Description This article describes the significance of auth timeout and
login session timeout when FortiAuthenticator is acting as an IDP Scope
FortiGate, FortiAuthenticator. Solution When configuring
FortiAuthenticator as an IDP two timers should be...
Description This article describes verifying if the UDP port is
unreachable when troubleshooting the Syslog server. Scope FortiGate.
Solution Telnet protocol can be used to check TCP connectivity for IP
and port but In the case of UDP Telnet cannot b...
Description This article describes a scenario where traffic goes out of
FortiGate but a reply does not come. This mostly happens either due to
permission on the server or routing issues. Scope FortiGate. Solution
Hairpin nat can be configured by foll...
Description This article describes how to take the device GUI access on
the IPV6 IP address. Scope FortiGate. Solution To take the GUI access to
the IPV6 IP address, use the format https://[IPV6 Ip address]. Inside
the bracket, specify the IPV6 IP ad...
Please refer below link
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disable-Redirect-HTTP-to-SSL-VPN/ta-p/339282#:~:text=The'Redirect%20HTTP%20to%20SSL%20VPN'%20option%20in%20the%20FortiGate,HTTPS%20version%20of%20the%20page.
Hello Alberto Please refer the below link
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-an-IPsec-tunnel-with-Overlapping/ta-p/242267
Thanks & Regards Mayank Sharma
Hello Please refer below link to verify it from debug
logshttps://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SAML-group-mismatch-issue-in-SSL-VPN/ta-p/193640Thanks
& Regards Mayank Sharma
Hello Meni You can check for few things If you are pinging FQDN which is
hosted internally then check if you have configured DNS server in SSL
settingsThe second condition is if you have configured DNS in SSL
settings and you are resolving public DNS...
Hello This is the expected behaviour of SSL VPN Web mode. First user
connect with firewall and when traffic goes to LAN it takes LAN
interface IP address in source.Thanks & RegardsMayank Sharma