Description This article describes how to resolve an issue where FSSO CA
stops sending new logged on users with a debug error message 'packet
size too big'. Scope FortiGate configured with FSSO. The FSSO user
filter is configured on the FortiGate (Lo...
Description This article describes how to configure an SSID on the
FortiGate that is restricted to the FortiAuthenticator self-service
portal. This article assumes that the self-service portal policy has
already been set up on the FortiAuthenticator....
Description This article describes that when configuring ZTNA proxy
policies, the ISDB objects cannot be selected as source. This article
explains how to secure a ZTNA access proxy from malicious sources using
local-in policies with ISDB objects. Sco...
Descriptionraf This article describes how to use Iperf as a source and
as a receiver to test multicast connectivity. Scope FortiGate configured
with multicast forwarding or multicast routing. Solution To run Iperf as
a receiver, the command below can...
Description This article describes how to take a snapshot of a FortiGate
VM hosted on Azure. Scope FortiGate VM hosted on Azure public cloud.
Solution Taking a snapshot of the FortiGate VM is possible by taking a
snapshot of the OS disk attached to t...
The IP address will not match the certificate wildcard subject name or
alternative subject name. The wildcard certificate cannot be used to
authenticate the server by its IP address.
Wildcard FQDN should cover all the subdomains, but you have to make sure
the DNS queries sent by the client must pass through the FortiGate.
Because unlike normal FQDNs, FortiGate does not activly sends queries
for wildcard FQDNs. Instead, FortiGate ...
Hi bfig90,FortiGate uses the configured DNS servers in (Network>DNS) to
resolve the IP of the given FQDN. If the DNS server only returns one IP,
FortiGate will use that IP. FortiGate will also re-query the FQDN to get
the latest IP. If the IP changes...