Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dan
Contributor

40F upgraded to 7.4.7: Virtual Server with letsencrypt certs not working anymore

I upgraded from 7.0.15 to 7.4.7 due to a request from Fortinet support to fix an IPSec issue I had.

After the upgrade, all was working fine.

 

Then, a couple of days ago, the letsencrypt certificates I use with Virtual Servers were renewed. Successfully.

However, since the renewal, the certificates are not applied anymore to the incoming connections. Instead the self-signed certs of the application are shown to the client.

 

After some research, I believe that this is because proxy based fw rules are not supported anymore on a 40F with 2GB RAM. 

Question: Can I still use the letsencrypt certificates with VIP connections? If yes, what do I need to change on the settings for those connections (FW rule, VIP serttings, etc.)?

 

Thanks

Dan

Networking and such...
Networking and such...
1 Solution
kaman
Staff
Staff

Hi Dan,

Yes, the proxy features will not be supported after 7.4.4 for devices having less than 2 GB of RAM.

Please refer to this article:- https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/519079

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-with-2-GB-RAM-or-less-no-longer-...


Also, after the FortiOS 7.6.0 for the 2 GB RAM models the SSL VPN Tunnel Mode and Web Mode will not be available as a feature in GUI or CLI.

Kindly elaborate on the behavior observed when applying the certificate to the SSL profile (incoming connections), and attach a screenshot of the error for reference


Regards,
Aman

View solution in original post

1 REPLY 1
kaman
Staff
Staff

Hi Dan,

Yes, the proxy features will not be supported after 7.4.4 for devices having less than 2 GB of RAM.

Please refer to this article:- https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/519079

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-with-2-GB-RAM-or-less-no-longer-...


Also, after the FortiOS 7.6.0 for the 2 GB RAM models the SSL VPN Tunnel Mode and Web Mode will not be available as a feature in GUI or CLI.

Kindly elaborate on the behavior observed when applying the certificate to the SSL profile (incoming connections), and attach a screenshot of the error for reference


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors