Description This article describes the typical circumstances behind the
'Authentication failed, invalid user'. Scope FortiAuthenticator.
Solution Event ID 20101 describes that the Fortiauthenticator had
checked the third-party authentication server b...
Description This article describes the typical circumstances behind the
'Interface status changed'. Scope FortiGate. Solution This event ID can
have two different outputs which separately describe whether the
interface went up or down. The sample sys...
Description This article describes the typical circumstances behind the
'A DNS resolution error occurs'. Scope FortiGate. Solution The sample
system event message will be looked like below: date=2025-01-06
time=01:22:11 eventtime=1697974411360510151 ...
Description This article describes how to check whether an address SSL
connection is exempted by FortiGate SSL/SSH profile Scope FortiGate.
Solution SSL exemption can be configured in both certificate inspection
and deep inspection profiles for many ...
Description This article describes how to check whether the firewall
policy is oversized. Scope FortiGate. Solution A policy can potentially
become oversized when modifying a variety of objects. It can cause the
policy to malfunction when it is overs...
Active-passive cluster is an L2 connection and it is only for local
network. It will not go through the firewall as L3 connection. If you
have another "passive" cluster member across the network located on
another place/location, it will be "global l...
If you are using Full SSL inspection, you might want to check the
exclusion list under the SSL profile. Security scanning will be excluded
when it is fallen under "Exempt from SSL Inspection" configuration.
From what I understood here there are no "free trial" version kind of
license. To be specific, "trial license" basically is the same as normal
license with shorter expiry date. Hence, it should function as the same
as a purchased license if it is sti...
Since you are able to reach to the FortiGate GUI interface and non other
device than that which is within this subnet, why not SNAT your source
IP to the FortiGate IP (the one which is the same subnet with other
device) and check your connection agai...