Fortinet
VPN
Troubleshooting
An IPsec tunnel that won't come up is almost always a proposal mismatch — encryption, authentication, DH group or lifetime not agreeing. How to tell Phase 1 from Phase 2, read the "no proposal chosen" debug, compare both sides in one table, and align them (plus why lifetime rarely blocks the tunnel).
2026-07-31 · 9 min read
Open the walkthrough →
Fortinet
VPN
Troubleshooting
The four most-reported FortiClient SSL-VPN errors, each mapped to the layer that failed — -14 credentials, -8 lockout, -20199 reachability, -5029 TLS — with the client-side fix and the FortiGate-side check for each.
2026-07-31 · 8 min read
Open the fixes →
Fortinet
Networking
Troubleshooting
The built-in GUI/CLI toolbox, the two commands that crack most cases (debug flow + sniffer), and a section per issue — connectivity, policy, VPN, performance, DNS & routing — each with the copy-ready command, a sample of the output, and the insight that makes it click.
2026-07-31 · 12 min read
Open the playbook →
Fortinet
Hardening
Troubleshooting
Fortinet's recommended response to the FortiBleed credential-exposure campaign, as an actionable runbook — terminate sessions and reset credentials, enforce MFA, upgrade and enforce PBKDF2, validate the config, check logs, and lock down management access.
2026-07-31 · 9 min read
Open the checklist →
Fortinet
Networking
Troubleshooting
Traffic to a service behind an FQDN firewall address object drops intermittently when the DNS record's TTL is 0 and the resolver round-robins its answers — the FortiGate's cached IP set and the client's connection drift apart. Why it happens, how to prove it, and why raising the TTL fixes it.
2026-07-29 · 8 min read
Open the walkthrough →