Description This article describes how to ensure the captive portal on
Apple devices is working after performing the initial configuration from
here: FortiAuthenticator as a Wireless Guest Portal for FortiGate To
verify whether the initial captive po...
Description This article describes that there may be times when the BGP
neighbors may show up as Idle (Admin). This is usually seen when the
neighbor, interface has been administratively disabled or shut down.
Sometimes this is even when the interfac...
Description This article describes that logging into the FortiSASE
instance results in an error message, ‘user login failed’. This is
because of the recent change as per https://status.fortisase.com where
sub-users have been deprecated in FortiCare/F...
Description This article describes how to use PCAPdroid to troubleshoot
Fortinet products. PCAPdroid is an Android application that can be
downloaded from the Google Play Store to perform packet captures on the
device. This can be useful when trouble...
Description This article describes how to check the kernel version on
FortiGate. Scope All currently supported versions of FortiOS. Solution
In the CLI, run this command: fnsysctl cat /proc/version The result of
the command should look like this: Som...
Even for this, you can follow the 'Dual Region' configuration but with
the same AS number in the BGP settings to ensure both Hubs and all
Spokes are in the same iBGP AS. The Spokes from different region
(different eBGP AS) will still end up forming s...
The SSL inspection that you were using, was it regular
certificate-inspection or deep-inspection? That aside, what security
profiles did you have Enabled on the specific firewall policy? Adding an
ssl exemption for *.google.com as google drive would ...
You may find the PDF in this document helpful, page 76 where there is
explanation on Dual Hub set up:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Fortinet-Auto-Discovery-VPN-ADVPN/ta-p/195698
Making the Hubs, spokes of each other is not...
FortiClient is not innately supported on ARM devices and the workarounds
may or may not work. To save yourself the hassle, I would highly
recommend you to purchase/exchange for a non-ARM based Surface Pro
As you are seeing traffic enter the ipsec tunnel on both sides, do you
see packets being received on both sides as well? Besides phase1 and
phase2 selectors being up and configured correctly, please check whether
the firewall policy, routing are conf...