Description This article describes when running into such a message in
the system event log, what it means, and provides a guideline for
troubleshooting as well as suggestions for log collection to engage
Fortinet TAC. Scope FortiGate Log CMDB deadlo...
Description This article describes that FQDN-based address objects are
easier to use in firewall policy. In many cases, an FQDN may return a
list of IPs. In such cases, the default setting is good enough. However,
in some cases, only one IP is return...
Description This article describes how, if the DLP fingerprint database
is enabled via dlp fp-doc-source, the 'DLP database space alarm' warning
log will be visible once the size of dB exceeds the configured value
(16MB default). The detailed message...
Description This article explains and describes how to resolve
SSL.Anonymous.Ciphers.Negotiation or SSL.Null.Ciphers.Negotiation
messages in the Intrusion Prevention log for traffic and traffic passed.
Scope FortiGate IPS. Solution Some users report ...
Description This article describes a solution when there is a name
change in the ISDB object. Scope FortiManager, Policy Package, ISDB name
change. Solution ISDB (Internet Service Database) name does not change
often. When it does, even if FortiGate ...
Another possible cause for this symptom is that the FGT never Acked on
FAZ connection. To check this, in the config, you would see the
FortiAnalyzer IP but not the serial number. If so, putting the command
"set serial" in would also address the issue...
If you see the following error msg when running TCL script, that usually
indicates password issue. Please refer to the article below for
solution. Script $NameoftheScript executed on $NameoftheDevice failed.
Reason: Run script fail
https://community....
To delete packet capture files (captured by policy), please use the
command below. execute policy-packet-capture delete-all Delete all
captured packet.
This feature is added in 7.0+
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/885870/interface-migration-wizard
Before it is available, it does require some effort. One way to do is to
create a new VLAN interface, and replace all the ...