After having done a load of testing I've come to the conlusion that
there actually is an issue with ASIC offlading and UTM on the 100F
Series.This issue does not occur on 100E Series or a 300E or a 60F but
it does on all of our 100F.All FGT here are ...
I have this constellation: FGT A (Shopsite) has static WAN IPs FGT B (on
events) has dynamic WAN IP(s) and is not allways online Between FGT A
and B is two IPSec Tunnels which should provide redundancy. Due to
reasons (to me this is still bugs in For...
In v7.0.7 FortiNet seems to have changed an option: config system
antivirus quarantaine FMG now defaults the destination option to disk.
Due to this policy package deployment will error out on every device
that does support FortiGuard Antivirus but d...
I just found out this issue: I set up a dial up IPSec. It is configured
to do ike v2 and only accept one specific peer id.I then downloaded and
installed latest FortiClient VPN 7 (as I just need VPN for testing
this).I configured that IPSec in my For...
This is what I have: Fortigate on Site with static WAN IPFortigate on
other Side whout static WAN IP What I need:redundant IPSec Tunnel
between those two FGT What I tried: 1) S2S with ddns on one site. Does
not work because S2S by default is negotiat...
unfortunately there is an issue with site2site and dyndns.A site2site
vpn always needs both "ends" to be defined. Since one Side does not have
a static wan IP and you do not want to always change the ip manually you
would need to use some dyndns serv...
First of all you have to have routing to your Terminalserver so you can
be routed to it coming from the FGT on Side B and getting back from
Terminalserver to Side A. The last can be the culprit. I'd recommend
doing some VIP with snat here to have the...
There is a known issue with FortiClient and Windows 11 and some Realtek
NICs that results in FortiClient being unable to connect the VPN. Maybe
you ran into this?
I also had issues with ipsec and ddns. In my case the problem is that
the other side does nothave a static public ip so I have to use ddns.
DDNS itself works fine on my FGT and resolves correctly. However even
though the IPSec goes down once the othe...