Description This issue discusses high CPU utilization on one CPU core by
softirq after upgrading to one of the following versions: v7.0.16,
v7.0.17, v7.2.11, v7.4.6 or v7.4.7. NP6xLite (SOC4), NP6Lite (SOC3), and
NP7Lite (SOC5) are affected by this i...
Description This article describes an issue where the CLI console fails
to load when logging in with the user account sso-forticloud-admin.
However, the console functions properly when logging in with accounts
other than sso-forticloud-admin. The err...
Description This article describes SSL VPN changes that were applied
from v7.6.3. Scope FortiGate v7.6. Solution From v7.6.3, SSL VPN tunnel
mode has been removed, leaving only web mode (which will be referred to
as Agentless VPN) on some models: Age...
Description This article describes about issue due to the
misconfiguration of the certificate on the RADIUS client machine. When
the client connects to WiFi SSID with RADIUS authentication, it gives a
bad password error and when checking from the RAD...
Description This article describes an issue with the RADIUS server EAP
type that cannot be processed by the server when the user connects to
the Wi-Fi SSID. While checking RADIUS server logs, the following logs
were observed for the user: Error logs ...
@brar45 1. In a hub-and-spoke model using FortiGate VM in Azure with
SD-WAN feature, it is possible to have ExpressRoute and internet as the
underlay networks without limitations. You can configure SD-WAN rules to
route traffic based on your requirem...
@luccap07 Make sure that your web filter is in flow mode and it is able
to identify category. If you see category shows unknown then please
provide screenshot of error and also provide log output.
Hello @ctyctyctctcty , I would suggest to soft restart BGP route as
below and if we still have issue, you can run bgp debug as mentioned:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-soft-reset-to-refresh-BGP-routing-table/ta-p/19014...
@FTAdmin You need to follow steps as below: 1. You need to add 3rd party
address in phase-2 selectors of main firewall if that traffic is behind
main firewall 2. You can configure SNAT/DNAT for this traffic to moved
traffic from main to third party w...
@piaakit1210 Based on details and requirements , you can configured
firewall policy as you mentioned, From: AnyTo: AnySource:
AllDestination: "Tor-Relay.Node" and
"Malicious-Malicious.Server"Schedule: AlwaysAction: DenyLog Violation
Traffic: EnabledE...