Description This article provides steps to integrate DUO Security with
FortiGate using SAML authentication for administrator access. The
application type used is 'Fortinet FortiGate Administrators - Single
Sign-On'. Scope FortiGate. Solution To set u...
Description This article indicates the setup of an IPsec tunnel between
FortiGate and GCP using Classic VPN configuration. Scope FortiGate.
Solution Network Topology: To set up GCP, follow this link: GCP Static
IPsec VPN Setup GCP configuration: Note...
Description This article describes the limitations of using Let's
Encrypt certificates for SSL/TLS inspection on FortiGates. Scope
FortiGate. Solution FortiGate is capable of generating Let's Encrypt
certificates for securing web applications. Howeve...
Description This article describes a scenario where group matching for
SSL VPN authentication on FortiGate was not functioning correctly with
DUO SAML for multiple Active Directory groups. Scope FortiGate. Solution
Since DUO does not provide an Objec...
Description This article explains how to manage untagged traffic on a
FortiGate interface. By default, untagged traffic arriving on a
FortiGate interface is processed by the physical interface itself. This
means that the physical interface handles th...
Hi @heye - As far as I know, if there are no interfaces added to that
SDWAN Zone, it is disabled by default. However, once an interface is
added, it should turn green, indicating that the Zone is up.
Hi @Staphisco - Yes, it will essentially become a separate network, so
you'll need to allow it on the FortiGate depending on your
configuration. Where are you getting your DHCP from, is it also from the
FortiGate?You might try making the hardware swi...
Hi @grod777 - Glad to hear that it's working now. It might have been due
to the initial session where traffic was routed out through the WAN
interface. The issue arises when creating a new session with the exit
interface set to IPSec, which can cause...
Hi @Dattatray - I think that's only possible if you format the device
with a 7.2.8 image and manually convert the config file, or use the
FortiConverter app to automatically handle the conversion. Upgrading and
downgrading have become more strict sta...
Hi @Staphisco - As far as I know, if your FortiSwitch is not part of
FortiLink, you cannot manage it directly from your FortiGate firewall.
So, FortiSwitch managed by FortiGate must be part of FortiLink. Since
it's standalone, you need to manage it d...