Description This article describes how to set up MCLAG with ISP router
redundancy for Standalone FortiSwitches. Scope FortiSwitch Standalone.
Solution Example of MCLAG topology with ISP routers and crossed links
for redundancy: In this scenario, each...
Description This article explains how to map domain IP addresses to
wildcard FQDN objects when DNS traffic is encrypted. FortiOS supports
wildcard FQDN objects for firewall policies, static routes, SD-WAN
rules, and other configurations. However, for...
Hello @pralad I suggest you recreate the Security Fabric connection both
on FortiGate and EMS side, to restart the trust relationship between the
devices.
I believe something in this doc might help you:
https://community.fortinet.com/t5/FortiClient/Technical-Tip-FortiClient-SAML-Authentication-Configuration/ta-p/369318
FortiOS enhanced it's TLS support from 5.6 to 7.4, so SNI check is
probably the cause of the issue. Check SSL logs for errors in SNI
validation and take a look at the behavior when each of the actions is
defined on the ssl inspection profile:
Are you using the public ip address to manage the firewall? Because this
could be messing up your management session, since you have the same IP
for management and also for a DNAT rule. Also, your vip object maps to a
lan interface IP, which would be...