Description This article describes the creation of an automation stitch
that schedules a reboot for downstream devices in the security fabric.
Scope FortiGate. Solution If the device is in a security fabric, an
automation stitch can only be configure...
Description This article describes steps to troubleshoot why an AWS SDN
connector on FortiGate shows as down. Scope FortiGate, SDN Connector,
AWS, IAM, STS. Solution The following is an example of SDN connector
configuration via the CLI: config syste...
Description This article describes the troubleshooting steps to resolve
the DHCP error 'DHCPOFFER in wrong transaction' on FortiGate. Scope
FortiGate. Solution Below is port1 configured as a DHCP-enabled WAN
interface. An attempt is made to get an IP...
Description This article describes how to set a password expiration for
specific admin accounts on FortiGate, while having another admin account
that does not have the expiration policy. It also explains how to check
the expiry date and provides info...
Description This article describes how to import a specific FortiClient
VPN profile to FortiClient without affecting/losing other profiles.
Scope FortiClient Solution As per the below screenshot, currently, there
is only one profile configured 'LDAPS...
Hello @hyder ,Have you tried deep packet inspection, and also what mode
is configured on the policy [flow/proxy]. You can try creating a test
policy and test using Deep packet inspection + Proxy mode and Deep
packet inspection + Flow mode. Also what ...
Hello @hyder , From Application Control profile have you tried blocking
"Apple.Messages" ? Reference:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-particular-application-using/ta-p/357034
Good day @Floh , - Can you enable FEC on both sides, specifically with
cl74-fc-fec? If that helps to bring link up or not. - Also you can
collect following debugs and open up a TAC case for further
investigation:config sys interfaceedit sh fu | grep
...
Good day @IrbkOrrum , - If the tunnel is between 2 FortiGates it's fine
to use wizard that will create policy, routes and will add default ENC
and AUTH protocols. But if you are configuring tunnel to 3rd party
firewall you might need to modify ENC an...