Description This article describes how to read and understand the
Kerberos authentication log on FortiGate. Scope FortiGate. Solution This
sample log is from FortiGate with IP-based transparent proxy
configuration and using Kerberos authentication. T...
Description This article describes a possible error that can be seen in
the WAD debug when authenticating a user with Kerberos. Scope FortiGate.
Solution This error is seen when the time difference (skew) between the
client machine and Service and th...
Description This article describes why an endpoint displays a pop-up
prompting the installation of a version of FortiClient that is already
installed. Scope FortiClient EMS. Solution This issue occurs when
FortiClient is manually installed on an endp...
Description This article describes how to discover a device via SNMP and
troubleshoot on failure for FortiSIEM. Scope FortiSIEM. Solution First,
check that the device supports SNMP from the External Systems
Configuration Guide in section Supported De...
Description This article describes how to read SAML logs with the output
obtained from the following commands: diag debug application samld
-1diag debug enable Scope FortiGate. Solution This article uses SAML
login as an example. Once the user enters...
Hello, What network ports are allowed between endpoints and EMS ? Please
check the Firewall and ensure that following ports are open "TCP 135,
445, and 10443 ports between EMS Server". Regards, Manosh
Hi, Yes the above mentioned steps are correct. Additionally, you may
also refer to these links for any configuration in NAT mode and
Transparent Mode
VDOM:https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-VDOM-with-Transparent-m...
Hi, Here are some of the key features of
Fortimanager:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/0300_FMG_architecture/0400_Key%20features+.htm
Hi, If you have disabled Split Tunneling for SSL VPN, in that case, on
the Policy which you have created for the SSL VPN users to access
Internet, you would need to call the SAML USER GROUP. This group will be
for the non gallery application which yo...