For your IPSec tunnels to non-fortigate devices, do you have "set
auto-negotiate enable" configured under the phase2? For the 6.2.4
connection issues, disable DoS sensor if configured.
Where are the clients located in relation to the firewall they're going
through?Are they hitting a policy with certificate inspection or full
SSL inspection enabled?What firmware are you running?