Search results
Resources
Up to 25 matches in the local ASN name index.
Tools
- FortiGate Address Group Generator — Create an IPv4 address group snippet from existing object names.
- FortiGate Bulk Address Object Generator — Generate FortiOS address objects from IPv4 lists or name,cidr CSV, preview the batch, and copy or download the CLI configuration.
- FortiGate Service Object Generator — Generate a TCP or UDP destination-port service object for FortiOS.
Guides
- FortiGate BGP commands for neighbors and route verification — Check FortiGate BGP state, accepted and advertised routes, and routing-table installation. Diagnose one peer without resetting the BGP session.
- FortiGate Cannot Delete an Interface or Its Address Object — Remove an automatically created interface-subnet object or an obsolete packet-capture reference using the documented correction.
- FortiGate Config Migration: Interface Mapping and Import Errors — Troubleshoot cross-model FortiGate imports with config-error-log, interface dependency mapping and a comparison of the loaded configuration.
- FortiGate Conserve Mode During FortiGuard Updates — Apply Fortinet’s scoped IPS-update memory workaround on 2 GB models and identify the related fixed high-CPU defect.
- FortiGate DNS cache and NTP diagnostic commands — Inspect FortiGate FQDN resolution and NTP synchronization. Distinguish cached addresses, DNS reachability, clock offset and time-zone display.
- FortiGate HA status and configuration synchronization commands — Inspect FortiGate FGCP members, roles and configuration checksums. Localize a synchronization mismatch without forcing failover or resynchronization.
- FortiGate Hardware Offload Problems: NPU/ASIC Fixes and Workarounds — Traffic works until FortiGate offloads it? Find scoped NPU/ASIC fixes for IPsec, QinQ, NP6 failback and SoC5 shaping, with CLI commands and fixed releases.
- FortiGate IKE Debug Shows No Output — Check VDOM, inherited filters, log-filter versus log filter syntax and whether a negotiation is actually starting.
- FortiGate IKEv1 to IKEv2 Site-to-Site Migration — Convert an existing route-based FortiGate tunnel to IKEv2: phase 1 changes, peer IDs, Child SA selectors and common negotiation failures.
- FortiGate IPsec Tunnel Up but Traffic Stops Intermittently — Diagnose intermittent IPsec data loss using Child SA rekey, tunnel counters, routing and narrowly scoped hardware-offload issues.
- FortiGate IPsec Up but a New Subnet Has No Traffic — Trace one new protected network through Child SA selectors, routing, policy, NAT and the destination host’s return path.
- FortiGate IPsec with Overlapping Subnets: NAT and Selectors — Map overlapping VPN networks to distinct translated prefixes and align FortiGate selectors, routes, IP pools, VIPs and reverse traffic.
- FortiGate Local-In Policy: Management Access and Rule Order — Troubleshoot FortiGate management access using interface services, trusted hosts and local-in rule order, with a scoped CLI example.
- FortiGate Policy Routing Between VDOMs Fails RPF — Fix an inter-VDOM policy-routing RPF drop when a suitable kernel return route cannot be used, with an exception on the receiving VDOM link.
- FortiGate SD-WAN diagnostic commands for members, SLA and rules — Check FortiGate SD-WAN health, members and rule selection. Use the right service command for your FortiOS version and verify the actual flow.
- FortiGate SSL VPN Support Matrix by Model and FortiOS Version — Check which FortiGate models still support FortiClient SSL VPN, the last working FortiOS version, upgrade cutoffs, and where Agentless VPN remains.
- FortiGate and FAC commands for IKEv2 MFA troubleshooting — Correlate FortiGate IKE and RADIUS authentication with FAC push approval. Capture one login, identify timeout boundaries and stop debugging cleanly.
- FortiGate debug flow commands: filter, capture and stop — Run a bounded FortiGate debug flow for one connection. Understand policy, route and session messages, then stop debugging and clear filters.
- FortiGate interface, ARP and error counter commands — Inspect FortiGate link state, interface counters and ARP resolution. Compare counter changes and separate physical faults from Layer 3 problems.
- FortiGate packet capture commands and useful filters — Capture one FortiGate traffic flow with bounded sniffer commands. Find ingress, egress and replies, account for NAT, and stop captures safely.
- FortiGate route lookup and policy route commands — Check the route to a destination and match a complete flow against FortiGate policy routing. Separate route availability from forwarding decisions.
- FortiGate session table commands for policy and NAT checks — Filter FortiGate sessions by client, destination and port. Read policy IDs, NAT actions and reply counters without clearing live connections.
- FortiGate “no proposal chosen”: IKE, ESP and DH Checks — Troubleshoot FortiGate proposal errors by tunnel selection, IKE/ESP transforms, PRF, DH, PFS and the failed negotiation stage.
- FortiClient IKEv2 Migration: Enable EAP and Restore User Groups — Fix the PSK/local-user migration settings: enable EAP, restore policy groups and remove the conflicting tunnel-level group binding.
- Network Commands Compared: FortiGate, MikroTik, Junos and Cisco — Find interface, IPv4 route and BGP inspection commands across FortiGate, MikroTik, Junos and Cisco, with context and links to detailed references.