Description This article describes how, when creating a new VPN
connection with v7.4.1 or v7.4.2 that uses IKEv2 as the protocol with
the default VPN settings, NAT-T is disabled. Scope Users connecting from
the same public IP or sitting behind a NAT ...
Description This article describes that when upgrading a FortiGate to
v7.6.1, the GUI shows LAN interfaces that have an IP address in the
network ranges 172.31.0.0/16 or 192.168.0.0/16 to be managed by IPAM
even though the feature is globally disable...
Description This article describes the case when there is
TS_UNACCEPTABLE coming up during IKE debugs. Scope IKEv2 IPsec tunnel on
FortiGate. Solution When troubleshooting IKEv2 IPsec tunnels, the
following error in IKE debugs can be observed: ike V=...
Description This article covers a specific scenario where, due to a PFS
mismatch, an IKEv2 tunnel will result in a tunnel flap at each IPSec
rekey even though it comes up initially. Another scenario can be where
the first IPsec SA comes up, however, ...
Description This article addresses how to disable AES CBC ciphers for
SSL VPN and Admin GUI Access (HTTPS). Scope FortiGate, SSL VPN, HTTPS,
GUI, CBC (Cipher-Block-Chaining). Solution As vulnerability scanners are
starting to report AES CBC ciphers a...