Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
 But seriously: I would not expect that the fault will not come up again. If I had to debug this I' d 
 a) let the sniffer show me the packets entering the tunnel (' diag sniffer packet ...' )
 b) start a ' diag debug flow'  to see how packets are handled and routed
 
 The policy itself will not route anything; routes do. I' ve seen networks where the active route was not the defined one but the one proposed by ICMP redirection. And that' s a factor outside the firewall and thus hard to keep in view.
 
 Firmware updates are downloaded manually from support.fortinet.com where you identify yourself by your user account. To create one, you have to register your FGT' s serial number. Updates and upgrades are for free, lifetime.
 
 The 50B is an old workhorse and as such is supported in the newer firmware versions. Versions generally seen as stable are 3.7.10, 4.1.10 and 4.2.8 (read: version, MR, patch).
 
 But seriously: I would not expect that the fault will not come up again. If I had to debug this I' d 
 a) let the sniffer show me the packets entering the tunnel (' diag sniffer packet ...' )
 b) start a ' diag debug flow'  to see how packets are handled and routed
 
 The policy itself will not route anything; routes do. I' ve seen networks where the active route was not the defined one but the one proposed by ICMP redirection. And that' s a factor outside the firewall and thus hard to keep in view.
 
 Firmware updates are downloaded manually from support.fortinet.com where you identify yourself by your user account. To create one, you have to register your FGT' s serial number. Updates and upgrades are for free, lifetime.
 
 The 50B is an old workhorse and as such is supported in the newer firmware versions. Versions generally seen as stable are 3.7.10, 4.1.10 and 4.2.8 (read: version, MR, patch).
					
				
			
			
				 
					
				
				
			
		
| User | Count | 
|---|---|
| 2647 | |
| 1405 | |
| 810 | |
| 690 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.