{"allowContribute":false,"item":{"activeCommit":"752a726e0b3e17e008fb8e80faf53dccdb119fac","apis":{"routes":[{"method":"POST","path":"/api/notify-line"},{"method":"POST","path":"/api/fetch-follower-id"},{"method":"POST","path":"/__webhook__/line-notify"},{"method":"POST","path":"/__webhook__/fetch-follower-id"}],"types":{}},"backendSchedules":[],"bundleHash":"25480da3da9376c8","createdAt":1786804820374,"displayName":"Fortinet 情報儀表板","gitCommit":"752a726e0b3e17e008fb8e80faf53dccdb119fac","id":"ff7d7f30e15480f5abf8021e","isPublic":true,"itemType":"PLUGIN","name":"Fortinet 情報儀表板","pluginDir":"ff7d7f30e15480f5abf8021e","repositoryID":"repo_6e75c256398cb21f237676c5","status":"active","updatedAt":1787359049818,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":27},"ownerMemberId":"6a8078820109edc319b69b","ownerName":"Daniel Kay","publicPlugins":{"PLUGIN":{"pluginItemId":"ff7d7f30e15480f5abf8021e","pluginDir":"ff7d7f30e15480f5abf8021e","bundleHash":"25480da3da9376c8","live":true}},"subtree":[{"activeCommit":"752a726e0b3e17e008fb8e80faf53dccdb119fac","apis":{"routes":[{"method":"POST","path":"/api/notify-line"},{"method":"POST","path":"/api/fetch-follower-id"},{"method":"POST","path":"/__webhook__/line-notify"},{"method":"POST","path":"/__webhook__/fetch-follower-id"}],"types":{}},"backendSchedules":[],"bundleHash":"25480da3da9376c8","createdAt":1786804820374,"displayName":"Fortinet 情報儀表板","gitCommit":"752a726e0b3e17e008fb8e80faf53dccdb119fac","id":"ff7d7f30e15480f5abf8021e","isPublic":true,"itemType":"PLUGIN","name":"Fortinet 情報儀表板","pluginDir":"ff7d7f30e15480f5abf8021e","repositoryID":"repo_6e75c256398cb21f237676c5","status":"active","updatedAt":1787359049818,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":27},{"createdAt":1787012472241,"deletedAt":null,"id":"default_fortinet_question_folder_6a8078820109edc319b69b","isNew":false,"isPublic":false,"itemType":"FORTINET_QUESTION_FOLDER","name":"LINE 提問","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"fortinet":1787012472241},"preParentID":null,"reviewedAt":1787058751000,"updatedAt":1787059113187,"updatedBy":{"agentId":"ceo","agentName":"CEO","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":2},{"answer":"這兩個料號都是給 **FortiGate 60F (FG-60F)** 用的續約/授權料號，硬體型號完全一樣，差別在於 **包含的服務內容**，`DD` 只是年期的佔位符。\n\n### 1. 料號拆解\n\n\u003e Fortinet 料號規則：`FC-10-XXXXX-YYY-ZZ-DD`\n\u003e *   `FC` = FortiCare 服務\n\u003e *   `10` = FortiGate 產品線\n\u003e *   `0060F` = 適用機型 FG-60F\n\u003e *   `YYY` = 服務組合包代碼 **這就是 131 和 585 的差異**\n\u003e *   `02` = 24x7 TAC 支援等級\n\u003e *   `DD` = 年期，常見為 `12`=1年 / `36`=3年 / `60`=5年，實際下單會寫成如 `FC-10-0060F-131-02-12`\n\n| 料號 | 官方完整名稱 | 定位 |\n| :--- | :--- | :--- |\n| **FC-10-0060F-131-02-DD** | **FortiGate-60F 1/3/5 Year FortiCare Premium Support** | **純支援服務** |\n| **FC-10-0060F-585-02-DD** | **FortiGate-60F 1/3/5 Year FortiGuard Unified Threat Protection (UTP)** | **支援 + 安全防護 Bundle** |\n\n**一句話總結：585 = 131 + 一整套 FortiGuard 安全服務。買了 585 就不用再買 131，重複購買會造成授權重疊。**\n\n### 2. 詳細內容差異\n\n**FC-10-0060F-131-02-DD [僅 FortiCare]**\n*   包含：24x7 Fortinet TAC 技術支援、RMA 硬體保固換修、韌體升級 (FortiOS) 權限、FortiGuard 韌體更新查詢\n*   **不包含**：任何 FortiGuard 安全特徵庫更新。IPS、應用程式控管、防毒、網頁過濾、DNS 過濾等功能到期後將無法更新特徵庫。\n\n**FC-10-0060F-585-02-DD [UTP Bundle - 最常見的組合]**\n*   **已完整包含 131 的所有 FortiCare Premium 內容**\n*   額外包含 FortiGuard 安全服務，通常為以下 5-6 項：\n    1.  IPS 入侵防禦\n    2.  AntiVirus 防毒 / Fortisandbox Cloud\n    3.  Web Filtering 網頁過濾\n    4.  DNS Filtering\n    5.  Application Control 應用程式控管\n    6.  AntiSpam (若有啟用 Email 相關功能)\n*   這是讓 FG-60F 上的 UTM / NGFW 功能能持續正常運作的必要授權。\n\n\u003e 提醒：Fortinet 近年已將 UTP/ATP/Enterprise Protection 重新命名，585 在新版報價單上可能標示為 `FortiGate UTP` 或 `FortiGuard + FortiCare Premium`，但 `585` 這個核心代碼定義不變。實際包含項目建議查閱官方 Ordering Guide 或請代理商提供 BOM 表確認。\n\n### 3. 檢查點與如何確認你需要哪一個\n\n**適用產品/版本：** 僅適用於 FG-60F / FG-60F-BP 等 60F 系列，不適用於 FG-61F / FG-70F / FG-80F。\n\n**購買前檢查步驟：**\n1.  到 FortiGate CLI 檢查現有授權：\n    ```\n    get system status\n    diagnose autoupdate version\n    get system fortiguard-service status\n    ```\n2.  到 GUI `Dashboard \u003e Status \u003e Licenses` 查看 `FortiCare Support` 和 `FortiGuard Services` 的到期日。\n3.  到 `support.fortinet.com \u003e Asset Management` 輸入序號，確認目前綁定的合約到期日，決定要續多久 (12/36)。\n\n### 4. 風險與 Workaround\n\n*   **風險 1：買錯 131 導致斷防護**\n    若你的防火牆政策有啟用 UTM Profile (AV/IPS/Web Filter)，但只續了 131，FortiGuard 到期後，依 `System \u003e FortiGuard \u003e FortiGuard Options` 的設定，會變成 `Fail Close` 阻擋流量或 `Fail Open` 無防護，且特徵庫停留在過期版本，有資安風險。\n\n*   **風險 2：重複購買**\n    已有 585 又加買 131，不會延長 FortiGuard 時間，只會延長 FortiCare，浪費預算。\n\n*   **Workaround：**\n    若預算有限且真的不需要 UTM，只當純 VPN/防火牆使用，買 131 即可。若之後又需要 FortiGuard，可單獨加購 FortiGuard 單項服務，但單買總價通常比直接買 585 Bundle 貴。\n\n### 5. 建議下一步\n\n1.  **有開 UTM/上網管控的一般企業：** 直接選 **FC-10-0060F-585-02-DD**，依需求選 12/36。這是 95% 客戶的標準選擇。\n2.  **純做 VPN/路由、完全沒開 AV/IPS/Web Filter：** 可選 **FC-10-0060F-131-02-DD** 節省成本。\n3.  下單前請代理商提供正式 `BOM List` 並註明到期日是否 `Co-Term (續到同一天)`，避免授權天數不連續。\n\n\u003e 你提供的情報中沒有與此料號相關的 Bug/漏洞公告，故無需引用。\n\n需要我幫你看一下嗎？你可以貼一下 `get system status` 裡 `License Status` 的截圖或到期日，我幫你判斷續 131 還是 585 比較划算，以及該續 1 年還是 3 年最符合成本。","count":1,"createdAt":1787202920240,"id":"57a23630770d323fcf5f87be","isFortinetRelated":true,"itemType":"FORTINET_QUESTION","lastAskedAt":1787202920237,"lastUserId":"Ucaee8f51070d72ca4da541d75d4bbba1","lineUserIds":"Ucaee8f51070d72ca4da541d75d4bbba1","name":"FC-10-0060F-585-02-DD和FC-10-0060F-131-02-DD有什麼差異","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_question_folder_6a8078820109edc319b69b":1787202920237},"question":"FC-10-0060F-585-02-DD和FC-10-0060F-131-02-DD有什麼差異","tags":"[]","updatedAt":1787202920240,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"variants":"[]","version":1},{"answer":"要讓使用者在 FortiGate 後面只能用公司網域 `＠company.com` 登入 Microsoft 365 / Azure AD，正確做法是用 **FortiOS Inline CASB 的 Tenant Restrictions 功能**，自動幫你插入 Microsoft 官方的 Tenant Restrictions Header，不是只靠 Web Filter 擋網址。\n\n這是目前最乾淨、Microsoft 官方也建議的做法。\n\n### 一、適用產品 / 版本\n\n* **產品：** FortiGate 全系列，含 VM\n* **版本：** FortiOS 7.4.1 以上才有 `Inline CASB`，建議使用 **7.4.4+、7.6.3+、8.0.1+** 功能最完整\n  \u003e 7.4.1-7.4.3 的 CASB 選項較少，建議查閱官方文件確認你版本 GUI 位置\n* **授權：** 不需額外 CASB 授權，需有 `Application Control` 授權且 Firewall Policy 有啟用 UTM\n* **必要條件：必須做 SSL Deep Inspection**，因為要解密 `login.microsoftonline.com` 才能插入 Header，明文流量無法控制\n\n\u003e **升級提醒：** 若你正計畫升級到 7.4.12 / 7.6.7，請注意目前有已知 Bug 會遺失部分 `system global` 設定，升級前請務必備份設定。[來源](https://community.fortinet.com/fortigate-3/troubleshooting-tip-partial-configuration-loss-after-upgrade-from-fortios-v7-4-11-and-fortios-v7-6-6-229443)\n\n### 二、運作原理\n\nMicrosoft 支援 [Tenant Restrictions V2]，只要在使用者連到 `login.microsoftonline.com / login.windows.net / login.microsoft.com` 時，HTTP Header 帶上以下兩個 Header，Microsoft 雲端就會直接拒絕非公司租戶/網域的登入：\n\n* `Restrict-Access-To-Tenants: \u003c你的 Tenant ID\u003e`\n* `Restrict-Access-Context: \u003c你的 Tenant ID\u003e`\n\nFortiGate Inline CASB 就是幫你在 Proxy 層自動插入這兩個 Header，使用者用個人 `＠gmail.com / ＠outlook.com` 登入時，Microsoft 會直接回 `This organization does not allow access from your account`。\n\n### 三、設定步驟\n\n#### 前置作業 1：取得公司 Tenant ID 與網域\n\n1. 到 Entra ID Portal `portal.azure.com` \u003e Microsoft Entra ID \u003e Overview\n2. 複製 `Tenant ID`，例如 `72f988bf-86f1-41af-91ab-2d7cd011db47`\n3. 確認公司主網域，例如 `company.com`\n\n#### 前置作業 2：準備 Deep Inspection\n\n1. `Policy \u0026 Objects \u003e Security Profiles \u003e SSL/SSH Inspection` 確認有 `deep-inspection` Profile\n2. 將 Fortinet CA 憑證透過 GPO / MDM 派送到所有 User 電腦，否則會出現憑證錯誤\n3. 建議在 Application Control 中阻擋 `QUIC`，並阻擋 DoH，避免流量繞過解密\n\n#### 步驟 1：建立 Inline CASB Profile\n\n**GUI 操作 FortiOS 7.4 / 7.6 / 8.0：**\n1. `Security Profiles \u003e Inline CASB` 或 `CASB \u003e CASB Profile`\n2. 點 `Create New` \u003e 名稱 `MS-Only-Company-Domain`\n3. `SaaS Application` 點 `Add` \u003e 選擇 `Microsoft 365` / `Microsoft Office 365`\n4. 啟用 `Tenant Control` / `Tenant Restrictions`\n5. `Allowed Tenants` 填入你的 Tenant ID\n6. `Allowed Domains` 填入 `company.com`，若有多個網域用逗號分隔\n7. `Action when tenant/domain not matched` 選 `Block`\n8. 儲存\n\n**CLI 範本：**\n```cli\nconfig casb profile\n    edit \"MS-Only-Company-Domain\"\n        config saas-application\n            edit \"office365\"\n                set casb-name \"Microsoft Office 365\"\n                set tenant-control enable\n                set allowed-tenants \"72f988bf-86f1-41af-91ab-2d7cd011db47\"\n                set allowed-domains \"company.com\"\n                set action block\n            next\n        end\n    next\nend\n```\n\u003e 不同版本參數名稱可能為 `set restrict-access-to-tenants` / `set casb-profile`，若指令報錯，建議查閱官方文件對應版本語法。\n\n#### 步驟 2：套用到 Firewall Policy\n\n將 CASB Profile 套用到所有對外上網的 Policy：\n\n```cli\nconfig firewall policy\n    edit 10\n        set name \"LAN-to-WAN-CASB\"\n        set srcintf \"internal\"\n        set dstintf \"wan1\"\n        set srcaddr \"all\"\n        set dstaddr \"all\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n        set utm-status enable\n        set ssl-ssh-profile \"deep-inspection\"\n        set application-list \"default\" \n        set casb-profile \"MS-Only-Company-Domain\"\n        set logtraffic all\n    next\nend\n```\nGUI 就是在 Policy 的 `Security Profiles` 區塊同時勾選 `SSL Inspection: deep-inspection` 和 `CASB Profile`。\n\n\u003e FortiManager 集中管理：`Policy \u0026 Objects \u003e Security Profiles \u003e CASB Profile` 建立後，透過 Policy Package 下發即可。\n\n### 四、檢查點與驗證\n\n1.  **用無痕視窗測試：**\n    * 用 `user@company.com` 登入 `portal.office.com` 應成功\n    * 用 `user@gmail.com` 或 `user@outlook.com` 登入應被 Microsoft 擋下，FortiGate 上 `Log \u0026 Report \u003e Security Events \u003e CASB` 會出現 `Action: Block`\n2.  **檢查解密是否生效：** `Log \u0026 Report \u003e Forward Traffic` 看該連線的 `SSL Inspection = deep-inspection`，若是 `no-inspection` 代表沒解密，CASB 不會生效\n3.  **除錯指令：**\n    ```cli\n    diagnose debug application wad -1\n    diagnose debug enable\n    # 然後重現登入，看是否有插入 Restrict-Access-To-Tenants header\n    ```\n4.  **確認涵蓋的 SaaS 網域：** FortiGate 內建的 Microsoft 365 已包含 `login.microsoftonline.com, login.windows.net, login.microsoft.com`，不需手動加\n\n### 五、風險與 Workaround\n\n| 風險 | 說明與解法 |\n| :--- | :--- |\n| **未做 Deep Inspection 就無效** | 這是最大地雷。Inline CASB 強制依賴解密，若 User 端未安裝 CA，會大量報錯。Workaround：先對 IT 測試群組 pilot，再全量推送憑證 |\n| **舊版 FortiOS 無 Inline CASB** | 7.2 含以下無此功能。Workaround：用 `Web Proxy Profile \u003e Header Filter` 手動插入 Header，但維護成本高，強烈建議升級到 7.4+ |\n| **已登入的 Session 繞過** | Tenant Restrictions 只在登入當下檢查，已登入的個人帳號 Session 不會被踢。解法：測試時務必清 Cookie / 無痕 |\n| **非瀏覽器 App 繞過** | 部分 Thick Client 會走不同驗證流程。建議同步在 Entra ID ","count":1,"createdAt":1787017449516,"id":"b42215af280ee230004b0cde","isFortinetRelated":true,"itemType":"FORTINET_QUESTION","lastAskedAt":1787017449508,"lastUserId":"Ucaee8f51070d72ca4da541d75d4bbba1","lineUserIds":"Ucaee8f51070d72ca4da541d75d4bbba1","name":"Fortigate如何設定inline CASB讓user 只能使用公司domain 登入Microsoft？","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_question_folder_6a8078820109edc319b69b":1787017449508},"question":"Fortigate如何設定inline CASB讓user 只能使用公司domain 登入Microsoft？","tags":"[\"FortiGate\"]","updatedAt":1787017449516,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"variants":"[]","version":1},{"answer":"在 FortiGate 上要做 SSID 的 MAC 白名單，是透過 **FortiGate 內建 Wireless Controller + MAC Filter** 來達成，不是直接在 SSID 密碼裡設定。以下給你完整作法，適用所有有接 FortiAP 的 FortiGate。\n\n### 一、適用產品 / 版本\n\n* **產品：** 任何有啟用 WiFi Controller 的 FortiGate + FortiAP / FortiAP-U 系列\n* **版本：** FortiOS 7.2 / 7.4 / 7.6 / 8.0 皆支援，CLI 語法略有差異，建議用 `?` 確認\n* **模式皆支援：** Tunnel 隧道模式 / Bridge 本地橋接模式 都可以做 MAC Filter\n\n\u003e 觀念：MAC Filter 是在「關聯 Association」階段就擋掉，不通過連密碼都無法取得 IP。分為 `allow 白名單` 和 `deny 黑名單` 兩種，你要的是 `allow`。\n\n### 二、設定步驟\n\n#### 方法1：GUI 圖形介面 - 最推薦新手\n\n1.  **建立 MAC 白名單清單**\n    `WiFi \u0026 Switch Controller \u003e Connectivity \u003e SSIDs` 或舊版 `WiFi \u0026 Switch Controller \u003e SSIDs`\n    \u003e 如果找不到，請先確認 `System \u003e Feature Visibility \u003e Wireless Controller` 已開啟\n\n    另一條路徑建立清單：\n    `WiFi \u0026 Switch Controller \u003e Connectivity \u003e MAC Filter` \u003e 點 `Create New`\n    * Name：`MAC-Whitelist-Office`\n    * 點 `Create New` 逐筆加入 MAC，格式 `00:11:22:33:44:55`\n    * Device / Description 可填註記方便管理\n\n2.  **套用到指定的 SSID / VAP**\n    `WiFi \u0026 Switch Controller \u003e Connectivity \u003e SSIDs` \u003e 編輯你要套用的 SSID\n    * 找到 `MAC Filter` 選項 \u003e 設為 `Enable`\n    * `MAC Filter Policy` 選 `Allow` 代表只允許清單內的 MAC，白名單\n    * `MAC Filter List` 選擇剛剛建立的 `MAC-Whitelist-Office`\n    * 按 `OK` 儲存\n\n    儲存後 FortiGate 會自動將設定 Push 到所有廣播此 SSID 的 FortiAP，約 10-30 秒生效。\n\n#### 方法2：CLI 指令 - 適合大量 MAC\n\n**步驟1：建立白名單**\n```bash\nconfig wireless-controller mac-filter\n    edit \"MAC-Whitelist-Office\"\n        set description \"辦公室 SSID 白名單\"\n        config filter\n            edit 1\n                set mac 00:11:22:33:44:55\n                set description \"主管筆電\"\n            next\n            edit 2\n                set mac AA:BB:CC:DD:EE:FF\n                set description \"會議室印表機\"\n            next\n        end\n    next\nend\n```\n\n**步驟2：綁定到 SSID / VAP**\n```bash\nconfig wireless-controller vap\n    edit \"你的SSID名稱\"  # 注意這是 vap 名稱，不是 ssid 字串，可用 show 查看\n        set mac-filter enable\n        set mac-filter-policy allow  # allow = 白名單, deny = 黑名單\n        set mac-filter-list \"MAC-Whitelist-Office\"\n    next\nend\n```\n\u003e **版本差異提醒：** 部分版本語法為 `set mac-filter-policy-allow enable` / `set selected-mac-filter-list`。若指令報錯，請在 `config wireless-controller vap` 下打 `set mac-filter ?` 查看你當前版本的正確參數，建議查閱官方文件為準。\n\n### 三、檢查與驗證\n\n設定完請做以下驗證：\n\n1.  **檢查 VAP 是否已套用：**\n    ```bash\n    get wireless-controller vap\n    diagnose wireless-controller wlac -c vap | grep -A5 \"你的SSID\"\n    ```\n\n2.  **測試連線：**\n    * 用白名單內的裝置連線 -\u003e 應可正常取得 IP\n    * 用不在清單的裝置連線 -\u003e 會在輸入密碼後直接被踢掉，無法取得 IP\n\n3.  **看 Log 判斷是否被擋：**\n    `Log \u0026 Report \u003e WiFi Events` 或 CLI：\n    ```bash\n    diagnose wireless-controller wlac -c station\n    execute log filter category event\n    execute log display\n    ```\n    被 MAC Filter 擋掉會出現 `station MAC blocked by mac-filter` 相關訊息。\n\n### 四、風險、限制與 Workaround\n\n1.  **MAC 很容易被偽造：** MAC Filter 只能防君子、防誤連，不能當作唯一安全機制。攻擊者可透過嗅探合法 MAC 並偽造繞過。務必搭配 WPA2/WPA3 強密碼或 802.1X。\n2.  **客戶端私密位址問題：** iOS / Android / Windows 預設會開啟「私密 Wi-Fi 位址 / MAC 隨機化」，會導致每次連線 MAC 都不同而被擋。**Workaround：** 要求使用者在該 SSID 設定中關閉「私密位址」，使用裝置真實 MAC。\n3.  **數量上限與管理成本：** 單一 MAC Filter List 預設上限約 256~512 筆，超過效能會下降且難維護。若超過 50 台以上，不建議用此方法。\n4.  **升級風險：** 若你近期有計畫升級 FortiOS，請注意目前 7.4.12 / 7.6.7 有已知升級遺失設定的 Bug，建議升級前先備份設定 `execute backup config usb`。\n\n### 五、進階建議：超過 50 台請改用 RADIUS\n\n如果你的白名單很多或人員異動頻繁，強烈建議改用 **RADIUS MAC 認證**，改由 FortiAuthenticator / Windows NPS / ClearPass 集中管理，就不用在 FortiGate 上一筆一筆 Key。\n\n架構：`SSID 安全模式改為 WPA2-Enterprise \u003e 啟用 RADIUS MAC Auth \u003e 在 RADIUS 上建 MAC 帳號`，FortiGate 會自動去 RADIUS 查詢，管理效率高很多。\n\n---\n需要我幫你直接產生指令嗎？你可以告訴我：\n1. 你的 FortiOS 版本是多少？`get system status` 可看\n2. 你的 SSID 名稱和 FortiAP 型號\n3. 要加入白名單的 MAC 有幾筆？\n\n我幫你把完整可貼上的 CLI 直接整理好給你。","count":1,"createdAt":1787015461339,"id":"d84e7c7a8035c128d478dda0","isFortinetRelated":true,"itemType":"FORTINET_QUESTION","lastAskedAt":1787015461331,"lastUserId":"U078b00507b427e0ff48040cc8fe67f34","lineUserIds":"U078b00507b427e0ff48040cc8fe67f34","name":"怎麼把MAC白名單加進FORTIGATE的SSID裡面","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_question_folder_6a8078820109edc319b69b":1787015461331},"question":"怎麼把MAC白名單加進FORTIGATE的SSID裡面","updatedAt":1787015461339,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"variants":"[]","version":1},{"answer":"您好，針對 FortiGate 60F 開啟 SSL VPN，我幫您整理成完整可落地的設定流程與注意事項。60F 屬於桌上型入門機種，功能完整支援 SSL VPN，但效能與併發數有限，需特別注意版本選擇與安全加固。\n\n### 一、適用產品 / 版本說明\n\n*   **適用硬體：** FortiGate 60F / 60F-3G4G 等全系列，支援 Tunnel Mode 與 Web Mode SSL VPN。\n*   **適用韌體：** FortiOS 7.2.x、7.4.x、7.6.x 皆支援。60F **不支援** FortiOS 8.0.0，8.0.0 僅支援含 NP7/NP7Lite 的高階機種。\n*   **版本建議：**\n    \u003e **重要提醒：** 若您目前在 FortiOS 7.4.11 或 7.6.6，請**暫緩升級至 7.4.12 / 7.6.7**。官方已公告自 7.4.11 -\u003e 7.4.12、7.6.6 -\u003e 7.6.7 可能遺失部分 `system global` 設定如 hostname、timezone 等 [Bug] 來源：https://community.fortinet.com/fortigate-3/troubleshooting-tip-partial-configuration-loss-after-upgrade-from-fortios-v7-4-11-and-fortios-v7-6-6-229443\n    \u003e 另 FortiOS 7.6.6 存在檢視記憶體 Forward Traffic Log 導致 GUI 凍結的 Bug #1205102，7.4.12 則有 Clearpass RADIUS/EAP 認證中斷的回報，若有用 RADIUS 需特別測試。來源：https://community.fortinet.com/fortigate-3/troubleshooting-tip-gui-freeze-when-viewing-forward-traffic-log-from-memory-after-upgrading-firmware-to-v7-6-6-229357\n\n    建議：新部署請優先選用官方標示為 Mature 的穩定版，例如 7.4 分支，並在變更前完整備份 `System \u003e Settings \u003e Backup`。若不確定版本支援，請以官方支援矩陣為準，建議查閱官方文件。\n\n### 二、前置檢查點\n\n1.  **授權與連線：** 確保有有效 FortiCare 授權，WAN 介面已有固定 IP 或 DDNS，且防火牆前無阻擋 TCP 10443 / UDP 443。\n2.  **憑證：** 預設使用自簽憑證會有瀏覽器警告，建議更換為 Let’s Encrypt 或內部 CA 簽發憑證：`System \u003e Certificates \u003e Create/Import`\n3.  **使用者來源：** 先決定要用 Local User、LDAP/AD 還是 RADIUS。若用 RADIUS/Clearpass 且考慮升級到 7.4.12，請先在測試環境驗證。\n4.  **IP 規劃：** 準備一個獨立的 SSL VPN IP Pool，不可與內網網段重疊，例如 `10.212.134.0/24`。\n\n### 三、設定步驟 (GUI + CLI 對照)\n\n#### 步驟 1：建立使用者與群組\n`User \u0026 Authentication \u003e User Definition \u003e Create New` 建立使用者，再到 `User Groups` 建立群組 `SSLVPN_Group` 並加入使用者。\n\u003e 若整合 AD/LDAP，請先在 `User \u0026 Authentication \u003e LDAP Servers` 測試連通性。\n\n#### 步驟 2：建立 SSL VPN Portal\n`VPN \u003e SSL-VPN Portals \u003e Create New`\n*   Tunnel Mode：啟用 `Enable Split Tunneling` 並設定 Routing Address (例如內網 192.168.1.0/24)，可大幅節省 60F 頻寬。\n*   Web Mode：依需求啟用 Bookmark。\n\n#### 步驟 3：設定 SSL VPN 全域參數\n`VPN \u003e SSL-VPN Settings`\n*   Listen on Interface(s)：選擇 `wan1` 或 `wan2`\n*   Listen on Port：預設 `10443`\n*   Server Certificate：選擇您的正式憑證\n*   Tunnel Mode Client Settings \u003e Address Range：選擇步驟4建立的 IP Pool\n*   Authentication/Portal Mapping：新增一條 `Group: SSLVPN_Group -\u003e Portal: full-access`\n*   啟用 `DTLS` 以提升 Tunnel Mode 效能\n\nCLI 對照：\n```bash\nconfig vpn ssl settings\n    set servercert \"your_cert\"\n    set tunnel-ip-pools \"SSLVPN_TUNNEL_ADDR1\"\n    set tunnel-ipv6-pools \"SSLVPN_TUNNEL_ADDR1\"\n    set port 10443\n    set source-interface \"wan1\"\n    set source-address \"all\"\n    set source-address6 \"all\"\n    set default-portal \"full-access\"\n    set dtls-max-proto-ver dtls1-2\n    set dtls-min-proto-ver dtls1-0\nend\nconfig vpn ssl web portal\n    edit \"full-access\"\n        set tunnel-mode enable\n        set split-tunneling enable\n        set split-tunneling-routing-address \"Internal_LAN\"\n    next\nend\n```\n\n#### 步驟 4：建立防火牆政策\n這是最常遺漏的一步，必須放行 SSL VPN 虛擬介面到內網：\n`Policy \u0026 Objects \u003e Firewall Policy \u003e Create New`\n*   Incoming Interface：`SSL-VPN tunnel interface (ssl.root)`\n*   Outgoing Interface：`internal` / `lan`\n*   Source：`SSLVPN_TUNNEL_ADDR1` + `SSLVPN_Group`\n*   Destination：`Internal_LAN`\n*   Action：`ACCEPT`，啟用 NAT 關閉，啟用 Log\n\nCLI：\n```bash\nconfig firewall policy\n    edit 0\n        set name \"SSLVPN to LAN\"\n        set srcintf \"ssl.root\"\n        set dstintf \"internal\"\n        set srcaddr \"SSLVPN_TUNNEL_ADDR1\"\n        set dstaddr \"Internal_LAN\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n        set groups \"SSLVPN_Group\"\n    next\nend\n```\n\n#### 步驟 5：用戶端連線\n1. 下載 FortiClient VPN (免費版) 或 FortiClient EMS 版本。\n2. 新增 SSL VPN 連線，輸入 FortiGate WAN IP:10443、使用者帳密。\n3. 連線後測試 `get vpn ssl monitor` 是否取得虛擬 IP。\n\n### 四、驗證與除錯指令\n\n```bash\n# 查看線上使用者\nget vpn ssl monitor\ndiagnose vpn ssl statistics\n\n# 即時除錯登入失敗\ndiagnose debug application sslvpn -1\ndiagnose debug enable\n# 完成後務必 diagnose debug disable\n\n# 檢查 Port 是否監聽\ndiagnose vpn ssl hw-acceleration-status\nexecute ping / traceroute 測試 Split Tunnel 路由\n```\n\nGUI 驗證：`Dashboard \u003e SSL-VPN Monitor` 與 `Log \u0026 Report \u003e VPN Events`\n\n### 五、風險與 Workaround\n\n1.  **安全風險：** SSL VPN 是近年攻擊熱點，Fortinet 已建議長期改以 ZTNA/IPsec Dial-up 取代。若必須使用 SSL VPN，請務必：\n    *   啟用 MFA (FortiToken / FortiAuthenticator / Email 2FA)\n    *   `VPN \u003e SSL-VPN Settings` 限制 `Restrict Access` 來源 IP / 地區\n    *   啟用 `Login Lockout` 與 `System \u003e Admin \u003e Brute Force` 防護\n    *   關閉不必要的 Portal，僅保留 Tunnel Mode\n\n2.  **效能風險：** 60F 官方建議 SSL VPN 併發約 15-30 人，超過會出現 CPU 滿載、DTLS 斷線。建議開啟 Split Tunnel，並避免讓所有流量回送 FortiGate。\n\n3.  **版本 Workaround：**\n    *   需升級但遇到上述 7.4.12/7.6.7 設定遺失 Bug：升級前執行 `execute backup config`，升級後立即 `show system global` 比對 h","count":1,"createdAt":1787014414133,"id":"30022d418936a0441b889550","isFortinetRelated":true,"itemType":"FORTINET_QUESTION","lastAskedAt":1787014414121,"lastUserId":"Ucaee8f51070d72ca4da541d75d4bbba1","lineUserIds":"Ucaee8f51070d72ca4da541d75d4bbba1","name":"FortiGate 60F 要怎麼開 SSL VPN？","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_question_folder_6a8078820109edc319b69b":1787014414121},"question":"FortiGate 60F 要怎麼開 SSL VPN？","updatedAt":1787014414133,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"variants":"[]","version":1},{"createdAt":1786804823063,"deletedAt":null,"id":"default_fortinet_folder_6a8078820109edc319b69b","isNew":false,"isPublic":false,"itemType":"FORTINET_FOLDER","name":"Fortinet 情報","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"fortinet":1786804823063},"preParentID":null,"reviewedAt":1786885810949,"updatedAt":1786886004398,"updatedBy":{"agentId":"ceo","agentName":"CEO","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":2},{"category":"已知 Bug","createdAt":1789249004452,"id":"5ed8875dbd1598d2fd717c66","itemType":"FORTINET_INFO","name":"FortiOS v8.0.0 單介面無法建多組 DHCP server（技術文件 #229894）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789249004452},"product":"FortiOS v8.0.0","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-unable-to-create-additional-dhcp-servers-associated-to-one-interface-229894","summary":"發布於 09/11/2026。FortiOS v8.0.0 即使關閉 IPAM，同一介面也無法建第二組以上 DHCP server；由 7.6.x 帶多組 DHCP 升級上 v8.0.0 者多餘的會被移除且無法重建。解法：升級至已修復的 v8.0.1（含）以後。","updatedAt":1789249004452,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789249001703,"id":"68f55d201252011508039124","itemType":"FORTINET_INFO","name":"LLDP 鄰居上限說明（技術文件 #229886）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789249001703},"product":"FortiOS v7.2+（FortiGate）","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-lldp-neighbor-limits-for-fortios-229886","summary":"發布於 09/11/2026。v7.2 起 LLDP 鄰居上限改為每介面 4 筆；第 5 個鄰居進來會覆寫最舊一筆並觸發 LLDP Fast Start（約每 1-2 秒送一次而非 30 秒一次）。同介面多鄰居一般非預期，多因中間設備轉發 LLDP 封包所致。","updatedAt":1789249001703,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789248997213,"id":"3a026096cdb5d2c7c1586d53","itemType":"FORTINET_INFO","name":"FGFM 通道斷線超時產生告警事件設定（技術文件 #229887）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789248997213},"product":"FortiAnalyzer","sourceUrl":"https://community.fortinet.com/fortianalyzer-6/technical-tip-how-to-generate-an-event-when-an-fgfm-tunnel-remains-down-beyond-a-specified-duration-229887","summary":"發布於 09/11/2026。FGFM 通道斷線超過指定時長時產生事件並通知：先設 mail server 與 notification profile，再建 Correlation 類 event handler（門檻 30m），加 FGFMTunnelDown / FGFMTunnelUp 兩條 correlation rule，以同台 FortiGate 為關聯條件綁定通知設定檔後啟用。","updatedAt":1789248997213,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789162677463,"id":"5c5726e588b1c6cba462e4f5","itemType":"FORTINET_INFO","name":"升級 FortiOS v7.6.7 後 hostapd 崩潰致 Wi-Fi RADIUS 驗證失敗（技術文件 #229839）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789162677463},"product":"FortiGate（FortiOS v7.6.7）","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-process-hostapd-crash-after-upgrade-to-fortios-v7-6-7-causing-wi-fi-radius-authentication-to-fail-229839","summary":"發布於 09/09/2026。升級至 FortiOS v7.6.7 後 hostapd 發生 segmentation fault 崩潰，Wi-Fi RADIUS 驗證失敗（官方 Staff Jaye17 發布）。觸發條件：WPA-Enterprise + RADIUS 直接驗證、RADIUS 以 FQDN 設定、SSID 為 bridge mode。Workaround：RADIUS 伺服器改用 IP 取代 FQDN。","updatedAt":1789162677463,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789162674871,"id":"144475b6e45df112397c4163","itemType":"FORTINET_INFO","name":"FortiGate 700G 設 25000full 無法選 CR media-type（技術文件 #229840）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789162674871},"product":"FortiGate 700G（FortiOS v7.4 / v7.6）","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-unable-to-set-the-media-type-to-cr-on-fortigate-700g-when-speed-on-the-interface-is-set-to-25000full-229840","summary":"發布於 09/09/2026。25G SFP 介面設 speed 25000full 時 media-type 僅有 SR/LR 可選，DAC 線材（FN-CABLE-SFP28-5）需 CR 而無法選。Workaround：改用 25000auto 即可選 CR。官方開發中，預計修於 FortiOS v7.6.8 / v8.0.1。","updatedAt":1789162674871,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789162670349,"id":"a60d99eb99d7c0a442f21432","itemType":"FORTINET_INFO","name":"FortiGate 連不上 FortiGuard 服務 CRL scope errors（技術文件 #229879）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789162670349},"product":"FortiGate（FortiGuard anycast）","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-fortigate-unable-to-access-several-fortiguard-services-due-to-crl-scope-errors-september-2026-229879","summary":"發布於 09/10/2026。2026 年 9 月起 FortiGate 連線數個 FortiGuard 服務失敗，憑證驗證報 Cert error 44 different CRL scope（官方 Staff pjang 發布，Reddit 亦有多起回報）。Workaround：由 anycast 切回 unicast 版 FortiGuard 設定即恢復。","updatedAt":1789162670349,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789076272426,"id":"ea4bbaa89a43240975a6ab89","itemType":"FORTINET_INFO","name":"Ubuntu 建 OpenLDAP 供 FortiAuthenticator 實驗室測試（技術文件 #229873）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789076272426},"product":"FortiAuthenticator","sourceUrl":"https://community.fortinet.com/fortiauthenticator-8/technical-tip-configuring-an-openldap-server-on-ubuntu-for-fortiauthenticator-lab-testing-229873","summary":"說明在 Ubuntu 上建基本 OpenLDAP（dc=labtest,dc=com、ou=people/groups、三測試使用者、測試群組、唯讀查詢帳號），並在 FortiAuthenticator 設定 LDAP 遠端認證伺服器，以 Browse 或 Import Users 驗證查詢與匯入。僅供實驗室測試，不模擬 AD。發布日期：2026-09-10。","updatedAt":1789076272426,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789076269684,"id":"00f647efd178dcc8992fc32c","itemType":"FORTINET_INFO","name":"LDAP 使用者被誤顯示為單一遠端使用者（技術文件 #229870）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789076269684},"product":"FortiAuthenticator","sourceUrl":"https://community.fortinet.com/fortiauthenticator-8/troubleshooting-tip-multiple-ldap-users-appear-as-a-single-remote-user-in-fortiauthenticator-229870","summary":"FortiAuthenticator 把多個 LDAP 使用者顯示為單一遠端使用者。原因：User object class 與 Username attribute 誤映射到群組屬性（如 groupOfUniqueNames / uniqueMember），把整個群組當成單一使用者。解法：改用正確的使用者物件類別與使用者名稱屬性。發布日期：2026-09-10。","updatedAt":1789076269684,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789076265960,"id":"052ef4f104926102a601e324","itemType":"FORTINET_INFO","name":"路由容錯切換後 VPN passthrough session 仍走舊路徑（技術文件 #229875）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789076265960},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-vpn-passthrough-sessions-remain-active-after-routing-failover-229875","summary":"路由容錯切換後既有 VPN passthrough session 仍維持舊 session 狀態走舊路徑，直到逾時、手動清除或 VPN rekey。原因：firewall-session-dirty 設為 check-new，既有 session 不被重查。解法：改回預設 check-all，受影響既有 session 會被標記並依新路由重驗、移除不符者；注意高吞吐量平台可能短暫增加 CPU。發布日期：2026-09-10。","updatedAt":1789076265960,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1789076257237,"id":"90d9fae51adc61cc46cb4537","itemType":"FORTINET_INFO","name":"IPsec remote VPN 用 TACACS+ 群組認證失敗（技術文件 #229869）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1789076257237},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-ipsec-remote-vpn-authentication-does-not-work-with-tacacs-229869","summary":"FortiGate 上 IPsec Remote VPN（IKEv1/IKEv2）使用 TACACS+ 群組認證失敗，本地使用者群組則正常。原因：TACACS+ 並非 IPsec VPN 官方支援的使用者認證方式。解法：改用 RADIUS 或 LDAP；IKEv2 亦可使用 SAML。發布日期：2026-09-10。","updatedAt":1789076257237,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990136271,"id":"180e01e1052b5c3e5cc5af78","itemType":"FORTINET_INFO","name":"FG-IR-26-174 FortiOS_FortiProxy Agentless ZTNA 憑證驗證不當致中間人攻擊","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990136271},"product":"FortiOS 7.6.1–7.6.6 / FortiProxy 7.6.2–7.6.6","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-174","summary":"FG-IR-26-174 / CVE-2026-84393（CWE-295 Improper Certificate Validation），發布於 09/08/2026。Agentless ZTNA 入口憑證驗證不當，未經驗證遠端攻擊者可執行中間人攻擊，攔截或竄改 ZTNA 入口與後端網站間流量。高嚴重性（CVSSv3 7.3）。修復：升 7.6.7+；7.2/7.4/8.0 不受影響。尚無在野利用證據。","updatedAt":1788990136271,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990133175,"id":"f5a11dfe50dcd8996a4dc193","itemType":"FORTINET_INFO","name":"FG-IR-26-173 FortiOS_FortiProxy NULL 指標解引用阻斷服務","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990133175},"product":"FortiOS 7.2.0–7.4.12 / FortiProxy 7.2.0–7.6.6 / FortiPAM 1.0.0–1.9.0","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-173","summary":"FG-IR-26-173 / CVE-2026-84392（CWE-476 NULL Pointer Dereference），發布於 09/09/2026。遠端具權限使用者可致部分阻斷服務（Partial DoS）。影響 FortiOS 7.2.0–7.4.12、FortiProxy 7.2.0–7.6.6、FortiPAM 1.0.0–1.9.0。請依官方 PSIRT 公告升級至修復版本。","updatedAt":1788990133175,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990129579,"id":"f01e7d7441366508dcfe815c","itemType":"FORTINET_INFO","name":"FG-IR-26-171 FortiManager 不當存取控制弱點","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990129579},"product":"FortiManager 7.6.0–7.6.4 / 7.4.0–7.4.10（含 Cloud）","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-171","summary":"FG-IR-26-171 / CVE-2026-22575（CWE-284 Improper Access Control），發布於 09/09/2026。FortiManager 7.6.0–7.6.4、7.4.0–7.4.10（及 Cloud 對應版本）經 HTTPS 請求的不當存取控制弱點。請依官方 PSIRT 公告升級至修復版本。","updatedAt":1788990129579,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990126756,"id":"af8efe5bf82bf22797b832eb","itemType":"FORTINET_INFO","name":"FG-IR-26-170 FortiMonitor OnSight 靜態金鑰 JWT 認證繞過","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990126756},"product":"FortiMonitor OnSight 7.2.0–7.2.7","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-170","summary":"FG-IR-26-170 / CVE-2026-84390（Web GUI 認證用 JWT 以靜態金鑰簽署），發布於 09/08/2026。攻擊者可經偽造或重用 JWT 繞過身分驗證。重大嚴重性（CVSS 9.6）。請依官方 PSIRT 公告升級至修復版本。","updatedAt":1788990126756,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990120627,"id":"6358a81cecbb19f28fe675f2","itemType":"FORTINET_INFO","name":"FG-IR-26-169 FortiSIEM 開放重定向弱點","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990120627},"product":"FortiSIEM 7.5.0–7.5.1 / 7.4.1–7.4.2","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-169","summary":"FG-IR-26-169 / CVE-2026-84389（CWE-601 Open Redirect，URL 重定向至不可信網站），發布於 09/09/2026。FortiSIEM 7.5.0–7.5.1、7.4.1–7.4.2 可能允許攻擊者將使用者重定向至任意網站。低嚴重性（CVSSv4 1.8）。請依官方 PSIRT 公告升級至修復版本。","updatedAt":1788990120627,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990104617,"id":"5d826f538e32b12549b7fa46","itemType":"FORTINET_INFO","name":"FG-IR-26-167 FortiSandbox 命令注入弱點","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990104617},"product":"FortiSandbox 5.2.0（含 5.0.x / 4.4.x 系列，詳見官方公告）","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-167","summary":"FG-IR-26-167 / CVE-2026-84387（命令注入，特殊元素中和不當），發布於 09/09/2026。FortiSandbox（含 5.2.0）存在命令注入弱點，可能允許攻擊者執行未經授權命令。請依官方 PSIRT 公告確認完整影響版本並升級至修復版本。","updatedAt":1788990104617,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788990065508,"id":"ab7c940179c1e5c977fc7f94","itemType":"FORTINET_INFO","name":"FG-IR-26-168 FortiPAM Chrome 擴充功能認證缺陷致瀏覽器劫持","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788990065508},"product":"Fortinet Privileged Access Agent Chrome 擴充功能（搭配 FortiPAM）","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-168","summary":"FG-IR-26-168 / CVE-2026-84388（CWE-287 不當認證），發布於 09/09/2026。Privileged Access Agent Chrome 擴充功能存在信任機制缺陷與未經驗證工作階段啟動，惡意網站可操控瀏覽器 Proxy、任意開啟分頁並錄製分頁內容。重大嚴重性（CVSS 9.1）。2026-07-17 接獲通報，2026-08-01 釋出修復：FortiPAM 升 1.9.1/1.8.4，擴充功能升 8.0.1.123+。尚無在野利用證據。","updatedAt":1788990065508,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788989983416,"id":"f2d8d9d7ecd3fb11ffb02af3","itemType":"FORTINET_INFO","name":"FG-IR-26-166 FortiSandbox Web UI 不當存取控制致敏感資訊外洩","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788989983416},"product":"FortiSandbox 5.0.0–5.0.5 / 4.4.0–4.4.8（含 Cloud / PaaS 5.0.4–5.0.5）","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-166","summary":"FG-IR-26-166 / CVE-2026-26084（CWE-284 Improper Access Control），發布於 09/08/2026。FortiSandbox Web UI 未正確驗證工作階段，未經驗證攻擊者可以此構造 HTTP 請求存取設定、日誌等敏感資訊。高嚴重性（CVSSv3.1 8.9），無需權限與使用者互動。Fortinet 內部發現，尚無在野利用證據。修復：地端升 5.0.6+/4.4.9+；Cloud/PaaS 升 5.0.6+。","updatedAt":1788989983416,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788989978208,"id":"9443de98142c295b24bdf4b1","itemType":"FORTINET_INFO","name":"FG-IR-26-165 FortiClient Windows 未驗證所有權致任意程序終止","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788989978208},"product":"FortiClient for Windows 7.2.0–7.4.7","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-165","summary":"FG-IR-26-165 / CVE-2026-84386（CWE-283 Unverified Ownership），發布於 09/09/2026。FortiClient for Windows 7.2.0 至 7.4.7 暴露的 minifilter 通訊埠允許具本機權限使用者終止任意處理程序，致資料損壞或刪除。低嚴重性（CVSSv4 6.8）。請依官方 PSIRT 公告升級至修復版本。","updatedAt":1788989978208,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788903415255,"id":"a6ab57da6e1723d1f7018b12","itemType":"FORTINET_INFO","name":"HA FortiGate 管理 FortiSwitch 預期行為（技術文件 #229820）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788903415255},"product":"FortiGate / FortiSwitch（FortiLink）","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-what-to-expect-for-fortiswitches-managed-by-ha-fortigates-229820","summary":"發布於 09/08/2026。FortiSwitch 僅與 HA Primary 建 FortiLink 控制通道，Secondary 上顯示 disconnected 屬預期；failover 時管理連線短暫中斷後陸續恢復（DTLS/CAPWAP 約 60–90 秒、HTTPS FortiLink 約 25–30 秒，須 FortiOS / FortiSwitchOS 7.4.2+）；離線期間資料轉發不受影響。","updatedAt":1788903415255,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788903412422,"id":"552013cc7ed6acfe1714cab4","itemType":"FORTINET_INFO","name":"HA 切換後 FortiCloud SSO 因序號不符被拒（技術文件 #229818）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788903412422},"product":"FortiGate v7.2 / v7.4 / v7.6 / v8.0","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-forticloud-sso-request-rejected-after-ha-failover-due-to-a-serial-number-mismatch-229818","summary":"發布於 09/08/2026。HA 叢集啟用 FortiCloud SSO 後，failover 時 secondary 的 BIOS 憑證產生 SSO 請求而 SSO daemon 仍跑在 primary，primary 偵測序號不符而拒絕（追蹤 Issue 1286934）。無 workaround，修於 FortiOS v7.4.13 / v7.6.7 / v8.0.1。","updatedAt":1788903412422,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788903409717,"id":"ceea044e524f4931270aa801","itemType":"FORTINET_INFO","name":"FortiOS 7.4.12 GUI 升級後 HA 狀態誤顯示（技術文件 #229817）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788903409717},"product":"FortiGate v7.4.12","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-the-fortios-v7-4-12-gui-may-display-an-incorrect-ha-status-until-the-browser-refresh-229817","summary":"發布於 09/08/2026。升級至 FortiOS 7.4.12 後，登入 Primary 的 GUI 可能誤顯示為 Secondary（CLI get system status / ha status 仍為 Primary，純 GUI 顯示問題）。解法：重新整理瀏覽器即恢復；官方調查中，預計修於 v7.6.8 / v8.0.1。","updatedAt":1788903409717,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788903406314,"id":"982da28893a336d331e90d01","itemType":"FORTINET_INFO","name":"FortiClient 簽章更新因 Trusted Host 設定失敗（技術文件 #229816）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788903406314},"product":"FortiManager 7.6 / FortiClient","sourceUrl":"https://community.fortinet.com/fortimanager-27/troubleshooting-tip-forticlient-signature-updates-failing-due-to-trusted-host-configuration-229816","summary":"發布於 09/07/2026。FortiManager 上所有管理員帳號皆設 trusted hosts 且未含 FortiClient 子網路時，FortiClient 簽章更新請求無回應。Workaround：在管理員 Trusted Hosts 加入 FortiClient 子網路；永久修正：升級至 FortiManager v7.6.8 / v8.0.1（含該 bug 修正）。","updatedAt":1788903406314,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"漏洞公告","createdAt":1788903400274,"id":"22ff55887ba9e36f02748fdd","itemType":"FORTINET_INFO","name":"FG-IR-26-164 FortiSOAR PaaS 不當存取控制致權限提升","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788903400274},"product":"FortiSOAR PaaS 7.6.0–7.6.6","sourceUrl":"https://fortiguard.fortinet.com/psirt/FG-IR-26-164","summary":"FG-IR-26-164 / CVE-2026-84385（CWE-284 Improper Access Control），發布於 09/08/2026。FortiSOAR PaaS 7.6.0 至 7.6.6 可能允許攻擊者提升權限。請依官方 PSIRT 公告升級至修復版本。","updatedAt":1788903400274,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816988521,"id":"eb10607fcd0a315c8da79bfa","itemType":"FORTINET_INFO","name":"FortiGate API 使用者遇 401 insufficient_scope（技術文件 #229810）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816988521},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-existing-api-user-on-fortigate-encountering-the-401-error-bearer-error-insufficient-scope-229810","summary":"FortiGate API 使用者若設了 cors-allow-origin 但請求未帶相符 Origin 標頭，會回 401 Bearer error=\"insufficient_scope\"。解法：請求加上相符 Origin 標頭，或移除該 API 使用者的 cors-allow-origin 設定。發布日期：09/07/2026。","updatedAt":1788816988521,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816986292,"id":"ffa78f3315932dcc0e015e30","itemType":"FORTINET_INFO","name":"FortiGate Cloud WiFi 報表不顯示 Bridge Mode SSID 用戶端（技術文件 #229801）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816986292},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-fortigate-cloud-wifi-report-does-not-display-the-client-data-for-fortiap-bridge-mode-ssids-229801","summary":"FortiGate Cloud WiFi 報表僅顯示 Tunnel Mode SSID 用戶端；Bridge Mode 流量由 FortiAP 本地橋接、不經 CAPWAP 送 FortiGate，紀錄缺 srcssid 欄位故無法關聯，此為預期行為無需修正。發布日期：09/07/2026。","updatedAt":1788816986292,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816984252,"id":"ffe89f15ea005514f7ab55aa","itemType":"FORTINET_INFO","name":"FortiAnalyzer syslog 檔直接匯入 FortiSIEM 做解析驗證（技術文件 #229803）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816984252},"product":"FortiSIEM","sourceUrl":"https://community.fortinet.com/fortisiem-34/technical-tip-how-to-directly-ingest-a-syslog-file-from-fortianalyzer-into-fortisiem-229803","summary":"需把 FortiAnalyzer 下載的 syslog 直接餵給 FortiSIEM 做收錄與 parser 驗證時，下載選 Text（勿用 CSV），依 reporting_ip 在 Collector 建 /opt/phoenix/cache/syslog/\u003creporting_ip\u003e 目錄並放入檔案，確認 phoenix_config.txt 的 event_sftp_directory 後重啟 phParser，再於 GUI Analytics 驗證解析。發布日期：09/07/2026。","updatedAt":1788816984252,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816981627,"id":"fd49b141e98a943233689984","itemType":"FORTINET_INFO","name":"HTTP-only 政策下 Raw TCP 與 FTP 繞過應用程式控制（技術文件 #229802）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816981627},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-raw-tcp-and-ftp-traffic-bypassing-application-control-on-an-http-only-policy-229802","summary":"FortiGate 政策用 ALL/ALL_TCP 搭配僅允許 HTTP/TLS 的應用程式控制時，無 L7 特徵的 Raw TCP/FTP 會被標為 generic-TCP 而非未知應用，導致未被封鎖。解法：Service 明確限縮為 HTTP/HTTPS（80、443），Unknown Application Action 設 Block，必要時按服務拆分政策。發布日期：09/07/2026。","updatedAt":1788816981627,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816978918,"id":"8bed0f417accaeaadce68e90","itemType":"FORTINET_INFO","name":"FortiSwitch 110G 升級 v7.6.8 後用戶端拿不到 IP（技術文件 #229813）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816978918},"product":"FortiSwitch","sourceUrl":"https://community.fortinet.com/fortiswitch-36/troubleshooting-tip-clients-are-not-getting-the-ip-after-a-fortiswitch-upgrade-to-v7-6-8-229813","summary":"FortiSwitch 110G 升級 v7.6.8 後，VLAN 啟用 DHCP snooping 時用戶端拿不到 IP（僅見 DHCPDISCOVER、後續交握中斷）。此為已知問題，已於 7.6.9 與 8.0.1 修復。發布日期：09/07/2026。","updatedAt":1788816978918,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816976664,"id":"1f329e3662e80c1fc5053cab","itemType":"FORTINET_INFO","name":"FortiManager v7.6 無法安裝 FortiAnalyzer set serial 設定（技術文件 #229814）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816976664},"product":"FortiManager","sourceUrl":"https://community.fortinet.com/fortimanager-27/troubleshooting-tip-cannot-install-fortianalyzer-set-serial-settings-229814","summary":"FortiManager v7.6 安裝 FortiOS v7.6 的 FortiAnalyzer 設定時，若同時設 set serial 與 set certificate-verification disable 會安裝失敗（v7.6 起停用憑證驗證後不需也不允許設 serial）。解法：啟用 certificate-verification 或刪除 serial 設定。發布日期：09/07/2026。","updatedAt":1788816976664,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816974587,"id":"5593f58ff39d7e3239ae63b5","itemType":"FORTINET_INFO","name":"FortiManager 推送政策包報 fortiextender 未指派給設備（技術文件 #229807）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816974587},"product":"FortiManager","sourceUrl":"https://community.fortinet.com/fortimanager-27/troubleshooting-tip-fortimanager-failed-to-push-policy-package-with-error-fortiextender-xxx-yyy-is-not-assigned-to-device-229807","summary":"FortiManager 推送政策包時報「fortiextender 'XXX-YYY' is not assigned to device」，肇因於無效的範本指派。解法：在 FortiManager 執行 diagnose cdb check policy-packages \u003cpolicy_package_name\u003e 即可排除。發布日期：09/07/2026。","updatedAt":1788816974587,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788816971932,"id":"1ebc3f718f7c1abbda1de732","itemType":"FORTINET_INFO","name":"FortiManager 從 ACI 匯入 EPG 報 Data is not committed（技術文件 #229811）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788816971932},"product":"FortiManager","sourceUrl":"https://community.fortinet.com/fortimanager-27/troubleshooting-tip-fortimanager-fails-to-import-all-epgs-from-aci-with-data-is-not-committed-due-to-other-data-s-error-229811","summary":"FortiManager 從 ACI 匯入 EPG 時，若任一 EPG 失敗會以「Data is not committed due to other data's error」覆蓋所有結果，難以定位真因。解法：執行 diagnose debug application connector 255 並搜尋 error 關鍵字找出真正違規物件（例：firewall address 名稱超過 79 字元），修正後重匯即可。發布日期：09/07/2026。","updatedAt":1788816971932,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730742380,"id":"aeda6a427ac54b7970453c93","itemType":"FORTINET_INFO","name":"FortiGate 以外部 IP 服務經 API 做 External Feeds（技術文件 #229782）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730742380},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-how-to-use-an-external-ip-address-service-with-an-external-api-external-feeds-api-229782","summary":"FortiGate 接第三方外部 IP 資料庫作 External Feeds connector，搭配外部應用經 API 供數。步驟：Security Fabric \u003e External Connectors \u003e Create New，類別選 External Feeds (IP address)，Status 啟用、Name 自訂、Update method 選 External feed，URL of external resource 填第三方服務給的 FQDN 加 API key，存檔後 feed 即開始運作。建立時間 09/04/2026。","updatedAt":1788730742380,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730739057,"id":"7ee07b1d3f318986a721c60b","itemType":"FORTINET_INFO","name":"FortiMail Cloud 部署報 Error 142 需由後台開通（技術文件 #229754）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730739057},"product":"FortiMail","sourceUrl":"https://community.fortinet.com/fortimail-26/technical-tip-resolving-error-142-during-fortimail-cloud-deployment-229754","summary":"FortiMail Cloud 新建 tenant 部署中出現 Error 142 狀態。自助開通僅限 Fortinet 內部工程師：一般用戶須向 cloud admin 團隊送 provisioning request；若曾有舊 tenant 應先確認已刪除再重送新申請。開通後以配發帳密登入並走 setup wizard，細節見官方 Provisioning a FortiMail Cloud tenant 與 Accessing a FortiMail Cloud tenant 文件。建立時間 09/03/2026。","updatedAt":1788730739057,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730735424,"id":"2044657cbb918dc0963750d1","itemType":"FORTINET_INFO","name":"FortiGate 單機併入 HA 後 rule.otdt 不同步（技術文件 #229749）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730735424},"product":"FortiOS","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-ha-out-of-sync-due-to-otdt-database-mismatch-after-migrating-from-standalone-to-ha-229749","summary":"FortiOS v7.4.1 起，單機 FortiGate 併入 HA 後 rule.otdt 表 checksum 不一致（主機有 OTDT、副機為全 0）。原因：原單機曾有 FortiGuard OT Security Service 授權並下載 OT Detection Definitions，新成員沒有對應 OT 資料庫。仍需要 OT 服務：兩台皆備齊授權，在主機 System \u003e FortiGuard 點 Update Licenses \u0026 Definitions Now，再走 HA 手動同步流程；不再需要：先備份，原機以 TFTP 重刷（VM 則重部署）清掉殘留 OTDT 使兩端一致，再以 diagnose sys ha checksum show global | grep -i otdt 驗證。建立時間 09/02/2026。","updatedAt":1788730735424,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730730848,"id":"52cf26d7d6abed41dc39df16","itemType":"FORTINET_INFO","name":"FortiMail Cloud 擋 Google 日曆通知報 550 domain not protected（技術文件 #229731）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730730848},"product":"FortiMail","sourceUrl":"https://community.fortinet.com/fortimail-26/troubleshooting-tip-fortimail-cloud-rejects-google-calendar-notifications-with-a-550-domain-not-protected-error-229731","summary":"Google Calendar 通知（calendar-notification@google.com）經 FortiMail Cloud 被拒並退 550 5.7.1 Domain is not a protected domain：Google Workspace 系統通知走不同投遞路徑，寄件網域不在該 tenant 受保護網域內（Drive 分享通知 drive-shares-dm-noreply@google.com 類似）。解法：在 Google Admin Console 的 Gmail Routing 另建規則，把 envelope sender 匹配 ^calendar-notification@google\\.com$ 的內部收發信改道至 FortiMail Cloud MX 主機（如 example-com-1/2.fortimailcloud.com），再發測試邀請驗證。建立時間 09/02/2026。","updatedAt":1788730730848,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730719918,"id":"a25cf58f053879df2609899e","itemType":"FORTINET_INFO","name":"FortiAnalyzer 報表中介面頻寬與使用率數值解讀（技術文件 #229725）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730719918},"product":"FortiAnalyzer","sourceUrl":"https://community.fortinet.com/fortianalyzer-6/technical-tip-understanding-interface-bandwidth-and-utilization-values-in-fortianalyzer-reports-229725","summary":"FortiAnalyzer 報表中介面頻寬/使用率因 dataset、資料來源、篩選、取樣週期與時間範圍不同而有落差：介面統計與 traffic-log 算出的頻寬是不同資料源，不應期待一致，且皆為 dataset 聚合平均非即時讀數。排查：Reports \u003e Chart Library 查圖表 Dataset，再到 Datasets 看 SQL Query 為準；以 get system log interface-stats 查取樣設定；比對需同設備同介面同時段，並確認查詢與聚合方式。無資料時用 All Reports 下 Report Guidance 查 Analytics 資料是否齊全。建立時間 09/01/2026。","updatedAt":1788730719918,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730714726,"id":"196ed235cce1fd38bd5c4550","itemType":"FORTINET_INFO","name":"FortiDeceptor 部署 Custom Decoy 報 Failed to connect to SQL Server（技術文件 #229717）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730714726},"product":"FortiDeceptor","sourceUrl":"https://community.fortinet.com/fortideceptor-18/technical-tip-troubleshooting-error-failed-to-init-decoy-failed-to-connect-to-sql-server-when-deploy-custom-decoy-229717","summary":"FortiDeceptor v6.1/v6.2 部署 Custom VM（Microsoft SQL Server）時報 Failed to init decoy: failed to connect to SQL Server。原因：SQL Server Management Studio 會自動安裝 ODBC Driver 18，該版本不受 FortiDeceptor v6.1/v6.2 支援。解法：執行 odbcad32.exe 確認 Drivers 頁籤，經由控制台解除安裝 ODBC Driver 18 後依官方文件重走部署流程即可成功初始化。建立時間 09/01/2026。","updatedAt":1788730714726,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788730709935,"id":"466b2fc0cf4b429af1ad2a69","itemType":"FORTINET_INFO","name":"FortiWeb WebSocket/XHR 串流觸發 Exceeding Internal Parsing Limits（技術文件 #229693）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788730709935},"product":"FortiWeb","sourceUrl":"https://community.fortinet.com/fortiweb-40/technical-tip-handling-exceeding-internal-parsing-limits-for-http-based-websocket-xhr-streaming-traffic-229693","summary":"FortiWeb 針對 HTTP-based WebSocket（XHR streaming）請求，在 HTTP Protocol Constraints 例外中豁免 Missing Content-Type 與 Malformed Request 後，attack log 出現 Exceeding Internal Parsing Limits（Internal Resource Limits: Bad Firstline）。解法：在既有匹配該 WebSocket URL path 的 HTTP Constraints Exception 規則中啟用 internal-resource-limits-check（預設關閉），僅對該端點停用此單一 parser 限制，其餘 WAF 模組照常檢查，不影響效能。建立時間 08/31/2026。","updatedAt":1788730709935,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644173284,"id":"1bd8c77edf2014e7e460de9b","itemType":"FORTINET_INFO","name":"FortiManager JSON API 加 address group 成員後補 Object Revision（技術文件 #229724）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644173284},"product":"FortiManager","sourceUrl":"https://community.fortinet.com/fortimanager-27/technical-tip-generate-object-revision-history-after-adding-address-group-members-using-json-api-229724","summary":"發布：2026-09-01。以 JSON API field-level add 加 firewall addrgrp 成員不會自動產生 Object Revision History。解法：add 成功後再對父物件做一次 update（不帶 member，只改 comment 加 audit 註記並帶 revision note），即可產生修訂紀錄且不重寫成員清單；comment 已有內容時用附加。先在非正式群組測試並備份 FMG（VM 另做快照）。","updatedAt":1788644173284,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644170240,"id":"2fec341332d566b06913f263","itemType":"FORTINET_INFO","name":"FortiMail 個人隔離區保留天數延長超過 14 天（技術文件 #229776）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644170240},"product":"FortiMail","sourceUrl":"https://community.fortinet.com/fortimail-26/technical-tip-extending-the-fortimail-personal-quarantine-message-retention-period-beyond-14-days-229776","summary":"發布：2026-09-04。FortiMail 個人隔離區預設 14 天後自動刪除，需延長時在 Profile→Resource 建/改 resource profile 設定保留天數，再到 Policy→Recipient Policy 以 Sender（信箱/群組/網域）套用該 resource profile。保留期由 resource profile 控制，非個人隔離區設定直接改。","updatedAt":1788644170240,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644167717,"id":"21cd2e3a8f51c724b8196a03","itemType":"FORTINET_INFO","name":"FortiGate 加 LDAP server 到 authentication scheme 報 Entry not found（技術文件 #229730）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644167717},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-entry-not-found-error-when-trying-to-add-remote-ldap-server-to-authentication-scheme-on-fortigate-229730","summary":"發布：2026-09-02。將遠端 LDAP server 加入 authentication scheme 時報 Entry not found，主因 LDAP 的 group-member-check 設為 group-object 又同時設 member-attr，兩種群組成員比對方式衝突。解法：unset group-member-check 與 member-attr 回預設後即可選用並建 authentication rule。","updatedAt":1788644167717,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644165420,"id":"4c2b42e3815cb23826f79e2a","itemType":"FORTINET_INFO","name":"FortiGate 不顯示 DNS 狀態與解析失敗（技術文件 #229733）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644165420},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-fortigate-dns-does-not-show-status-ms-state-and-not-dns-resolution-229733","summary":"發布：2026-09-02。FortiGate DNS 狀態/ms 空白且解析失敗，主因 kernel 層 DNS daemon 未初始化（根本沒起來，kill/重啟無效）。解法：重開機讓 DNS 程序初始化，之後狀態與解析恢復。","updatedAt":1788644165420,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1788644160811,"id":"b8ae5f90ba4797e29d077e8a","itemType":"FORTINET_INFO","name":"FortiGate Proxy Address Group 超過 10 個成員僅存前 10 筆（技術文件 #229760）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644160811},"product":"FortiOS 7.6.7","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-proxy-address-group-saves-only-up-to-10-members-229760","summary":"發布：2026-09-03。GUI 新建/編輯超過 10 個成員的 proxy address group 只顯示存下前 10 筆，CLI 查成員其實完整（純 GUI 顯示/編輯問題）。原因：FortiOS 7.6.7 Bug；修復預計 7.6.9 / 8.0.2。Workaround：改用 CLI 修改 proxy address group。","updatedAt":1788644160811,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644157976,"id":"6c71fe54c8fc973fd75a7b33","itemType":"FORTINET_INFO","name":"FortiClient 就地升級後 VPN 組態備份/還原無回應（技術文件 #229743）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644157976},"product":"FortiClient","sourceUrl":"https://community.fortinet.com/forticlient-4/troubleshooting-tip-forticlient-vpn-configuration-backup-or-restore-does-not-respond-after-an-in-place-upgrade-229743","summary":"發布：2026-09-02。就地升級後按 Backup/Restore 點 OK 對話框關閉卻無備份檔、VPN 連線自 tray 消失、GUI 與 tray 顯示版本不一致，主因舊版 binary 殘留致 IPC 異常。解法：完整解除安裝→重開機→重裝；急用時以 FCConfig.exe 備份/還原（-m all -f 備份檔 -o export/import -p 8字元以上密碼，資料夾需先建好）。","updatedAt":1788644157976,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644150551,"id":"8341f2edb656682fe61cf281","itemType":"FORTINET_INFO","name":"FortiAP 經 FortiEdge Cloud 管理時無線用戶連不上 802.11ax（技術文件 #229778）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644150551},"product":"FortiAP","sourceUrl":"https://community.fortinet.com/fortiap-5/technical-tip-why-wireless-clients-does-not-connect-with-802-11ax-when-fortiap-are-managed-on-fortiedge-cloud-229778","summary":"發布：2026-09-04。FortiAP 由 FortiEdge Cloud 代管時無線用戶無法以 802.11ax 連線。解法：到 Wireless→SSID→Edit 確認 High Efficiency 已啟用；該選項需 Advanced FortiAP management license，無授權時即使雲端開啟 AP 端也不會生效。","updatedAt":1788644150551,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644146556,"id":"eab5d93034dc10826af147d6","itemType":"FORTINET_INFO","name":"FortiSOAR csadm source-control 匯出報 KeyError: 'exclude'（技術文件 #229692）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644146556},"product":"FortiSOAR","sourceUrl":"https://community.fortinet.com/fortisoar-35/troubleshooting-tip-csadm-source-control-export-config-fails-with-keyerror-exclude-229692","summary":"發布：2026-08-31。用 csadm source-control export-config 搭配自訂 config 匯出 playbook collection 時報 KeyError: 'exclude'，因 config 缺頂層 exclude 鍵。解法：在 config 補 exclude 區段（如 modules/dashboards/reports/roles/global_variables/picklists），確認 include 的 collection 名完全相符後重跑；成功會產出 playbooks 與 tags 子目錄。注意匯出 JSON 可能內含憑證/token，入版控前先檢查。","updatedAt":1788644146556,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788644133480,"id":"b30ebd04b0fee02de6628e5e","itemType":"FORTINET_INFO","name":"FortiCNAPP VS Code 擴充功能安裝與掃描除錯（技術文件 #229737）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788644133480},"product":"FortiCNAPP","sourceUrl":"https://community.fortinet.com/forticnapp-63/technical-tip-how-to-troubleshoot-forticnapp-vs-code-extension-229737","summary":"發布：2026-09-02。說明 FortiCNAPP VS Code extension 安裝與除錯：支援 SCA/SAST/IaC 本地掃描；遇「需先在 Lacework CLI 安裝 IaC 元件」可照常掃描但缺新功能。掃描出錯時取 Extension Host 日誌（View→Output→Save/Export Logs），並可用 lacework sca scan \u003cdir\u003e -f lw-json 獨立驗證。","updatedAt":1788644133480,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557781001,"id":"bd61860abf29cdbb4a3310b8","itemType":"FORTINET_INFO","name":"SAML SSO後sts.windows.net找不到頁面（技術文件 #229779）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557781001},"product":"FortiGate、IPsec SAML SSO","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-how-to-solve-this-sts-windows-net-page-can-t-be-found-over-saml-sso-229779","summary":"datePublished 2026-09-04。SAML VPN過2FA後報sts.windows.net找不到：IdP SSO URL配錯。解法：config user saml核對URL並回填正確值。","updatedAt":1788557781001,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557778897,"id":"bbb5ce74d1e07d757d1aba26","itemType":"FORTINET_INFO","name":"FortiOS 7.4.10至7.4.12 DDNS不更新（技術文件 #229755）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557778897},"product":"FortiOS 7.4.10/7.4.11/7.4.12","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-ddns-fortiguard-not-working-on-fortios-v7-4-10-v7-4-11-v7-4-12-229755","summary":"datePublished 2026-09-03。升7.4.12後DDNS不更新，報DigiCert根憑證error 19/2。解法：匯入DigiCert High Assurance EV Root CA或改ddns-server-ip 173.243.138.226；根本修復升7.6.x或待7.4.13+。","updatedAt":1788557778897,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557776718,"id":"09a1bb1d413d778930f5d86e","itemType":"FORTINET_INFO","name":"FortiGate 70G升7.4.11第三方AP CAPWAP中斷（技術文件 #229690）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557776718},"product":"FortiGate 70G、FortiOS 7.4.11","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-3rd-party-ap-over-vpn-stopped-working-229690","summary":"datePublished 2026-08-31。70G升7.4.11後第三方AP CAPWAP停，virtual-switch成員口分片被NP7丟棄。Workaround：接AP埠移出virtual-switch；根本修復升7.4.12。","updatedAt":1788557776718,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557773669,"id":"c160e7888ff061d289674795","itemType":"FORTINET_INFO","name":"FortiOS 8.0 proxy策略NNTP POST超限被reset（技術文件 #229715）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557773669},"product":"FortiGate、FortiOS 8.0","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-resolving-nntp-post-connection-reset-due-to-oversize-limit-in-proxy-based-229715","summary":"datePublished 2026-09-01。proxy策略下NNTP POST傳一半被reset，AV日誌Size limit is exceeded。解法：Protocol Options調大oversize limit。","updatedAt":1788557773669,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557771729,"id":"b2db796db6b544d60af45cf1","itemType":"FORTINET_INFO","name":"FortiDeceptor上傳CA憑證報Validation Failed（技術文件 #229718）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557771729},"product":"FortiDeceptor 6.3以下","sourceUrl":"https://community.fortinet.com/fortideceptor-18/troubleshooting-tip-error-validation-failed-invalid-certificate-when-uploading-a-ca-certificate-229718","summary":"datePublished 2026-09-01。v6.3以下匯入CA報Validation Failed. Invalid Certificate.。解法：開TAC索取v6.0 interim build 0479或等v6.3.1 GA。","updatedAt":1788557771729,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557768960,"id":"d7dfa5a35cd6438a1734c42f","itemType":"FORTINET_INFO","name":"第三方CA憑證缺clientAuth致FGFM失敗（技術文件 #229790）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557768960},"product":"FortiGate、FortiManager","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-fgfm-debug-contains-unsuitable-certificate-purpose-when-using-a-3rd-party-ca-generated-certificate-on-fortigate-229790","summary":"datePublished 2026-09-04。FGFM mTLS建連失敗報unsuitable certificate purpose：憑證缺TLS Web Client Authentication EKU。解法：重申請時明確要求clientAuth，並以GUI或openssl確認EKU。","updatedAt":1788557768960,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557767016,"id":"f98a048f3a7e6d24b107e54d","itemType":"FORTINET_INFO","name":"FortiManager推配置報error -999無fortilink介面（技術文件 #229748）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557767016},"product":"FortiManager","sourceUrl":"https://community.fortinet.com/fortimanager-27/troubleshooting-tip-error-999-entry-not-exist-detail-no-fortilink-interface-exists-for-fsp-managed-switch-entry-not-exist-detail-no-fortilink-interface-exists-for-fsp-managed-switch-229748","summary":"datePublished 2026-09-02。推配置報error -999無fortilink介面，係export-to跨VDOM功能集中管理不支援。解法：ADOM Central Management取消FortiSwitch，export-to改本機改完再同步。","updatedAt":1788557767016,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557761771,"id":"246730e6854c0683910cdeeb","itemType":"FORTINET_INFO","name":"FortiGate HA重複VMAC致第二ISP上網異常（技術文件 #229757）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557761771},"product":"FortiGate HA","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-resolving-internet-connectivity-issues-caused-by-duplicate-ha-vmacs-229757","summary":"datePublished 2026-09-03。HA新增第二ISP後上網斷續：多組HA同Group ID致VMAC重複。修復：維護窗內改唯一Group ID，再以get system ha status確認。","updatedAt":1788557761771,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788557757901,"id":"3abdd77fefcc85947fb65a9e","itemType":"FORTINET_INFO","name":"FortiGate NP7Lite G系列介面持續physical down排查（技術文件 #229766）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788557757901},"product":"FortiGate NP7Lite G系列","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-troubleshooting-fortigate-interfaces-remaining-physically-down-np7lite-g-serries-229766","summary":"datePublished 2026-09-03。NP7Lite G系列多介面physical down無法建連，伴隨NP7LITE_ERR。排查：diagnose hardware deviceinfo nic、crashlog、serdes-status及fnsysctl讀取platform/x1-log/x2-log，備齊開機console送TAC。","updatedAt":1788557757901,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788125991103,"id":"e607e11f3c9b317b065bc90a","itemType":"FORTINET_INFO","name":"File-Filter UTM Profile 與 Web Filter URL Exempt 跨檢測模式行為差異（技術文件 #229671）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788125991303},"product":"FortiGate / UTM File-Filter","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-file-filter-utm-profile-behavior-with-a-web-filter-exemptions-across-different-inspection-modes-229671","summary":"說明：獨立 File-Filter UTM Profile 搭配 Web Filter URL「exempt」動作時，行為依檢測模式而異。flow-based 檢測模式下，File-Filter 無法被 URL exempt 繞過；proxy-based 檢測模式下則可被繞過。\n適用：FortiOS 全版本，屬預期行為。\n來源：官網 KB 229671（2026-08-28 發布，datePublished 核實）。","updatedAt":1788125991103,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788125991103,"id":"422d5495d1f3527f124941f3","itemType":"FORTINET_INFO","name":"FortiAuthenticator VM 6.6.7 升級報 Image validation failed（技術文件 #229670）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788125991403},"product":"FortiAuthenticator VM","sourceUrl":"https://community.fortinet.com/fortiauthenticator-8/troubleshooting-tip-error-image-validation-failed-the-current-image-model-number-is-different-from-the-appliance-s-when-trying-to-upgrade-vm-from-firmware-version-6-6-7-229670","summary":"問題：在 FortiAuthenticator VM 6.6.7 上傳序號 FACVMS 開頭之 subscription 授權後，升級時報錯「Image validation failed: The current image model number is different from the appliance's (current appliance model is FACVMS)」導致無法升級。\n原因：6.6.7 誤允許 8.0+ 專用的 subscription 授權，導致機型判定錯亂（Bug 1229991，6.6.8 起已阻擋）。\n解法：1) 套用非 subscription VM 授權覆蓋後再升級至 8.0.x，再重套 subscription 授權；2) 新建未授權 VM 直升 8.0.x 再套授權（會遺失設定，備份還原無效因授權含於設定）。常見於 Azure 市集 6.6.7 範本。\n來源：官網 KB 229670（2026-08-28 發布，datePublished 核實）。","updatedAt":1788125991103,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788125991103,"id":"1f845e3743c66ae5fdc9b585","itemType":"FORTINET_INFO","name":"FortiMail Session Limit 導致外部 SMTP 連線被拒（技術文件 #229682）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788125991503},"product":"FortiMail","sourceUrl":"https://community.fortinet.com/fortimail-26/troubleshooting-tip-fortimail-rejects-incoming-connections-due-to-session-limit-restrictions-229682","summary":"問題：寄件主機連線超過 Session Profile 中「Maximum concurrent connections for each client」上限時，FortiMail 拒絕 SMTP 連線，歷史紀錄顯示 Classifier=Session Limit、Disposition=Delay，寄件端重試導致郵件延遲。\n解法：調整對應 IP Policy 所套用 Session Profile 的並發連線數上限，並以 History Log 驗證。\n來源：官網 KB 229682（2026-08-28 發布，datePublished 核實）。","updatedAt":1788125991103,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788125991103,"id":"68c121cd3a7249256120436d","itemType":"FORTINET_INFO","name":"FortiClient 下載選項未顯示於 ZTNA Web Portal（技術文件 #229679）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788125991103},"product":"FortiOS 7.6.7 / ZTNA","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-forticlient-download-option-is-missing-from-the-ztna-web-portal-229679","summary":"問題：FortiOS v7.6.7 中，即使 Portal 設定已啟用 FortiClient 下載，agentless ZTNA Web Portal 仍未顯示 FortiClient 下載選項。\n影響：FortiOS 7.6.7。\n解法：此為已知問題，已於 FortiOS v8.0.1 修復，升級至 8.0.1 即可解決。\n來源：官網 KB 229679（2026-08-28 發布，datePublished 核實）。","updatedAt":1788125991103,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788125991103,"id":"db16f3efcb2c5118ad61084a","itemType":"FORTINET_INFO","name":"FortiManager ADOM 升級報 XSS prop[_apn] 錯誤（技術文件 #229674）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788125991603},"product":"FortiManager / FortiExtender","sourceUrl":"https://community.fortinet.com/fortimanager-27/troubleshooting-tip-how-to-troubleshoot-the-string-contains-xss-vulnerability-characters-prop-apn-error-during-adom-upgrade-229674","summary":"問題：FortiManager ADOM 升級時因 FortiExtender 動態資料中 _apn / _cid 含 XSS 字元而報錯「The string contains XSS vulnerability characters - prop[_apn]」。\n解法：關閉 FortiExtender dynamic updates → 重置 ADOM 內 FortiExtender 動態資料 → 執行 ADOM 升級 → 再重新啟用 dynamic updates。\n來源：官網 KB 229674（2026-08-28 發布，datePublished 核實）。","updatedAt":1788125991103,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788125991103,"id":"74712fd37d6d077985e59a53","itemType":"FORTINET_INFO","name":"HA 叢集 Virtual Serial Number 導致 FortiToken Cloud 啟用失敗（技術文件 #229680）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788125991203},"product":"FortiGate HA / FortiToken Cloud","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-fortitoken-cloud-activation-failure-on-ha-cluster-with-virtual-serial-number-229680","summary":"問題：HA 叢集啟用 Virtual (Logical) Serial Number 時，FortiToken Cloud / FortiIdentity Cloud 本機使用者授權啟用失敗，CLI 顯示 no license、GUI 顯示 Failed to retrieve FortiToken Cloud status，debug 可見 HTTP 403 serial not registered at FortiCare。\n原因：FortiGate API 請求使用實體序號而非 Virtual Serial Number。\n解法：將 HA 叢集升級至 FortiOS v7.6.5（含）以上。\n來源：官網 KB 229680（2026-08-28 發布，datePublished 核實）。","updatedAt":1788125991103,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788039599841,"id":"027408842c70f64b36dbc175","itemType":"FORTINET_INFO","name":"FortiSIEM 7.5.x 升級後 TCP 514 Syslog 無法收事件（技術文件 #229646）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788039599941},"product":"FortiSIEM","sourceUrl":"https://community.fortinet.com/fortisiem-34/troubleshooting-tip-syslog-events-not-received-over-tcp-port-514-after-upgrade-to-fortisiem-7-5-x-versions-229646","summary":"升級至 FortiSIEM 7.5.x（例 7.5.1）後，Collector 上 TCP 514 的 Syslog 來源無法註冊事件，UDP 514 則正常（Scope: FortiSIEM）。根因：7.5.x 新增 listen_tcp_thread_limit 參數，預設 50 達上限後即不再接收 TCP Syslog。排查：在 Supervisor 執行 grep -i tcp_thread_limit /opt/phoenix/config/phoenix_config.txt 檢查。解法：備份 phoenix_config.txt 後以 sed 將 listen_tcp_thread_limit 由 50 調高至 60（例 60），驗證後 Collector 應恢復接收；UDP 不受此限制影響。","updatedAt":1788039599841,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788039599841,"id":"00a76c093ab4ed45cb138e4d","itemType":"FORTINET_INFO","name":"FortiAnalyzer 授權日誌速率超限郵件告警 Event Handler 設定（技術文件 #229641）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788039600141},"product":"FortiAnalyzer","sourceUrl":"https://community.fortinet.com/fortianalyzer-6/technical-tip-how-to-create-an-event-handler-for-log-rare-exceeding-licensed-log-rate-229641","summary":"FortiAnalyzer 當日誌速率超過授權值時以 Event Handler 寄送郵件告警的設定步驟（Scope: FortiAnalyzer）。步驟：1) System Settings -\u003e Advanced -\u003e Mail Server 設定郵件伺服器；2) Incidents \u0026 Events -\u003e Event Handlers -\u003e Notification Profiles 建立通知設定；3) Incidents \u0026 Events -\u003e Event Handlers 新增 Event Handler 並套用通知設定；4) Rules -\u003e Add New Rule 選 Log Device Type=FortiAnalyzer、Log Type=Event Log，並以欄位 gbdayusage 設過濾條件。授權速率可於 GUI License Information Widget 或 CLI get system loglimits 查詢。","updatedAt":1788039599841,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788039599841,"id":"b75d680bdb59c7a0bc91b728","itemType":"FORTINET_INFO","name":"FGFMd debug 出現 connect error / errno 11 無法回應 FortiManager API 請求（技術文件 #229656）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788039599841},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-connect-error-no-such-file-or-directory-or-errno-11-resource-temporarily-unavailable-seen-in-fgfmd-debug-229656","summary":"FortiGate 以 FGFMd debug 排查 FortiManager 查詢失敗時出現 'connect error: No such file or directory' / 'errno=11, Resource temporarily unavailable' 的說明（Scope: FortiOS）。成因：FortiGate 未正確回應 FortiManager 的 API 請求，透過 diagnose debug application fgfmd -1 可重現；簡易驗證為嘗試從 PC 連線 GUI 是否逾時，若原本可連而現逾時，多與 HTTPSd（同時處理 API 與 HTTP 請求的程序）異常有關。解法：本文不涵蓋 HTTPSd 根本原因，需進一步依官方指引排查 GUI 無法存取/登入頁無回應/頻繁斷線等相關 Troubleshooting Tip。","updatedAt":1788039599841,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1788039599841,"id":"46d6c57d063d09385d05ab67","itemType":"FORTINET_INFO","name":"FortiAuthenticator SCEP 出現 certificate already exists and not eligible for renewal（技術文件 #229668）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1788039600041},"product":"FortiAuthenticator","sourceUrl":"https://community.fortinet.com/fortiauthenticator-8/technical-tip-fortiauthenticator-log-message-show-new-issue-certificate-already-exists-and-not-eligible-for-renewal-229668","summary":"FortiAuthenticator 於 SCEP 請求時日誌出現 'A certificate with subject \"...\" and issuer \"...\" already exists and not eligible for renewal'（logid 50502，例：C=MY, CN=test1 / CN=FortiGate1，時間 2026-08-25）的處理（Scope: FortiAuthenticator）。成因：同 subject/issuer 的憑證已存在重複項目，不符合續期條件。解法：至 Certificate Management -\u003e End Entities 分別檢查 Users（使用者憑證清單）與 Local Services（伺服器憑證清單），以 Revoke 移除重複憑證項目即可排除。","updatedAt":1788039599841,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787953032982,"id":"f47f8909268e485d68537994","itemType":"FORTINET_INFO","name":"FortiGate 40F 經 FortiManager ZTP 由 7.2.6 直升 7.6.6 後無法開機 error 44010（技術文件 #229678）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787953033082},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-fortigate-40f-fails-to-boot-after-ztp-upgrade-from-fortios-v7-2-6-to-v7-6-6-229678","summary":"FortiGate 40F/60F 透過 FortiManager ZTP/autolink 或手動直升由 FortiOS v7.2.x 直接升級至 v7.6.6 build 3652 時，開機卡在配置初始化、報 duplicate built-in configuration object 並顯示 Initialize config error 44010。原因：7.2.x→7.6.x 直升為不支援路徑（無論是否 factory-default），需經中間版本逐步升級；ZTP 啟用 enforce 7.6.6 時預設單步直升會跳過必要中間版。Workaround：依官方支援升級路徑分段升級，避免直接跨大版直升。範圍 FortiGate 40F/60F、FortiOS v7.2.x/v7.6.x、FortiManager ZTP。建立時間 08/28/2026。","updatedAt":1787953032982,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787953032982,"id":"3c95d5ce07b3a41317644c99","itemType":"FORTINET_INFO","name":"FortiManager 新 Web Filter Profile 未自動出現在 FortiClient EMS（技術文件 #229647）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787953033182},"product":"FortiClient EMS","sourceUrl":"https://community.fortinet.com/forticlient-4/troubleshooting-tip-new-web-filter-profile-from-fortimanager-does-not-appear-in-forticlient-ems-229647","summary":"FortiManager 新建的 Web Filter Profile 同步後未自動出現在 FortiClient EMS 的說明。FortiClient EMS 支援由 FortiOS/FortiManager 匯入 Web Filter 設定，初次匯入路徑為 Endpoint Profiles → Import → Import from FortiOS/FortiManager；但初次匯入後、後續在 FortiManager 新增的 Web Filter Profile 不會自動同步顯示，需再次執行 Import 匯入新設定才會出現。範圍 FortiClient EMS、FortiManager。建立時間 08/27/2026。","updatedAt":1787953032982,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787953032982,"id":"1e05a9bca5655b5e81b85c54","itemType":"FORTINET_INFO","name":"FortiGate 以 IPv6 存取 GUI 時 CLI Console 無法開啟 Error -122（技術文件 #229654）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787953032982},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-unable-to-open-the-cli-console-via-gui-over-ipv6-229654","summary":"FortiGate v7.4.x 以 IPv6 開啟 GUI 內 CLI Console 時出現 Error Login Refused (err=-122) 的已知問題。範圍 FortiGate v7.4.x，透過 IPv6 存取 GUI 再開 CLI Console 觸發；部分在升級至 7.4.x 分支後才出現。官方說明 Development 團隊調查中，7.4.x 尚無修正時程；根據現有發現 FortiOS v7.6.x 無此問題。Workaround：改以 IPv4 存取 GUI，或升級至 FortiOS v7.6.x 解決。建立時間 08/27/2026。","updatedAt":1787953032982,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787866680860,"id":"fa0fbb35810efc628d48e10a","itemType":"FORTINET_INFO","name":"FortiWeb 流量日誌顯示已驗證使用者為 Unknown（技術文件 #229650）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787866680860},"product":"FortiWeb","sourceUrl":"https://community.fortinet.com/fortiweb-40/troubleshooting-tip-fortiweb-traffic-logs-show-user-name-as-unknown-for-authenticated-users-229650","summary":"FortiWeb 流量/攻擊日誌中已驗證使用者顯示 user_name=\"Unknown\" 的排查。原因為驗證由後端 Web 應用處理而 FortiWeb 未正確追蹤；解法為設定 User Tracking（waf user-tracking rule/policy 並套至 Web Protection Profile），定義 authentication URL、username/password 參數、session ID 及成功條件。範例：login 對 /login.php 以 username/password + PHPSESSID，成功回 302/失敗 200；若成功條件與應用實際回應不符則不會標記已驗證。注意：追蹤請求中出現 user_name 不代表已判定成功。","updatedAt":1787866680860,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787780228983,"id":"8ed4352556f854078dc6fc69","itemType":"FORTINET_INFO","name":"FortiGate 升級至 v7.6.6/v7.6.7 後無 Security Rating 報告（技術文件 #229613）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787780228983},"product":"FortiGate / FortiOS 7.6.6、7.6.7","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-no-security-rating-reports-after-upgrade-to-v7-6-6-or-v7-6-7-229613","summary":"Fortinet Community 2026-08-26 發布。範圍：FortiGate HA 叢集升級至 FortiOS v7.6.6 或 v7.6.7 後，Security Rating Report 無結果，Log \u0026 Report → System Events 中 Critical/High/Medium/Low/Passed 皆顯示為 0。原因：Node.js 程序異常。處置：於 CLI 執行 diagnose node process restart 重啟 Node.js，重新產生報告後 GUI 即正常顯示。此為 HA 環境下升級後已知處置方式。","updatedAt":1787780228983,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787780228983,"id":"cbbf64b12587bb852a2270d5","itemType":"FORTINET_INFO","name":"FortiGate 升級至 v7.6.7 後 WebSocket 服務連線異常（技術文件 #229543）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787780229083},"product":"FortiGate / FortiOS 7.6.7","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-resolving-service-connectivity-issues-after-upgrading-fortigate-from-fortios-v7-4-11-to-v7-6-7-229543","summary":"Fortinet Community 2026-08-24 發布。範圍：FortiGate 從 FortiOS v7.4.11 升級至 v7.6.7 後，Microsoft Loop、Microsoft Copilot、8x8 Work 等依賴 WebSocket 的服務連線失敗。原因：流量經 proxy-based 檢測、SSL Inspection 與 Application Control/IPS 的防火牆策略處理時，所關聯的 Protocol Options 未啟用 WebSocket 支援。處置：修改既有或新建 Protocol Options（如 websocket-enabled-profile）並啟用 WebSocket，套用至受影響策略；flow-based 檢測策略不受影響。","updatedAt":1787780228983,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787780228983,"id":"1d1ded3a926a9f8c18ab924d","itemType":"FORTINET_INFO","name":"FortiPAM Check-in/Check-out 機制行為與設定（技術文件 #229607）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787780229183},"product":"FortiPAM","sourceUrl":"https://community.fortinet.com/fortipam-52/technical-tip-the-behavior-and-configuration-of-check-in-and-check-out-feature-in-fortipam-229607","summary":"Fortinet Community 2026-08-26 發布。說明 FortiPAM Secret 的 check-out/check-in 行為：使用者 check-out 後若保持 launch session 存活，管理員無法強制 check-out，需待使用者終止 launch 並經過 idle timeout 後才可回收。設定要點：啟用 checkout、設定 checkout duration、force-checkout idle time，並配置使用者權限。適用於需控管特權存取與會話回收的 FortiPAM 部署。","updatedAt":1787780228983,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787693723468,"id":"4596385f2101f59080785a4f","itemType":"FORTINET_INFO","name":"特定 FortiGate 機型與 BT Openreach ADVA 對接連線異常（技術文件 #229592）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787693723468},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-connectivity-issues-with-certain-fortigate-models-with-bt-openreach-adva-devices-229592","summary":"特定 FortiGate 機型與 BT Openreach ADVA 路由器對接時，鏈路顯示 Up 但 ARP/ICMP 不通、MAC 表學不到對端，影響 FortiGate 與 BT Openreach ADVA 對接場景。處置：升級 FortiGate 至 v7.4.10 / v7.6.7 / v8.0.0 已修復此相容性問題。","updatedAt":1787693723468,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787693723468,"id":"ba61450c63ba070d8c9bc5f9","itemType":"FORTINET_INFO","name":"FortiClient VPN Before Logon 隧道未出現在 Windows 登入畫面（技術文件 #229540）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787693723868},"product":"FortiClient","sourceUrl":"https://community.fortinet.com/forticlient-4/troubleshooting-tip-forticlient-vpn-before-logon-tunnels-are-not-appearing-on-the-windows-sign-in-screen-229540","summary":"FortiClient v7.4.4 起不再支援 IKEv1，SAML VPN 改走 IKEv2；若同時將外部瀏覽器（external browser）設為 SAML user agent，則不支援 Before Logon VPN，導致 Windows 登入畫面看不到隧道。處置：停用 external browser 作為 SAML user agent，即可讓 Before Logon 隧道正常出現在登入畫面。","updatedAt":1787693723468,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787693723468,"id":"fd8188a642f51c06b64711eb","itemType":"FORTINET_INFO","name":"FortiGate ADSL 機型 SRA 狀態檢查（技術文件 #229576）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787693723768},"product":"FortiGate DSL","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-how-to-check-the-sra-seamless-rate-adaptation-status-on-fortigate-adsl-models-229576","summary":"FortiGate DSL 機型（60E DSL、50G DSL 等）SRA（Seamless Rate Adaptation，無縫速率自適應）預設啟用，可在不中斷連線下動態調整 VDSL2 速率。檢查方式：Telnet 至 240.0.0.1 執行 dsl_cpe_pipe g997racg 檢視 upstream/downstream，RA_MODE=3 代表 SRA 已啟用。","updatedAt":1787693723468,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787693723468,"id":"137d8535ee7e77f4c98323fd","itemType":"FORTINET_INFO","name":"SAML IPsec VPN 在 Wi-Fi Tunnel SSID 下無法連線（技術文件 #229574）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787693723668},"product":"FortiGate / FortiClient","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-saml-ipsec-vpn-not-connecting-when-on-wi-fi-network-tunnel-ssid-229574","summary":"SAML 驗證的 IPsec VPN 在連接 Wi-Fi Tunnel SSID 時無法建立，有線網路同設定可通，debug 停在 No SAML method found。影響 FortiOS v7.4.11 / v7.6.6。處置：升級 FortiOS 至 v7.4.12 / v7.6.7 / v8.0.0 已修復。","updatedAt":1787693723468,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787693723468,"id":"fc1d474e8a797882704f05e7","itemType":"FORTINET_INFO","name":"FortiClient 修改 Remote Gateway 後仍連舊閘道（技術文件 #229591）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787693723568},"product":"FortiClient","sourceUrl":"https://community.fortinet.com/forticlient-4/troubleshooting-tip-forticlient-may-continue-using-the-previous-remote-gateway-after-it-has-been-changed-229591","summary":"FortiClient 在既有 IPsec VPN Profile 中修改 Remote Gateway 後，GUI 顯示新閘道但實際 IKE 流量仍發往舊 IP；原因為 registry 鍵 RemoteGWSorted 仍殘留舊值。Workaround：刪除該 VPN Profile 後重新建立並填入正確 Remote Gateway。","updatedAt":1787693723468,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787607454904,"id":"8cb55ea97f92ffb3a045cd68","itemType":"FORTINET_INFO","name":"FortiNAC-F FortiSwitch standalone 整合主機/埠不可見（技術文件 #229552）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607455004},"product":"FortiNAC-F / FortiSwitch","sourceUrl":"https://community.fortinet.com/fortiswitch-30/troubleshooting-tip-how-to-fix-host-and-port-visibility-issues-with-fortiswitch-standalone-integration-229552","summary":"Scope: FortiNAC-F + FortiSwitch（SNMP+CLI 獨立整合，非 API）。症狀：SNMP/CLI 驗證成功但仍顯示 Failed to connect to the API Server，且無法顯示埠狀態/發現主機。說明：獨立整合不走 API，提示具誤導性，AuthVersion 屬性非必要。排查：於 FortiSwitch 執行 diagnose debug reset、diagnose debug application httpsd -1、diagnose debug enable 後，於 FortiNAC 重新 Validate Credentials 觀察 debug（正常應見 logincheck /logincheck 與 login success）。檢查：execute enter-shell device -ip \u003cIP\u003e 查看 AuthVersion，必要時於 FortiNAC CLI 執行 execute enter-shell device -ip \u003cIP\u003e -delAttr -name AuthVersion 移除。另避免 CLI 密碼含 £/€/$/æ/Ø/Å/Ä/Ö/Ü 等特殊/Unicode 字元。","updatedAt":1787607454904,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787607454904,"id":"5b2f0c4db160a542a59b2908","itemType":"FORTINET_INFO","name":"FortiAuthenticator Search Local Users First 行為說明（技術文件 #229551）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607454904},"product":"FortiAuthenticator","sourceUrl":"https://community.fortinet.com/fortiauthenticator-50/technical-tip-understanding-search-local-users-first-behavior-in-fortiauthenticator-229551","summary":"Scope: FortiAuthenticator（RADIUS Service \u003e Policies \u003e Identity sources）。說明：啟用 Search Local Users First 後，FortiAuthenticator 收到 RADIUS 認證先檢查使用者名稱是否為本地使用者；若存在則以本地流程處理（日誌顯示 Local user authentication，如 admintest 因未設 token 顯示 NAS forces two-factor auth but user token not defined），若不存在才續用遠端 LDAP realm（日誌顯示 Remote LDAP user authentication，如 admintest2 顯示 invalid user）。結論：此選項決定來源檢查順序，非僅限本地帳號的阻擋機制；適用於特定帳號需本地優先（如 admin）、或同名本地/遠端帳號共存時讓本地優先。","updatedAt":1787607454904,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787607446065,"id":"e4d1a34a29403c6309438bf3","itemType":"FORTINET_INFO","name":"FortiGate VIP/DNAT 策略匹配 incoming interface 行為（技術文件 #229567）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607446065},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-vip-dnat-and-firewall-policy-matching-incoming-interface-behavior-229567","summary":"Scope: FortiGate（含 NPU VDOM 轉送）。情境：有兩組 VIP 皆 DNAT 至 192.168.60.50:8080，VIP1=172.16.2.1（已設於 port19/DMZ）、VIP2=172.16.2.2（同網段但未設於介面）。結果：指向 172.16.2.1 命中 Policy 16（DMZ→Inside），指向 172.16.2.2 卻命中 Policy 21（Outside→Inside）。原因：依 fw_forward_dnat_indev 邏輯，封包經 NPU 虛擬鏈路進 root VDOM 並在 pre-routing DNAT 後，核心會檢查 VIP 目的 IP 是否設於本 VDOM 某介面；若有則將策略匹配的 incoming interface 改為該介面所屬 zone（故 VIP1 視為 DMZ），否則保留原始 ingress（VIP2 視為 Outside）。提醒：規劃 VIP 時注意外部 IP 是否與介面 IP 相同，以免策略命中非預期。","updatedAt":1787607446065,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787607446065,"id":"872ea3bb3ff3211eab46bae7","itemType":"FORTINET_INFO","name":"FortiGate 無法直接將 VIP 轉 Virtual Server（技術文件 #229556）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607446165},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-converting-an-existing-virtual-ip-object-to-virtual-server-is-unsupported-and-what-to-do-instead-229556","summary":"Scope: FortiGate（config firewall vip）。問題：VIP（static-nat，一對一/按埠 NAT）與 Virtual Server（server-load-balance，一對多負載平衡）雖同表但不支援直接互轉；CLI 變更 type 會報 can not change type object set operator error, -651。例如將 type server-load-balance（extip 203.51.100.1/extport 443）改為 static-nat/mappedip 10.0.0.1 即失敗，反之亦然。建議（v7.2.0+）：離峰時段新建對應 VIP/VS（extip/extintf 相同），將防火牆策略等引用由舊物件置換為新物件，再刪除舊物件。","updatedAt":1787607446065,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787607446065,"id":"64387551f39dd63e97e6891c","itemType":"FORTINET_INFO","name":"FortiAuthenticator 推送通知誤觸錯誤使用者（技術文件 #229568）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607446265},"product":"FortiAuthenticator","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-incorrect-user-triggered-for-push-notification-229568","summary":"Scope: FortiAuthenticator + FortiAuthenticator Agent。症狀：推送通知間歇性觸發給錯誤使用者，例如 Emer 的請求卻對 Emerson 推送；接受後 App 回應逾時，手動輸入 token 仍可登入。FortiAuthenticator 日誌顯示 (53417) facauth: Updated auth log 'lab.local/Emerson' for attempt from REST API: Remote LDAP user authentication ... 而實際應為 Emer。已知 Bug id 1312120，於 FortiAuthenticator 8.0.4 修復；8.0.3 有特殊組建可向 TAC 索取。影響：名稱前綴相似的使用者（如 Emer/Emerson）易重疊匹配。","updatedAt":1787607446065,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787607437888,"id":"8d7cbf46f40c1815965e79b2","itemType":"FORTINET_INFO","name":"FortiGate 升級/重啟後 BFD 持續翻動 Can't find intf（技術文件 #229550）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607437888},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-bfd-flaps-with-can-t-find-intf-after-upgrade-or-reboot-229550","summary":"Scope: FortiGate（BFD+BGP）。症狀：升級/重啟後 BFD 在 UP/DOWN 間持續翻動，連帶 BGP 鄰居翻動；執行 get router info bfd neighbor 顯示短暫 UP 後 DOWN，debug 出現 bfd_read_ipv4: Can't find intf，封包擷取顯示對端回應正常但本端逾時。根因：升級/重啟期間競爭條件，BFD 會話未以 local 標記建立，導致無法處理回應。判別：diagnose sys session filter dport 3784/dst \u003clocal\u003e/src \u003cpeer\u003e/proto 17 後 diagnose sys session list，異常會話 state=log may_dirty（缺 local），正常應為 state=log local may_dirty。處置：以相同 filter 執行 diagnose sys session clear 清除異常會話，FortiGate 重建含 local 的 BFD 會話，再以 get router info bfd neighbor / get router info bgp summary 確認穩定。注意：需先確認 peer 回應有到達且會話確缺 local 再清除。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787607437888,"id":"e47d5eaa360d7efa5e91ec22","itemType":"FORTINET_INFO","name":"FortiProxy 升級 AV 引擎後 console 出現 wcs_addref/wcs_update 錯誤（技術文件 #229563）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607438488},"product":"FortiProxy","sourceUrl":"https://community.fortinet.com/fortiproxy-47/troubleshooting-tip-console-output-errors-are-seen-on-fortiproxy-229563","summary":"Scope: FortiProxy（AV 引擎升級後）。症狀：console 隨機出現 b3-0 wcs_addref:3749 ERROR: Prevented addition of duplicate key、c3-1 wcs_update:3077 ERROR: Attempting to update a reference、sys_set_proc_intval:1864 can not open file /proc/sys/net/core/wmem_max；crashlog 出現 ext3 filesystem being mounted at /tmp/tmp_mnt 訊息。排查：執行 diagnose autoupdate versions 確認 AV 版本是否一致；若一致則非 AV 引起。結論：工程團隊確認多為 spam 訊息、可安全忽略，不影響運行，crashlog 該段亦非致命；相關崩潰已排定於 FortiProxy v7.6.7 修復。若持續，建議送 TAC 檢查是否有額外崩潰。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787607437888,"id":"d1bb9c4cb88881e59c366604","itemType":"FORTINET_INFO","name":"FortiGate 阻擋偽裝為 HTTPS 的非 TLS 流量（技術文件 #229558）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607438388},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-block-non-https-traffic-masquerading-as-https-with-unsupported-ssl-negotiation-checks-229558","summary":"Scope: FortiGate（SSL/SSH Inspection, deep-inspection）。問題：攻擊者以 TCP 443 承載 FTP/SSH/Telnet 等非 HTTPS 以繞過放行 443 的策略。解法：於 SSL/SSH inspection profile 設定 unsupported-ssl-negotiation 以檢測無效握手，並啟用 ssl-negotiation-log 與 expolicy-implicit-log：config firewall ssl-ssh-profile edit \"custom-deep-inspection\" config https set ports 443 set status deep-inspection set unsupported-ssl-negotiation block end set ssl-negotiation-log enable next end；config log setting set expolicy-implicit-log enable。當設為 allow 時 WAD 會以 unexpected bypass 放行（wad_ssl_proxy_srv_unexpect_bypass / reason=unexpect_protocol），設為 block 則阻斷並可於日誌稽核。tunnel-non-http 則用於阻擋偽裝為 HTTP 的非 HTTP 協定。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787607437888,"id":"1a26294428edd2018794f474","itemType":"FORTINET_INFO","name":"FortiGate WAD debug 日誌解析方法（技術文件 #229562）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607438288},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-how-to-parse-and-analyze-fortigate-wad-debug-logs-229562","summary":"Scope: FortiGate（WAD/Explicit Proxy）。內容：說明如何解析 diagnose wad debug 擷取，透過 [s:xxxxx] WAD session ID 隔離單一連線、依時間排序判讀處理階段。欄位：[I]/[V]/[E] 為等級、[p:1187] 為 WAD worker、[s:760084919] 為 session ID、[r:1397380] 為 request ID、wad_dump_http_request:2897 為函式行號。做法：先以 client IP/hostname/URL 定位受影響訊息取得 s，再以該 s 過濾全擷取；典型階段含 Matched webproxy object、Received request from client、CONNECT 等。參考：需配合 diagnose wad debug 分類/等級與過濾設定（見 Technical Tip: Using the diagnose wad debug command）。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787607437888,"id":"caf3daedd736779521bccebe","itemType":"FORTINET_INFO","name":"FortiGate HA 切換原因排查與切換後檢查指南（技術文件 #229561）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607438188},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-guide-identifying-fortigate-ha-failover-reasons-in-fgcp-and-running-post-failover-checks-229561","summary":"Scope: FortiGate FGCP HA。內容：系統性整理 HA failover 觸發原因與排查步驟。首動指令：於主/備機執行 diagnose sys ha history read，並檢視 Log \u0026 Report \u003e System Events \u003e HA events（或 diagnose log display）。涵蓋：電源中斷/手動重啟、心跳介面 keepalive 遺失、受監控介面失效、遠端鏈路偵測、SSD 故障、記憶體門檻切換、override 設定、手動 CLI 觸發（execute ha failover 等）、HA 設定變更、韌體升級不完整、硬體故障等，並給出對應處置（如增設冗餘心跳、調整監控介面/門檻）。切換後檢查：確認 HA 同步狀態、主機角色是否符合預期、心跳擁塞與記憶體/遠端鏈路調校。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787607437888,"id":"326356cd48bb6713ea431406","itemType":"FORTINET_INFO","name":"FortiAnalyzer v7.6.7 後 FortiGate 日誌檢視空白（技術文件 #229560）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607438088},"product":"FortiAnalyzer / FortiGate","sourceUrl":"https://community.fortinet.com/fortianalyzer-28/troubleshooting-tip-logs-are-not-displayed-in-fortigate-log-view-when-fortianalyzer-is-set-as-the-source-after-upgrading-fortianalyzer-v7-6-7-229560","summary":"Scope: FortiAnalyzer v7.6.7、FortiGate（Log View 來源設為 FortiAnalyzer）。症狀：升級 FortiAnalyzer 至 v7.6.7 後，FortiGate 上以 FortiAnalyzer 為來源的日誌檢視無資料。原因：v7.6.7 起 FortiAnalyzer 僅接受加密的 reliable 日誌，拒收未加密日誌（by design）。處置：於 FortiGate 啟用 reliable：config log fortianalyzer setting set status enable set server \u003cFortiAnalyzer_IP\u003e set reliable enable end。確認後日誌即恢復顯示。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787607437888,"id":"ba4234e70225301e4af703ab","itemType":"FORTINET_INFO","name":"FortiWeb API Machine Learning Redis max clients 致學習停擺（技術文件 #229555）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787607437988},"product":"FortiWeb","sourceUrl":"https://community.fortinet.com/fortiweb-40/troubleshooting-tip-workaround-for-api-machine-learning-failure-caused-by-redis-max-clients-error-229555","summary":"Scope: FortiWeb v8.0.0-8.0.6（API Machine Learning）。症狀：運行一段時間後所有已學習 API 轉為 zombie，重訓亦無新路徑；日誌重複出現 [MLD: mld_error] Error: connect DM redis error、[redis: alert] proxyd auth(127.0.0.1:6388) failed reason = ERR max number of clients reached。根因：內部 Data-Mining Redis 達到最大連線數。Workaround：關閉受影響 API 學習策略的 URL-cluster 功能：config waf api-learning-policy edit \u003cid\u003e set policy-id \u003cid\u003e config api-ip-list end set url-cluster disable next end。效果：ML 立即恢復學習，既有 MLAPI 保護不受影響，無需執行 Redis flush/rebuild/formatlogdisk。","updatedAt":1787607437888,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787520889009,"id":"f6aabe8f8bf5df750d2c3bf0","itemType":"FORTINET_INFO","name":"FortiOS 整合 IDIRA Identity 以 SAML 認證 SSL VPN 使用者（技術文件 #229519）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787520889209},"product":"FortiOS / SSL VPN","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-integrate-fortios-with-idira-identity-to-authenticate-ssl-vpn-users-using-saml-229519","summary":"說明以 IDIRA Identity（原 CyberArk Identity）作為 IdP、用 SAML 認證 SSL VPN 使用者的完整整合：IdP 端建立應用、設定信任/屬性/帳號對應並匯出簽署憑證；FortiGate 作為 SP 設定 SAML 使用者、群組對應與憑證匯入。網路建議將 SSL VPN 終止於 loopback 介面（私網 IP）並以 VIP 對應獨立公網 IP、搭配 FQDN 與公開信任憑證，另需放行 loopback 的防火牆政策、群組導向存取控制與 DNS A 紀錄；可對應多個 IDIRA 群組做細緻政策分流。","updatedAt":1787520889009,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787520889009,"id":"8d18fe31459e05ed7e7cb3eb","itemType":"FORTINET_INFO","name":"FortiAnalyzer v7.6.3 自訂 SQL 資料集報 relation does not exist（技術文件 #229527）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787520889009},"product":"FortiAnalyzer v7.6.3","sourceUrl":"https://community.fortinet.com/fortianalyzer-6/technical-tip-error-relation-does-not-exist-when-running-a-custom-sql-dataset-on-fortianalyzer-v7-6-3-229527","summary":"自訂 SQL 資料集執行時報 ERROR: relation \"adom***_fgt_wlog\" does not exist，因產生的查詢參照了資料庫中不存在的日誌表。可用 diagnose sql debug sqlqry dbgon 驗證查詢語句。屬 FortiAnalyzer 缺陷，已於 v7.6.7 修復，升級後同一資料集即可正常執行。","updatedAt":1787520889009,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787520889009,"id":"25ded0c500106c5af655a691","itemType":"FORTINET_INFO","name":"FortiGate 集中管理 FortiAP/FortiSwitch 設定 SNMP engine-id 造成 SNMPv3 認證錯誤（技術文件 #229513）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787520889109},"product":"FortiGate / FortiAP / FortiSwitch","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-configuring-snmp-engine-id-for-devices-managed-by-fortios-causes-snmpv3-notintimewindow-authentication-errors-229513","summary":"在 FortiGate 上為被管理的 FortiAP/FortiSwitch 手動設定相同全域 SNMP engine-id，會導致 SNMPv3 收集器收到衝突的 engine time/boots 而報 notInTimeWindow 認證錯誤。解法：在 FortiGate 上取消設定（config switch-controller snmp-sysinfo / config wireless-controller snmp 內 unset engine-id），若 FortiSwitch 本機仍殘留錯誤 engine-id 需一併清除；engine-id 在 SNMPv3 環境必須保持唯一。","updatedAt":1787520889009,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787434588219,"id":"c0626ac6958d1f53863a5c9f","itemType":"FORTINET_INFO","name":"FortiSIEM phMCPServer Service unavailable（技術文件 #229465）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787434588619},"product":"FortiSIEM","sourceUrl":"https://community.fortinet.com/fortisiem-34/troubleshooting-tip-phmcpserver-service-unavailable-229465","summary":"Fortinet Community 2026-08-18 發布。FortiSIEM 7.5.x 新增的 phMCPServer（MCP Server）僅支援 ClickHouse 資料庫，在 phstatus 中顯示 unavailable/缺失。處置：確認 ClickHouse 可用，檢查 /opt/phoenix/config/phoenix_config.txt 中 ClickHouse 設定為 enable=true，完成後執行 phxctl start 啟動服務。非 ClickHouse 部署不提供此服務。","updatedAt":1787434588219,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787434588219,"id":"28b3d821cd3b2e9f8fbc0a07","itemType":"FORTINET_INFO","name":"IPsec 隧道搭配 SD-WAN 導流時流量無法通過（技術文件 #229502）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787434588519},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-traffic-cannot-pass-through-ipsec-tunnel-with-sd-wan-traffic-steering-229502","summary":"Fortinet Community 2026-08-20 發布。IPsec 隧道已建立但分支至總部流量不通，常見於結合 SD-WAN traffic steering 與 Performance SLA「Update Static Route」啟用時。診斷：get router info routing-table details \u003cdst_IP\u003e 顯示路由為 inactive、SLA 狀態為 Down。處置：確認 SLA 指向的探測目標正確且為 UP，若目標已下線則刪除或修正 SLA；啟用 Update Static Route 時 SLA Down 會將靜態路由標為 inactive。修正後路由轉為 active 即可恢復。","updatedAt":1787434588219,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787434588219,"id":"373bb9690c31ec8fbdb6b4d3","itemType":"FORTINET_INFO","name":"FortiPAM v1.9.1 Web Launcher 自訂連接埠失效（Bug #229497）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787434588419},"product":"FortiPAM","sourceUrl":"https://community.fortinet.com/fortipam-52/troubleshooting-tip-fortipam-web-launcher-with-custom-port-stops-working-after-upgrade-229497","summary":"Fortinet Community 2026-08-20 發布。升級至 FortiPAM v1.9.1 後，帶自訂連接埠的 Web Launcher 啟動失敗：URL 中的 :port 被錯誤移到網址末尾。例如 https://host:8443/public/... 變成 https://host/public/...:8443。影響 FortiPAM v1.9.1。處置：聯絡 Fortinet TAC 取得 hotfix；官方將於 FortiPAM v1.9.2 內建修復。","updatedAt":1787434588219,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787434588219,"id":"79857968f51c11d231ea2de4","itemType":"FORTINET_INFO","name":"FortiGate 以 FortiManager 作為 FDS 時更新失敗（技術文件 #229518）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787434588319},"product":"FortiGate / FortiManager","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-fortigate-update-failed-when-the-device-is-configured-to-use-fortimanager-as-the-fds-server-229518","summary":"Fortinet Community 2026-08-21 發布。當 FortiGate 設定使用 FortiManager 作為 FDS（FortiGuard Distribution Server）時，System Event Log 出現「FortiGate update failed」，實為無法從 FortiManager 安裝 GeoIP（IPGE000/IPGO）更新。Workaround：1) 在 FortiGate 設 set include-default-servers enable 啟用回退 FortiGuard（air-gapped 不適用）；2) 在 FortiManager 執行 diagnose fmupdate del-object fds + diagnose fmupdate updatenow 重新整理（下次更新可能復發）。永久修復：FortiOS 7.4.12 / 7.6.7 / 8.0.0。","updatedAt":1787434588219,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"Bug","createdAt":1787434588219,"id":"46ccf88bf4d3c8200c9b843c","itemType":"FORTINET_INFO","name":"FortiOS 升級後 config-error-log 顯示 ISDB 物件 obsolete（技術文件 #229514）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787434588219},"product":"FortiOS / FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/technical-tip-after-fortios-upgrade-config-error-log-shows-certain-isdb-objects-are-now-obsolete-229514","summary":"Fortinet Community 2026-08-21 發布。FortiOS 升級至 7.4.x（亦可能影響 7.6）後，config-error-log 將部分已配置的 ISDB 物件誤標為 obsolete。原因為 FFDB（FortiGuard Flow Database）載入順序缺陷，初始化時載入較小的內建預設資料庫所致。Workaround/處置：重啟 FortiGate 一次、執行 execute internet-service refresh、等待下一次排程 FFDB 更新，或升級至已修復此缺陷的版本。","updatedAt":1787434588219,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"category":"技術文件","createdAt":1787348091400,"id":"7ea8c44310745a01d082af69","itemType":"FORTINET_INFO","name":"CLI 輸出區分 Policy Route 與 SD-WAN Rule（技術文件 #229499）","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"default_fortinet_folder_6a8078820109edc319b69b":1787348091800},"product":"FortiGate","sourceUrl":"https://community.fortinet.com/fortigate-3/troubleshooting-tip-identifying-policy-route-and-sd-wan-rule-entries-in-cli-output-229499","summary":"說明如何從 CLI 指令 get firewall proute 的輸出區分 Policy Route（策略路由）與 SD-WAN Rule（SD-WAN 規則），並指出 Policy Route 優先於 SD-WAN Rule。","updatedAt":1787348091400,"updatedBy":{"agentId":"6cd576b598cc9027c1e314c3","agentName":"情報蒐集員","userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":1},{"createdAt":1786807403851,"id":"fortinet_section_config_6a8078820109edc319b69b","itemType":"FORTINET_SECTION_CONFIG","lineChannelAccessToken":"A8PpgcaUuX1fnKUthX+rsewwtuh8GWppWRtGtOaD/R/MDx4YFFncYifCWf/qbU+aOg3coC7BRNW6yvHQfyhOe8W47/wN3wAMSfwhIrVsTyw8IKI/yX4f9nwz84PJtEh/kgsFI3yzVSLdUSumyZd3RAdB04t89/1O/w1cDnyilFU=","lineChannelId":"2011123140","lineChannelSecret":"c02a12177ae23efa576875b1d4560f54","lineNotifyEnabled":true,"lineTargetId":"U24934052107f384d83ed2f12e2b2e1c9,Ucaee8f51070d72ca4da541d75d4bbba1,U078b00507b427e0ff48040cc8fe67f34,Uaecd362198838dbdd646895bc662715e","name":"FORTINET_SECTION_CONFIG","originPluginDir":"ff7d7f30e15480f5abf8021e","originPluginID":"ff7d7f30e15480f5abf8021e","parents":{"fortinet":1786807403851},"updatedAt":1787016141914,"updatedBy":{"userId":"6a8078820109edc319b69b","userName":"Daniel Kay"},"version":11}]}