• Quick tips: FortiClient FQDN-based split tunneling with IPsec, FortiGate Web Application Firewall URL access

    Dear reader, I have another installment of the quick tips series. This time the topics are FQDN-based split tunneling for IPsec with FortiClient and how to use the URL access feature of a FortiGate Web Application Firewall (WAF) profile. Models and versions: FortiClient FQDN-based split tunneling with IPsec One of the nice things about SSL-VPN…


  • A real look at FortiGate FGCP HA BGP failover behaviour

    A FortiGate Cluster Protocol (FGCP) HA deployment is nothing new in today’s world, and with more and more of these clusters functioning as BGP routers, especially with the proliferation of SD-WAN and ADVPN, having a high BGP service uptime is becoming critical. In order to achieve this, there are a few things to keep in…


  • Exploring the FortiClient EMS API

    I am not a fan of the official FortiClient EMS API documentation that is available on the Fortinet Developer Network (FNDN). It is a bare-bones documentation that is sparse on explaining how to interact with the API, has very few examples, no responses, lacks a lot of API endpoints, and the endpoints that exist are…


  • FortiWeb installation on Proxmox and migration from VMware

    Proxmox is gaining a lot of traction in recent years, not just because it’s a great product and there isn’t nearly enough content out there about it. To help the people after me, and because I did this for work anyway, I created a short video on how to install FortiWeb on Proxmox and migrate…


  • Connecting to an HA FortiClient EMS cluster without an external load balancer

    Do you want redundancy? Don’t answer that question; the answer is “Yes!” This means you want your FortiClient EMS deployment to be redundant, and this gives you the problem of how to handle the FortiClients and FortiGate connection to your HA EMS nodes if you don’t have an external load balancer. Well, dear reader, I’ve…