Hi,In the FortiGate, I can see there are traffics initiating from
FortiGate' IP address (10.90.0.2) to IP Public which is
globalupdate.fortinet.net.I have configured the FGT so that it will use
FortiManager as local FDN, but seems like the FortiGate ...
Hi, Based on this KB:
https://community.fortinet.com/t5/FortiGate/Technical-Note-ICMP-and-UDP-traceroute-functionality-with-the/ta-p/195339#:~:text=The%20FortiGate%20is%20designed%20not,a%20from%20a%20Cisco%20Router.I
know that the UDP based tracerou...
Hi,I need to know whether iBGP routes that learnt in FortiGate can be
redistributed to OSPF by default or not?Because in other router like
Cisco, iBGP can't be redistributed to OSPF by default, it needs command
like 'bgp redistribute-internal' Thank ...
Hi,I'm deploying FortiGate SDWAN with dual-hub (DC and DRC) with many
spokes. The spokes may not required to communicate each other, so that
ADVPN is optional.I have routing challenge when I use iBGP between Hubs
and Spokes. At the first, the iBGP in...
Hi, I need to understand the risks of enabling tcp-session-without-syn
for asymmetric environment. Can someone help to explain to me all the
risks if I enable this? Thank you
Hi,I'm interested with this topic.At first, I have 1 hub and 1 spoke
with IP as below: Hub local IP: 10.90.0.1/32Hub remote IP:
10.90.1.254/23 Spoke1 local IP: 10.90.0.2/32Spoke1 remote IP:
10.90.0.1/23 From hub can ping to spoke1 local IP. When I ad...
Hi,Yeah, it is still in place config system central-managementset type
fortimanagerset fmg "::ffff:10.1.71.57"set fmg-source-ip
10.90.32.11config server-listedit 1set server-type update ratingset
server-address 10.1.71.57nextendset include-default-se...
Hi,Yes, I don't see traffic to globalupdate.fortinet.net anymore.For
globalproductapi.fortinet.net, I tried disable "set fortiguard-anycast
disable" in system fortiguard.Now, the remaining is to this
msgctrl1.fortinet.com, what does it for? And how t...