Description This article describes how to configure HA failover delay
when monitored interface go down. Scope FortiGate 7.0 and above.
Solution In the following example, the failover-hold-time has been set
to 30 seconds. The value can be set from 0 t...
Description This article explains the message about FortiGate HA
enrolled in FortiCloud, where the secondary unit shows its management
tunnel status as down. Scope FortiGate and FortiCloud. Solution Problem:
This is an expected behavior. Since the se...
Description This article describes how to identify the direction of
frames in a packet capture when using 'any' interface when running
'diagnose sniffer command'. The following scenario uses UDP an example
and transparent mode FortiGate. Scope FortiG...
Description This article describes the OSPF behavior when introducing a
new router that has a higher router ID and priority to the OSPF
neighborship in the same broadcast domain. Scope FortiGate. Solution
Problem. In the following scenario, VDOM1 and...
Description This article describes how to configure a TTL security
policy for BGP. Scope FortiGate. Solution BGP sessions are vulnerable to
off-path TCP attacks because the protocol runs directly over TCP port
179. An attacker who can spoof the peer’...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Generate-and-sign-certificates-using-OpenSSL-in/ta-p/208899If
I'm not mistaken, you just need to follow step 1 then upload it to your
FortiGate as CA certificate along with the private key.
Not pim sparse-dense mode per se but you may want to consider using BSR
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/920118/example-pim-configuration-that-uses-bsr-to-find-the-rp