FortiClient Azure Authentication
FortiClient Azure KB ID 0001797 Problem More and more people are using Azure as their primary identity provider, thanks in no small part to the massive success of Office/Windows 365. So if you want to provide a FortiGate/FortiClient SSL remote access VPN solution then securing it via Azure makes a lot of sense. Multi Factor Authentication: If you have MFA on your Azure accounts then that’s a big box ticked for your...
FortiGate DNS: Serving DNS Databases
Fortigate DNS KB ID 0001796 Problem A colleague rang to ask if I had any thoughts about a problem that they were having, we do a lot of VMware VCSA upgrades for customers, the process fails if there is no DNS resolution of the FQDN during the upgrade process. We had tried to fix the problem by creating hosts records (typically we don’t have access to the client’s DNS servers that run in the virtual environment). I had...
FortiClient SSL VPN Error
VPN Error KB ID 0001795 Problem I have a FortiGate/FortiClient test bench setup for testing, and its to been used for a while. When I attempted to use it this happened; Unable to logon to the server. Your username or password may not be configured properly for this connection. (-12) While messing around trying to fix it I also got this error; Unable to establish the VPN connection. The VPN server may be unreachable. (-14) Disclaimer:...
FortiGate FSSO AD Groups not Appearing?
FSSO KB ID 0001794 Problem While recently needing to add a new AD group to my firewalls FSSO setup, (to be used in a policy.) The new group could not bee seen (it’s called GS-Web-Block-Override). FSSO Force Sync The common fix for this is to create a filter on your FSSO agent server, that will ONLY look of the groups you specify like so. However, in my case that didn’t work either! I spent ages trawling Forti pages and...
FortiGate Certificate Import Errors
FortiGate Certificate KB ID 0001791 Problem A colleague messaged me last week because he could not import a certificate on a FortiGate (that had been exported from a Cisco ASA). He was seeing this error; Incorrect certificate file format for CA/LOCAL/CRL/REMOTE cert. FortiGate Certificate Problems A brief Google led me to ask “Is the FortGate licensed or on a Free/Trial license?” As that can produce this error...
FortiGate TFTP : Backup To & Restore From
FortiGate TFTP KB ID 0001788 Problem I know FortiGate prides itself on being able to do everything from the GUI, but if you can only get in at CLI and need to take a backup then you need to go old school. Recently I had an HA Pair of Fortis, the primary had broken and I could not get access to the GUI on the standby. My plan was to get a backup, blow both (virtual Firewalls) away, deploy two new ones, and restore the config. What...