Description This article explains the scenario in which phase 2 of
site-to-site VPN between FortiGate tunnels goes down and will not
automatically come up. Scope FortiGate. Solution This behavior is
expected when phase 2 'auto-negotiate' is kept disa...
Description This article describes a technique to track when an admin
user logged in and the reason for the same user session close due to the
admin logging out, the admin disconnecting, or the admin time out. Scope
FortiGate Solution When a user suc...
Description This article describes how to use the DNS filter profile to
filter and minimize Internet usage by interrupting client DNS queries.
Scope FortiGate Solution Internet access to the different network
segments is restricted by using security ...
Description This article describes how to find out whether FortiGate was
the initiator or responder during the BGP peering. Scope FortiGate.
Solution FortiGate BGP neighbor command output consists of Connection
status information, which provides deta...
Description This articles describes the reason behind BGP status
commands 'get router info bgp neighbors' and 'get router info bgp
summary' not showing any neighbor information when BGP is configured
with neighbor-group and range. Scope FortiGate. So...
yes, you could achieve it. Make sure to add dailup tunnel subnet in
phase2 selector of the site-site tunnel. in FGT1 source :10.5.41.0/24
dest :192.168.8.0/24in FGT2 source 192.168.8.0 dest :10.5.41.0/24 In
FGT2, add a routeto 10.5.41.0 via tunnel in...
Hi Imel, I believe, you need to create ip pools for each nat ip address.
Later call the same in specific soucre and destination policy. Please
refer to
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-SNAT-with-IP-pool/ta-p/...
hi, the script is correct. You can also follow alert mail for concerve
mode and logs collection
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Automation-stitch-for-the-conserve-mode/ta-p/240696#:~:text=FortiGate%20by%20default%20turns%20o...
hi Abel,Please make sure you have spit tunnel enable in the sslvpn so
you that only remote subnet are pointing todards sslvpn adaptor in local
pc. Better to check routing-table in the pc before and after connecting
to sslvpn. use "route print" if its...
Hi, Please try the solution provided in
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Error-The-VPN-server-may-be-unreachable-14-for/ta-p/190882