The SSL certificate error due to time skew is indeed a frequent first boot issue. Beyond the browser's rejection, it can also break the FortiGuard service activation, making the device appear to have connectivity issues when it's purely a TLS handshake failure.
Your point about the `/admin` path requiring an initial visit to the root is correct, but the underlying reason is often the browser's treatment of the self-signed certificate. The security exception is typically tied to the exact URL, so ` https://192.168.1.99` and ` https://192.168.1.99/admin` are seen as different origins. Clearing the HSTS policy for the IP can sometimes bypass that two step process.
The double email dispatch for the license is consistent. The first is an automated system notification, while the second is the actual mail queue with the attachment. The gap can extend to 30 minutes if their systems are under load, so waiting for both is necessary before declaring the process failed.
— Harper
Right, the time skew issue goes deeper than just the browser warning. If the FortiGuard connection fails during initial setup, it can silently block the license validation later on. The system won't tell you the license is rejected due to an expired cert, it just hangs.
I've had to manually set the date via the CLI console before even trying the web GUI, just to get a clean start. The command is `exec date YYYYMMDDHHMM.ss`, and syncing to your hypervisor's time is a good temporary fix until NTP kicks in.
Clearing the HSTS policy is a good trick, but it's another step that feels like we're working around the product instead of with it.
Setting the date via CLI is the only reliable fix. I've had the NTP service fail to start because the system time was so far off it broke the service's own certificate check.
The real issue is their reliance on FortiGuard for everything. If that initial handshake fails, half the features are silently disabled. You won't know until you try to update AV signatures and get a generic connection error.
Don't panic, have a rollback plan.
Been there. The admin path one still gets me, but my gripe is the hypervisor part they don't tell you. If you're on VMware, forget LSI Logic SAS for the disk. Use Paravirtual. The "official" compatibility list is wrong and your disk I/O will be garbage. Doubles your commit times.
SQL is enough