Description This article explains how to work around when changing the
'ip-fragmentation' settings for a Dial-up IPsec VPN tunnel is not taking
effect immediately. Scope FortiGate Solution Consider the following
setup: On the Hub location, a dynamic ...
Description This article describes how it can be avoided to SNAT all
traffic to VIP extip with 'set snat-source-vip enabled' and central-snat
is enabled on the FortiGate. Scope FortiOS. Solution As explained in
this article, Technical Tip: How to use...
Description This article describes a scenario where FortiGate fails to
redistribute BGP routes into OSPF Scope FortiGate. Solution There are
two Hub locations, i.e., Hub1 and Hub2. On Hub locations, the BGP route
is learned from Spoke, which then get...
Description This article describes the reason behind the DHCP failing
when having DHCP relay on FortiGate with dynamic VLAN change for the
DHCP client Scope FortiGate. Solution With a DHCP request received on
the VLAN 15, it will be relayed to the DH...
Description This article describes the scenario where a working stops
working and an RST response packet can be seen on the FortiGate. Scope
FortiGate, FortiOS, SSL VPN. Solution SSL VPN configured is fully
functional. However, it stops working witho...
Hi Balazs, The selection of FOS is usually based on the requirements or
features you are going to use. The latest version is 7.2 I would suggest
going through the release notes that highlight any known issues. If
there are known issues that are point...
Hi CustomX, For this, you will have to check how the traffic is getting
routed and might need Firewall policies with NAT between two interfaces.
This way you can perform source NAT and change the source as you like by
either using the IP address of t...
Hi Ranjith, This article might help:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuration-per-VDOM-DNS/ta-p/190815
Thank you. Shahan
Hi mhanna, A static route is necessary to ensure that traffic is going
via the correct interface. In the VPN setting, for phase2 when you add a
local subnet and a remote subnet, this ensures that traffic between
these two subnets can flow over the VP...