Description This article describes an issue where updating an
administrator password through the GUI does not update the associated
password expiration date. Scope FortiGate. Solution To create a system
password policy in the GUI Navigate to System -...
Description This article describes an issue where HA failover does not
trigger as expected on FortiGate VM units that are not directly
connected to the cluster. Scope FortiGate. Solution In this scenario,
one of the interfaces in the HA link monitor ...
Description This article describes the expected upgrade prompt that
appears after logging in to earlier firmware versions subject to the
FortiCloud SSO Login authentication bypass critical vulnerability, e.g.,
FG-IR-25-647, FG-IR-26-060. Scope FortiG...
Description This article describes the behaviour behind the out-of-sync
issue due to 'system.central-management' in an HA cluster. Scope
FortiGate. Solution Devices in an HA cluster may become out of sync due
to various factors, such as system upgrad...
Description This article describes the steps needed to resolve the
Kerberos authentication error, indicating 'No key table entry found for
HTTP/fortiproxy'. Scope FortiGate, FortiProxy. Solution Kerberos
authentication fails if the FortiGate device i...
Hi Marconet-22, You can also enable Multiple Interface Policies under
System → Feature in the GUI. After enabling it, you can add the IPsec
tunnels in the interface under firewall policy.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-...
Hi marconet-22, This feature only supports physical interfaces. It is
not possible to integrate virtual interfaces such as VLAN and tunnel
interfaces. Note: Migration is not supported if the physical or VLAN
interface is used in a tunnel configuratio...
Hi KobayashiMaru, Please refer to the documents below for more
information:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Change-of-NAT-type-for-game-console-to-play-online/ta-p/230913https://community.fortinet.com/t5/FortiGate/Technical-...
Hi MahmutKarali, You can enable IPsec NPU offload with the help of the
following command: config vpn ipsec phase1-interfaceedit phase-1-nameset
npu-offload enableend Please refer to the document below on how to
ensure that IPsec traffic is offloaded ...
Hi Ashish-pal, I am unable to find any known issues in version 7.4.11
related to tunnel establishment with no traffic flow.
https://docs.fortinet.com/document/fortigate/7.4.11/fortios-release-notes/236526
Please let us know if you have collected logs...