Description This article describes how to find the cause for traffic
getting dropped with the error 'policy-4294967295 is not active'. Scope
FortiGate. Solution When traffic is dropped due to a forward policy
check fail, collect the flow debug. The i...
Description This article describes how to enable assigning Threat levels
for blocked categories. Scope FortiSASE. Solution It is possible to see
an informational notification on Web-filter FortiGuard as mentioned
below for the blocked category. It ha...
Description This article describes how to validate the on-fabric rule
match status on endpoint using the Forticlient Diagnostic Tool. Scope
FortiSASE. Solution Once the configuration is completed according to the
following admin guide for on-fabric d...
Description This article describes how to troubleshoot FortiClient (FCT)
management connection issues with FortiSASE. Scope FortiSASE, EMS.
Solution EMS is one of the backend components in FortiSASE, and
FortiClient uses a telemetry connection for ma...
Description This article describes how to perform an SSL VPN debug
specific to a Point of Presence (PoP) in FortiSASE. Scope FortiSASE.
Solution In FortiSASE, customer access to backend devices is limited,
which restricts advanced troubleshooting cap...
Hi @yeowkm99 Based on the update, I understand that from Firewall Lan IP
as a source your not able to ping other network. Also when you mentioned
that from Lan to Lan reachability is fine, Was this validated from both
direction? Is Nat enabled on the...
@Akmostafa , Can you confirm if your have the FGT added to FAZ(which is
having IOC license). Also check if the blocked user source is getting
listed for the below command. diag user quarantine list or diag user
banned-ip list
Hi @joshow , I missed the part of cert error mentioned. As checked the
CN/SNI in SSL certificate we not get matched even with deep-inspection.
Suggesting to use Web-filter along with DNS-filter. Regards, Patterson
Hi @joshow , I understand that your looking for a replacement message if
the DNS filter is blocking the access based on your configuration. Since
this is a DNS query initiated, FGT can't responds back with http
responds. Instead we have the option to...
Hi Vassilis, I think we got the issue !!! Please change the Action
execution from Parallel to Sequential. The issue was occurring for me
also, when set to parallel... Regards, Patterson