Description This article describes the HA member's visibility
discrepancy on the Fabric Management page. Scope FortiGate. Solution The
Fabric Management page allows administrators to manage the firmware
running on each FortiGate. More details on Fabr...
Description This article describes the specific condition where
FortiManager generates a 'Device Offline' event for the managed
FortiGate devices even though the device is online. Scope FortiManager,
FortiGate. Solution FortiManager can generate Devi...
Description This article describes how to avoid issues with an IBGP
route being preferred over an EBGP route. Scope FortiGate. Solution If
the same route is learned through EBGP and IBGP, the EBGP route is
generally activated due to its lower adminis...
Description This article describes how to check the routes configured
using the HA reserved management interface on the FortiGate HA setup.
Scope FortiGate HA. Solution The HA direct management interface and the
route can be configured from the GUI a...
Description This article discusses the possible scenarios where the user
is able to see specific packets under the 'diagnose sniffer' output, but
it is not possible to see the packet leaving the firewall and no outputs
in the 'debug flow trace'. Scop...
When you say cluster restarted, do you mean it failed over? If so, the
new serial number is of the old backup node.Regarding VPN tunnels flap,
its expected with cluster failover.
Can you check if this matches your requirement
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Imposing-data-cap-for-web-access-for-end-users/ta-p/192427
Have you tried the configuration suggested in
https://docs.fortinet.com/document/fortigate/7.2.0/new-features/951346/saml-based-authentication-for-forticlient-remote-access-dialup-ipsec-vpn-clients
Are you facing any specific issues/errors after conf...