Description This article describes that Port A and Port B seen in model
FortiGate 60F/61F, 70F/71F, 80F/81F, and 90G/91G can be used as regular
traffic ports. Scope Entry-level FortiGate. Solution In earlier
FortiGate models, there could be dedicated...
Description This article explains an issue when user has a FortiGate
cluster (A-P) connecting to a FortiSwitch, multiple ports are configured
and connected, but only one port shows up. Scope FortiGate FortiLink
FortiSwitch Solution Topology: FortiGat...
Description This article describes the approach to allow only
TLS1.2/TLS1.3 through traffic and block lower version SSL traffic. Scope
FortiGate . Solution Most TLS traffic today is run on TLS1.2+ as the
modern browser by default supports TLS1.2+. Ho...
Description This article describes when running into such a message in
the system event log, what it means, and provides a guideline for
troubleshooting as well as suggestions for log collection to engage
Fortinet TAC. Scope FortiGate Log CMDB deadlo...
Description This article describes that FQDN-based address objects are
easier to use in firewall policy. In many cases, an FQDN may return a
list of IPs. In such cases, the default setting is good enough. However,
in some cases, only one IP is return...
Another possible cause for this symptom is that the FGT never Acked on
FAZ connection. To check this, in the config, you would see the
FortiAnalyzer IP but not the serial number. If so, putting the command
"set serial" in would also address the issue...
If you see the following error msg when running TCL script, that usually
indicates password issue. Please refer to the article below for
solution. Script $NameoftheScript executed on $NameoftheDevice failed.
Reason: Run script fail
https://community....
To delete packet capture files (captured by policy), please use the
command below. execute policy-packet-capture delete-all Delete all
captured packet.
This feature is added in 7.0+
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/885870/interface-migration-wizard
Before it is available, it does require some effort. One way to do is to
create a new VLAN interface, and replace all the ...