Description This article describes a known issue in FortiAuthenticator
where the RADIUS Client configuration cannot be retrieved through a REST
API call when using an admin account with a custom admin profile. Scope
FortiAuthenticator v6.6.5 and earl...
Description This article explains how FortiAuthenticator forwards the
SAML username to Azure Entra ID when operating as an IdP proxy. It also
highlights a common issue that may be encountered, and what to consider
when configuring the remote SAML ser...
Description This article describes the 'HA out of sync' issue that
occurs after importing an ACME certificate from Let's Encrypt and how to
resolve it. Scope FortiGate HA, ACME certificate. Solution The Automated
Certificate Management Environment (A...
Description This article describes a scenario where the RADIUS and other
authentication suddenly stop working in the secondary unit in the
FortiGate HA cluster. This issue may randomly happen in v7.4. Scope
FortiGate v7.4+. Solution In the HA A-P clu...
Description This article describes a FortiGate Switch-Controller GUI
behaviour that two FortiSwitches in MC-LAG mode are showing one online
and one offline in all tenant VDOMs when having FortiSwitch ports in a
multi-tenant VDOM setup. Scope FortiGat...
Hi @yeowkm99 , There is no compatibility issue between different
versions of FortiGate with the IPsec. So, we can either upgrade them at
same time or different time. But please be aware of the compatibility of
other devices such as FortiManager, Fort...
Hi @Liza1 , The only option is to perform factory reset and reload the
firmware image and configuration. This is for the security purpose.
Please follow below instructions to format and reload the firmware
image:
https://community.fortinet.com/t5/For...
Hi @genisi , The encryption algorithm of different FortiGate model is
different, which means we cannot copy the encrypted password string
between them. In this case, if we choose to manually copy the
configuration, we need to redo all passwords on ne...
Hi @gorapr , The branch should determine what type of traffic should be
forwarded to the Hub by routing or policy routing. The IPsec split
tunneling normally only applies to the Dialup IPsec connection initiated
from the FortiClient . Regards, George
Hi @sirma504 , To achieve this requirement, we may need to refer couple
of documents. There may not be a single document that fully explain each
detail step. Firstly, regarding to the 4 site-to-site IPsec tunnels and
BGP routing, we can follow below ...