Description This article describes how to enable and require client
certificates for specific URLs only. Scope FortiWeb and FortiWeb-VM
Solution Prerequisite: Enable the Client Certificate Verification in
FortiWeb Server Policy by following the guide...
Description This article describes how to fix the issue where the web
application is inaccessible after the Windows Server IIS Centralized
Certificate Store (CCS) is enabled for the Real Server. Scope FortiWeb
and FortiWeb-VM. Solution Windows Server...
Description This article describes how to get the FortiAppSec Cloud WAF
(FortiWeb Cloud) respective application IP list for firewall
whitelisting. Scope FortiAppSec Cloud WAF. Solution Step 1: Access the
FortiAppSec Cloud portal (https://appsec.forti...
Description This article describes what causes the error message and the
possible options to fix it. Scope FortiADC and FortiADC VM. Solution The
FortiADC will log the error 'AV engine meet error: out of memory'
message in the AV Security log when th...
Description This article describes how to troubleshoot the 'Invalid
Application ID, Directory ID, or Client Secret' error when adding an
Office365 account in FortiCASB. Scope FortiCASB. Solution FortiCASB
gives an 'Invalid Application ID, Directory I...
Hi rafaelrosseto88, Hope you're doing well. You may need to add below
Attributes mapping (UPN - EPPN) in the SAML Azure IdP. Below sample is
for SAML Microsoft Entra ID. The FortiWeb will show the respective
Username for the respective Traffic Log. Y...
Hi ys1, Hope you're doing well. Currently, there's no tool or converter
to migrate the FortiWAN configuration to the FortiADC. You may need to
adapt the configuration on the FortiADC manually. You may review below
documentation on the FortiADC Link L...
Hello Forti_New, Hope you're doing well. For Q1. The disk capacity is
the hardware spec for the said model. It is not possible to change it.We
would suggest to use external logging device for the FortiWeb logs such
as FortiAnalyzer.
https://docs.fort...
Hello @TBC, Please see below replies; > Do I need to request a separate
certificate for each domain? Yes. >Do all domains also have to be
reachable via port 80? You may want to check Letsencrypt's article
below: 1- Best Practice - Keep Port 80 Open
h...