Description When attempting to log in using local users configured on
FortiAuthenticator, authentication may fail with the following error in
debug logs: Credential::GetSerialization: Local user is not allowed to
log into PC [Credential.cpp:1140] Cre...
Description This article describes the configuration of BGP neighborship
using a loopback interface over IPsec (site-to-site). Scope FortiGate.
Solution Topology: Configuration on ISP1: Loopback interface
configuration: config system interface edit "...
Description This article describes the reason for the error: 'Please
enter correct credentials'. Scope FortiGate, FortiAuthenticator.
Solution After having entered the user details in the guest captive
portal for user creation, on the subsequent atte...
Description This article describes the significance of auth timeout and
login session timeout when FortiAuthenticator is acting as an IDP Scope
FortiGate, FortiAuthenticator. Solution When configuring
FortiAuthenticator as an IDP two timers should be...
Description This article describes verifying if the UDP port is
unreachable when troubleshooting the Syslog server. Scope FortiGate.
Solution Telnet protocol can be used to check TCP connectivity for IP
and port but In the case of UDP Telnet cannot b...
Hello Please refer below link to verify it from debug
logshttps://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SAML-group-mismatch-issue-in-SSL-VPN/ta-p/193640Thanks
& Regards Mayank Sharma
Hello Meni You can check for few things If you are pinging FQDN which is
hosted internally then check if you have configured DNS server in SSL
settingsThe second condition is if you have configured DNS in SSL
settings and you are resolving public DNS...
Hello This is the expected behaviour of SSL VPN Web mode. First user
connect with firewall and when traffic goes to LAN it takes LAN
interface IP address in source.Thanks & RegardsMayank Sharma
Hello It seems DNS is not getting resolved. Please check if DNS IP
address is assigned by fortigate.If DNS server is behind firewall you
can create DNS and it will be pushed towards the client Thanks & Regards
Mayank Sharma
Hello Please refer this link to get an Idea of configuration
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Hosted-NAT-Traversal-for-SIP/ta-p/197508
Thanks & Regards Mayank Sharma