Description This article describes how to use Failover sequence feature
to get connected to a different PoP for the IPsec Instance. Scope
FortiSASE. Solution In general, PoP selection is done based on eDNS/DNS
lookup; however, there can be scenarios ...
Description This article describes how to find firmware for an AWS
instance from the support portal. Scope FortiAuthenticator-AWS. Solution
While downloading firmware for an AWS instance from the support portal
under Downloads/Firmware Images, the fi...
Description This article describes the likely outcome of TLS version
difference post-enabling FIPS-CC mode for GUI access. Scope FortiOS
v7.2, v7.0. Solution By default, FortiGate supports tlsv1-1, tlsv1-2,
tlsv1-3 for GUI access. Once enabling FIPS-...
Description This article describes how to find the cause for traffic
getting dropped with the error 'policy-4294967295 is not active'. Scope
FortiGate. Solution When traffic is dropped due to a forward policy
check fail, collect the flow debug. The i...
Description This article describes how to enable assigning Threat levels
for blocked categories. Scope FortiSASE. Solution It is possible to see
an informational notification on Web-filter FortiGuard as mentioned
below for the blocked category. It ha...
Hi @yeowkm99 Based on the update, I understand that from Firewall Lan IP
as a source your not able to ping other network. Also when you mentioned
that from Lan to Lan reachability is fine, Was this validated from both
direction? Is Nat enabled on the...
@Akmostafa , Can you confirm if your have the FGT added to FAZ(which is
having IOC license). Also check if the blocked user source is getting
listed for the below command. diag user quarantine list or diag user
banned-ip list
Hi @joshow , I missed the part of cert error mentioned. As checked the
CN/SNI in SSL certificate we not get matched even with deep-inspection.
Suggesting to use Web-filter along with DNS-filter. Regards, Patterson
Hi @joshow , I understand that your looking for a replacement message if
the DNS filter is blocking the access based on your configuration. Since
this is a DNS query initiated, FGT can't responds back with http
responds. Instead we have the option to...
Hi Vassilis, I think we got the issue !!! Please change the Action
execution from Parallel to Sequential. The issue was occurring for me
also, when set to parallel... Regards, Patterson