Description This article describes how to advertise a static route with
a gateway IP in the BGP or ADVPN. Scope FortiOS 6. x.x, 7. x.x. Solution
If an advertised static route in the BGP includes a gateway IP, the BGP
next hop address will point to th...
Description This article describes how to Synchronize FortiClient
Endpoints/Users Across the Security Fabric. Scope FortiGate v6.x.x and
v7.x.x. Solution When FortiGates are connected in a security fabric
setup, the firewalls can only show the local ...
Description This article describes the scenario when Host machines
remained quarantined despite being removed from the quarantine/banned IP
list. Scope FortiGate v5.x.x, v6.x.x and v7.x.x. Solution When FortiGate
triggers rate-based IPS signatures, f...
Description This article describes that the SSL VPN client certificate
authentication prompt will appear for all the groups even if it is
enabled for a single group. FortiGate v6. x.x and v7. x.x. Solution If
the client certificate authentication is ...
Description This article describes that WSSO SSID users fail to
authenticate when using a local group with a Radius server but can
authenticate directly with Radius server authentication. Scope FortiGate
v6.x.x and v7.x.x. Solution Example: FortiGate...
As you mentioned, the server can see the DHCP discover messages(I assume
that the above packet capture is taken on the server) but sends a reply
with an ICMP error port unreachable, which implies that the DHCP service
is not running on 10.5.1.6. The ...
Capture ESP traffic on the wan interface of the firewalls(When issue is
present): di sniffer packet any 'host ' 6 0 a and
decrypt the esp traffic using Wireshark. This capture can also be
performed from GUI network--> diagnostics. In the decrypted pc...
Don't use the relay type"IPsec" becuase this option is for assigning
DHCP addresses to the remote VPN clients (for example dialup IPsec). In
this case, you should use the type as "Regular"
https://docs.fortinet.com/document/fortigate/6.4.5/administra...
There is a known bug in FortiOS 7.2.8--> 925554--> On the Network >
Interfaces page, hardware and software switches show VLAN interfaces as
down instead of up. The actual status of the VLAN interface can be
verified using the commandline :
https://do...
What Foritgate Model do you use?In the case of NP7 and NP6
Platforms(Including lite versions) under heavy load situations, packet
reordering problem can be handled by the following command config
firewall policy set delay-tcp-npu-session enable Pleas...