Description This article is a detailed, comprehensive guide for
collecting network troubleshooting information from a Windows client
machine using the command prompt. Scope FortiGate. Solution Step 1: Open
Command Prompt: Select the Start button or p...
Description The article describes how to use the ping command with
specific options to perform a Maximum Transmission Unit (MTU) path
discovery, specifically aiming to detect devices with an MTU less than
the standard Ethernet MTU of 1500 bytes. Scop...
Description This article explains the communication flow used by the
FortiGate to identify the public IP. Scope FortiGate Solution To get the
public IP address, the FortiGate performs a series of steps: DNS
Resolution: The FortiGate must first succes...
Description This article explains how to determine if Virtual Domains
(VDOMs) are enabled on a FortiGate. Scope FortiGate. Solution On
FortiGates, Virtual Domain(VDOM) is a feature that lets the admin split
a single physical FortiGate into multiple i...
Description This article describes the information about MSS needing to
be set for TCP communications in the policy based on the interface
involved in the communication. Scope FortiGate. Solution MTU (Maximum
Transmission Unit) is the largest size of...
yes, you could achieve it. Make sure to add dailup tunnel subnet in
phase2 selector of the site-site tunnel. in FGT1 source :10.5.41.0/24
dest :192.168.8.0/24in FGT2 source 192.168.8.0 dest :10.5.41.0/24 In
FGT2, add a routeto 10.5.41.0 via tunnel in...
Hi Imel, I believe, you need to create ip pools for each nat ip address.
Later call the same in specific soucre and destination policy. Please
refer to
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-SNAT-with-IP-pool/ta-p/...
hi, the script is correct. You can also follow alert mail for concerve
mode and logs collection
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Automation-stitch-for-the-conserve-mode/ta-p/240696#:~:text=FortiGate%20by%20default%20turns%20o...
hi Abel,Please make sure you have spit tunnel enable in the sslvpn so
you that only remote subnet are pointing todards sslvpn adaptor in local
pc. Better to check routing-table in the pc before and after connecting
to sslvpn. use "route print" if its...
Hi, Please try the solution provided in
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Error-The-VPN-server-may-be-unreachable-14-for/ta-p/190882