Description This article describes how to troubleshoot the 'duplicate
entry' error encountered when adding a new item to the FortiSIEM
Watchlist. Scope FortiSIEM. Solution This error can occur if the entry
value trying to add already exists in the Wa...
Description This article describes how to handle the error 'Cannot find
key for' the principal in Kerberos Authentication. Scope FortiGate,
FortiProxy Solution Kerberos authentication fails when it cannot locate
the correct key for the principal in t...
Description This article describes how to read and understand the
Kerberos authentication log on FortiGate. Scope FortiGate. Solution This
sample log is from FortiGate with IP-based transparent proxy
configuration and using Kerberos authentication. T...
Description This article describes a possible error that can be seen in
the WAD debug when authenticating a user with Kerberos. Scope FortiGate.
Solution This error is seen when the time difference (skew) between the
client machine and Service and th...
Description This article describes why an endpoint displays a pop-up
prompting the installation of a version of FortiClient that is already
installed. Scope FortiClient EMS. Solution This issue occurs when
FortiClient is manually installed on an endp...
Hello, What network ports are allowed between endpoints and EMS ? Please
check the Firewall and ensure that following ports are open "TCP 135,
445, and 10443 ports between EMS Server". Regards, Manosh
Hi, Yes the above mentioned steps are correct. Additionally, you may
also refer to these links for any configuration in NAT mode and
Transparent Mode
VDOM:https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-VDOM-with-Transparent-m...
Hi, Here are some of the key features of
Fortimanager:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/0300_FMG_architecture/0400_Key%20features+.htm
Hi, If you have disabled Split Tunneling for SSL VPN, in that case, on
the Policy which you have created for the SSL VPN users to access
Internet, you would need to call the SAML USER GROUP. This group will be
for the non gallery application which yo...