Description This article describes a MAC address issue that can affect a
VPN tunnel after cutover, preventing the tunnel from establishing until
the local ISP router is rebooted. Scope Hardware migration of an
existing firewall acting as a VPN gatewa...
Description This article demonstrates an uncommon ISP issue that can
affect a previously working IPsec tunnel, preventing the tunnel from
passing traffic until a manual workaround is applied. Scope VPN gateways
not using NAT traversal, especially sit...
Description This article demonstrates how to configure a dial-up IPsec
VPN using IKEv2 and Multi-Factor Authentication (MFA) with Duo
authentication proxy. Scope FortiOS v6.2.4 and later, dial-up IKEv2 VPN.
Solution This article refers to non-SSO aut...
Description This article provides an overview of guides and resources
for User and Multi-Factor authentication in FortiOS IKEv2 Dialup IPsec
VPN. Scope FortiOS v7 and later. Solution Determine the User source and
required MFA method(s) and refer to t...
Description This article demonstrates an example configuration allowing
Active Directory users to connect to FortiGate IKEv2 VPN with FortiToken
hosted on FortiAuthenticator. Scope FortiGate, FortiAuthenticator,
FortiClient, FortiToken, IKEv2. Soluti...
Seconded, open a TAC case. Even if it turns out to be a known issue,
tunnel issues are unlikely to be identified from a forum post unless
they are extremely common. There are just too many different possible HA
and VPN configurations, and too many po...
Qualsys added and updated some signatures in November 2025, see QID
530600 in their bulletin here
https://notifications.qualys.com/product/2025/11/28/application-security-detections-published-in-november-2025.
SSLVPN/Agentless VPN on all current Fort...
Thank you, this appears to match known issue 1205084 . It's scheduled
for fix in FCT v7.4.5.
https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/573433/new-known-issues."Re-importing
the certificate" is the listed workaround fo...
If it works for SSL VPN, this suggests FortiClient itself has the
required permissions to access the cert. For IPsec, ensure
is enabled for the VPN connection profile. It is
disabled by
default.https://docs.fortinet.com/document/forticlient/7.4.4/xm...
Thread is old, but to avoid the use of fnsysctl (which loses permissions
to read /etc/upd.dat in later firmware versions), use "diagnose test
update info" to retrieve the FortiCare account FortiGate believes it is
registered to.diagnose test update i...