Hi @rbenoit , Could you please upgrade your FAC to version 6.6.2 if it
is Older version as we have an some enhancement made with version 7.4.5
of FortiOS as a fix for the CVE-2024-3596 and FAC should be on 6.6.2 or
above to support this change. If yo...
@okan As a first step, please enable logging in the policy and please
check the traffic logs to see what IP is being matched in the deny
policy and see if this IP is in your Yandex_IP_Group. Also check the
port on the allow policy is matching with th...
Hi @Zhuo The "set interface-select-method" command is used when you have
more than one available routes to the destination like in the case of
SDWAN and where you want self-orginating traffic to consider SDWAN
rules/routes. Here with your setup I am ...
Hi @Chaker2002 , I didn't clearlt get your issue with ubuntu server and
its relation with Fortigate Firewall. But please check below article and
see if this helps you anyway.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-HSTS-enforcement/...
Hi @Zhuo The statement "set interface portx" tell the fortigate which
Interface it should listen for incoming NTP traffic (used when Fortigate
act as NTP server).
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-a-FortiGate-unit-...