DescriptionThis article describes how to connect to a FortiEMS over an
IPsec VPN tunnel.SolutionLet’s assume that the site-to-site IPSEC VPN
tunnel is up and the traffic can pass through just fine.1) Adding the
Forticlient EMS.Go to Security Fabric -...
DescriptionThis article describes how to use the built-in packet capture
feature in FortiOS from the GUI interface.SolutionOn the 5.6 firmware
branch, the unit needs a disk and logging to disk has to be
enabled.Since the firmware version 6.0.2, this ...
DescriptionThis article describes how to recover trial FortiToken Mobile
serial numbers in later FortiOS versions. If there were deleted from the
firewall, then the free service cannot be used.FortiGate firewalls are
shipped with two free FortiTokens...
DescriptionThis article explains how to enable and disable the FortiGate
system session helper.ScopeFortiGate units, running FortiOS versions
5.4, 5.6, 6.0 and 6.2SolutionAs outlined in the FortiGate CLI Reference
Guide, a session helper binds a serv...
DescriptionThe list of unit models supported by FortiAnalyzer and
FortiManager is documented in the release notes. Alternatively, there is
a CLI command that can be used to obtain this information.SolutionOpen
the CLI console in FortiAnalyzer or Fort...
Dear Jomof, it might need to check with configuration of Switch and
Fortigate, so it might be better to raise a TAC case with the serial
number of the Fortiswitch to check this a little bit deeper. Best,
Dear Jomof, it may be, that the FortiSwitch OS is not compatible to your
actual FortiOS for the Fortilink - please refer to the attached
Dear Tobias, the local-in-policy should match the traffic from what I
see in the logs. As you still receive these events it would be worth to
make the debug flow trace as my colleague already stated to see why this
traffic is still arriving the kerne...
Dear Sergio, below you find the scenarios and which SNAT is used in
which constellation : 1) VIP + central-nat + IP Pool - VIP has higher
priority compared to central-nat table hence traffic will nat using VIP
ip 2) VIP + nat-source-vip disable+ IP P...