Troubleshooting Common Deployment Issues
General, independent guidance for common connectivity, licensing, and configuration issues. For deployment-specific or account-specific problems, contact official Fortinet support or an authorized partner.
FortiClient VPN won't connect
Confirm the correct server address and port are configured, check that the account and any required certificate are valid, and verify general internet connectivity outside the VPN client first.
Licensing shows as invalid or expired
Check the licensing/registration status in the management interface, confirm the license hasn't actually expired, and verify the device has connectivity to Fortinet's licensing servers if validation is failing.
Firmware update fails or device won't boot after upgrade
Always review release notes and supported upgrade paths before updating, since skipping required intermediate versions is a common cause of upgrade issues. Keep a known-good backup configuration before any firmware change.
High availability (HA) cluster won't sync
Confirm both devices are running the exact same firmware version, check the HA heartbeat interface cabling and configuration, and verify both units have matching HA configuration settings.
Traffic is being blocked unexpectedly
Review the relevant firewall policy order and logic, since policies are commonly evaluated top-to-bottom and an earlier rule can unintentionally block traffic before a later, intended rule is reached. Check logs for the specific policy that matched the blocked traffic.
SSL inspection breaking a specific website or app
Some applications use certificate pinning or other mechanisms incompatible with SSL inspection; check whether an exemption is needed for that specific destination rather than assuming a general misconfiguration.
FortiClient EMS not showing an endpoint as connected
Confirm the endpoint's FortiClient installation is actually running and pointed at the correct EMS server address, and check basic network connectivity between the endpoint and the EMS server.
Performance seems slower than expected after enabling deep inspection features
Features like full SSL inspection and deep packet inspection add processing overhead; check current hardware utilization and consider whether the specific deployment's throughput needs match the device's rated capacity for those features enabled.
No topics matched your search. Try a different keyword.