DescriptionThe Fortigate IPsec VPN phase 1 is set to initiate the IKE SA
negotiation by default. The option is available to disable it and
respond only with the IKE SA initiation from remote peer side.This
article describes how to disable this option...
DescriptionThis article describes how to verify if SIP session helper or
SIP ALG are used to process the SIP traffic.SolutionIn case the SIP
session helper is being used instead of the SIP ALG, one can use the
#diagnose sys sip command to determine i...
Description This article describes the behavior and changes of the
'Create address object matching subnet' option for different Interface
roles via GUI/CLI. Scope FortiGate interface created with role LAN in
v7.0+ via GUI/CLI. Solution The 'Create ad...
Description This article describes that in a source or destination NAT
firewall policy that accepts SIP sessions, it is possible to configure
the SIP ALG (or the SIP session helper) to remove the original source IP
address of the SIP message in the S...
DescriptionThis article describes how to troubleshoot the fact that a
FortiNAC running on HA (Control Server/Application Server Pair), which
requires a reboot for maintenance, does not perform a
failover.SolutionImportant: For L2 HA configurations, d...