGuard SDNS servers), Troubleshooting Tip: FortiGuard Web Filtering problems

  18. Basic Routing Troubleshooting: Troubleshooting Tip: FortiOS routing (RIP, OSPF, BGP, static routes, ECMP)

  19. Basic Throughput Troubleshooting: Technical Tip: Low throughput troubleshooting

  20. Basic Logging Troubleshooting: Log-related diagnose commands

  21. Troubleshooting Tip: How to deal with a kernel panic for continual monitoring.

  22. Restricting system access to appropriate parties: Technical Tip: Optional security considerations for FortiOS SSL VPN access, Trusted hosts and local in policies

  23. Programming-related configuration scope: Technical Tip: Technical support on customization on various Fortinet products (API, Regex, signatures, HTML, scripting, reports).

  24. Standby support requests (unless an issue has been previously encountered). Advanced Support can cover this need.

  25. Performance evaluation on CPU or memory after enabling security features, unless it is high CPU: Technical Tip: Debugs for troubleshooting high CPU Issues) or high memory(Troubleshooting Tip: How to do initial troubleshooting of high memory utilization issues (conserve m...troubleshoot.

  26. Configuration Migration. Users must either use the FortiConverter tool or FortiConverter service or seek professional services.

 

  1. DoS Policies. Refer to the following resource Denial of service policies

  2. LACP Negotiation. Refer to the following resource Technical Tip: Initial troubleshooting steps for LACP (Link Aggregation - 802.3ad).

A CLI cheat sheet reference for diagnostics can be used to gather details before engaging TAC.

 

Related articles:

Technical Tip: Technical Support on customization

Technical Tip: Fortinet Support: FortiCare Service Level Agreements and FortiCare Case Priority

Technical Tip: How to enhance experience with TAC representative