: Newer FortiOS versions use Anycast for communication, which can sometimes experience TLS handshake failures (TLSv1.3).
If your WAN interface receives its IP via DHCP or PPPoE, the ISP may be pushing DNS servers that cannot resolve Fortinet's internal DDNS domains.
The firewall cannot call home if its baseline routing or account state is broken. Run validation checks to guarantee external connectivity: