Description This article explains a step-by-step guide on how to block
remote access software for client connections. Scope FortiGate. Solution
Blocking remote applications can be achieved in multiple ways.
Application control: To block remote access...
Description This article describes the step-by-step instructions for
troubleshooting and resolving the 'Cache conflict with DDNS gateway
' error in IKE debug, which prevents IPsec
Site-to-Site (S2S) tunnels from establishing. Scope FortiGate. Solutio...
Description This article describes how to block application signatures
based on the Risk severity of the application. Scope FortiGate v7.x.x.
Solution To achieve this: Go to 'Security Profiles'. Select 'Application
Control'. Select the Existing or th...
Description This article describes a scenario where SD-WAN is configured
on the FortiGate, but traffic is still routing through the WAN-1
interface despite the expected redirection to the WAN-2 connection.
Although, the interface-select-method is set...
Description This article describes the steps to take when FortiGate and
FortiClient EMS cloud have valid licenses but the FortiGate side
displays 'EMS cloud license Expired'. Scope FortiOS 7.x.x. Solution
One common cause of this issue is an expire...
Hello @aguerriero , It looks like above debug is related to internet
options. Please check the below article.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-When-logging-in-with-SSL-VPN-the-error/ta-p/260630
https://community.fortine...
Hello @aguerriero, How are you sharing the logs? Are you uploading files
or pasting the log content directly into the forum? Please note that
file uploads are limited to 5MB. Thanks, Amandeep
Hello @aguerriero, Could you provide the SSL VPN debug logs from your
testing with FortiClient 7.2.5? Additionally, please confirm which
authentication server is being utilized. To collect the necessary logs,
please run the following commands: diag d...
Hello @jbcastillo You can use the same group but not the same IP range.
Related Document:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Do-not-use-the-same-IP-address-range-for-both/ta-p/340393
Thanks, Amandeep
Hello @columbiavalley Could you please share your desired network
topology and configuration goals? Additionally, I'd like to understand
your requirements better - what is the reason for not wanting to
implement an IPsec site-to-site tunnel between t...