With FortiOS 6 the configuration of the FSSO servers moved to the
Security Fabric Connectors section in GUI.Am I right that you can no
longer see in the GUI what FSSO server is the active one ? We have a
primary and a secondary. In FortiOS 5 you were...
FortiOS 6.0.14, using ssl inspection.Lately, browsing to microsoft.com
or www.microsoft.com fails. Firefox throws error PR_END_OF_FILE_ERROR,
Chrome ERR_CONNECTION_CLOSED.No such problems with other subdomains like
teams.microsoft.com. I guess it's a...
We are in a (painful and lengthy) transition from FortiOS 5.6 to 6. Next
step in the upgrade path is from 5.6.11 tot 6.0.10. Yes, I know, we are
3 years behind... But for us this upgrade to a major version, feels like
a giant milestone. We currently ...
All our SSID's are tunneled. But now I need a locally bridged SSID (name
"tech") in a separate VLAN (eg VLAN20). VLAN20 is an existing VLAN
interface on the Fortigate (serving as gateway, DHCP, DNS...).A few
existing tunneled SSID's and the new bridg...
We often have users that are in the FSSO Agent list, but ar not known on
the fortigate. Sometimes it takes several minutes.So user comes to work,
logs in. Logon event is picked up by FSSO agent. But user has no access
to mail (in cloud) or internet. ...
Thank you, but it does not seem to be the case in 6.0.14, at least not
with Firefox and Chrome.If I hover over the Users/Groups icon, it shows
me the Windows domain. Must have been introduced later...
Thank you. I don't think it's related. At the time of writing,
microsoft.com resolved to an IP on akamai. That one served a very nasty
certificate (this one:
https://www.ssllabs.com/ssltest/analyze.html?d=e13678.dscb.akamaiedge.net&s=184.27.30.29&ign...
Wow this sound terrible. We've had none of those issues. I would have
known with 250+ VPN users... Maybe Forticlient 6.0.8 is a really bad
version in combination with Win10.
Thank you firewallNoob. Curious you mention Win10 not playing. We've
been having no issues with Forticlient 6.0.3 . May I ask what kind of
problems you experienced ? Altough we use neither, it's good to know
functionality is lost with anything newer ...
Sorry I have to respond on an old topic. What do you mean with "You will
need to change the groups to the FSSO groups you set up in the firewall
proxy policy" ? And how do you set the active-auth-scheme to "NTLM" ?