This site uses cookies. Some are essential to the operation of the site; others help us improve the user experience. By continuing to use the site, you consent to the use of these cookies. To learn more about cookies, please read our privacy policy. Accept...
© 2025 Fortinet, Inc. Privacy Policy Legal This site uses cookies. Some are essential to the operation of the site; others help us improve the user experience. By continuing to use the site, you consent to the use of these cookies. To learn more about cookies, please read our privacy...
© 2025 Fortinet, Inc. Privacy Policy Legal This site uses cookies. Some are essential to the operation of the site; others help us improve the user experience. By continuing to use the site, you consent to the use of these cookies. To learn more about cookies, please read our privacy...
If you are using a FortiOS 6.0.1 or later: config system interface edit <name> set preserve-session-route enable next endIf you are using a FortiOS 6.0.0 or earlier: config vpn ssl settings set route-source-interface enable endTo troubleshoot users being assigned to the wrong IP range:...
Troubleshoot WAD with real-time debugs to understand how the proxy handled a client request: # diagnose wad debug enable category all # diagnose wad debug enable level verbose # diagnose debug enable [0x7fbd7a46bb60] Received request from client: 10.10.10.20:56312 GET / HTT...
This site uses cookies. Some are essential to the operation of the site; others help us improve the user experience. By continuing to use the site, you consent to the use of these cookies. To learn more about cookies, please read our privacy policy. Accept...
The diagnose debug application ike -1 command is the key to troubleshoot why the IPsec tunnel failed to establish. Run the diagnose vpn ike gateway list command on the HQ FortiGate. The system should return the following: vd: root/0 name: for_Branch_0 version: 1 interface: wan...
Troubleshoot an HA formation Check HA sync status Disabling stateful SCTP inspection Upgrading FortiGates in an HA cluster HA cluster setup examples HA active-passive cluster setup HA active-active cluster setup HA virtual cluster setup HA using a hardware switch to replace a physical...
Use the following diagnose commands to check IPsec phase1/phase2 interface status including the sequence number on the secondary FortiGate. The diagnose debug application ike -1 command is the key to troubleshoot why the IPsec tunnel failed to establish....
Both ping and traceroute require particular ports to be open on firewalls to function. Since you typically use these tools to troubleshoot, you can allow them in the security policies and on interfaces only when you need them. Otherwise, keep the ports disabled for added securit...