Description This article explains why link-monitor, when appearing as
dead, fails to remove the route when more than one is configured with
the command 'set route' under 'config system link-monitor'. Scope
FortiGate v7.0, v7.2. Solution Link monitor ...
Description This article explains how port mirroring can be configured
for NP7 platforms on ISF. Scope NP7 FortiGate. Solution It is possible
to run a sniffer on the FortiGate to capture packets as explained here:
Troubleshooting Tip: Using the Forti...
Description This article explains a scenario where an explicit proxy may
fail on a Loopback if there is a captive portal config on the incoming
interface. Scope FortiGate. Solution A loopback interface is configured
and has explicit proxy enabled: co...
Description This article explains how to work around when changing the
'ip-fragmentation' settings for a Dial-up IPsec VPN tunnel is not taking
effect immediately. Scope FortiGate Solution Consider the following
setup: On the Hub location, a dynamic ...
Description This article describes how it can be avoided to SNAT all
traffic to VIP extip with 'set snat-source-vip enabled' and central-snat
is enabled on the FortiGate. Scope FortiOS. Solution As explained in
this article, Technical Tip: How to use...
Hi Balazs, The selection of FOS is usually based on the requirements or
features you are going to use. The latest version is 7.2 I would suggest
going through the release notes that highlight any known issues. If
there are known issues that are point...
Hi CustomX, For this, you will have to check how the traffic is getting
routed and might need Firewall policies with NAT between two interfaces.
This way you can perform source NAT and change the source as you like by
either using the IP address of t...
Hi Ranjith, This article might help:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuration-per-VDOM-DNS/ta-p/190815
Thank you. Shahan
Hi mhanna, A static route is necessary to ensure that traffic is going
via the correct interface. In the VPN setting, for phase2 when you add a
local subnet and a remote subnet, this ensures that traffic between
these two subnets can flow over the VP...