Hello,
I have a Fortigate 60D unit that has a lapsed subscription. Since then the configured port forwarding did not work anymore. Based on the information, I've disabled all features that requires subscriptions (Application Control, Web Filtering, etc.), but the port forwarding still does not work.
The settings are configured before the unit is registered to Fortinet, so I am assuming that the features should still work. Is there anything else that I may have missed here that will help to re-enable the settings?
In my experience there's no dependency between licence status and VIP. Web filter will block traffic if unlicenced but not firewalling.
Thanks for the clarification.
To further troubleshoot this issue, is there a page that contains the steps to do so? I've attempted to do a packet trace of the server affected from Fortigate, but it does not seem to capture any data.
vlite
'diag debug flow' is your friend!
(sorry Ken, I just had to...)
Ken Felix has posted a tutorial on the debug flow command here
Post the output here and we'll see what to make of it.
Sounds good. Thanks for the steps. I'll try them out when I'm back to the premise on a few days.
See Hua
NP ;)
And yes on web-filter would block traffic if subscription laspes and that's only if categorization is enabled.
IPS AV/MAL would just leave you un-protected. Your port forwarding issues is probably something else but your doing the right thing with disabling any UTM features to eliminate them.
PCNSE
NSE
StrongSwan
Hello all,
I've managed to pin down the real issue this time. It was due to the DDNS update not working properly.
I noticed earlier that the packet traces failed to record anything when I tried to access the the port services within the premise. Thus I decided to check whether the IP pointed by the dyndns address is the same as the public IP address of the premise, and voila! The addresses did not match.
Set the Dyndns in the firewall to use x.float-zone.com and outside access worked again!
Thanks everyone for your advice, they have been really helpful in troubleshooting this issue. I've also learned a lot about the Fortigate Firewall in the process.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.