Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hello Fortinet Community Users!As you have seen in recent banner updates, we are in the process of upgrading the Fortinet Community. Our long-term goal with this change is to provide a foundation for a more modern user experience that scales with all of us as we grow the Fortinet Community together. Phase 1 Starting the Week of April 13thPhase 1 migrates all the great Community content you have been a part of creating over the past 10 years. Future releases will add personalization, more localization options, and additional functionality to make it easier to create and consume content. Key dates and what to expectRead‑only window: The current Community will be read‑only starting the week of April 13 and will remain read‑only for ~6–7 days before the new site launches. We apologize in advance for this unavoidable part of this project. 2‑hour production test: We will switch to the new Community for 2 hours on April 16th from 10:00 AM PST to Noon PST. The new site will function normally
My WAN utilization is full (total 20Mbps), how we can easily which source is consume high bandwidth?I try to block the graph and click fortiview source and destination and if i compare with the Netflow from my NPM then the source is different.
FortiEMS 8.0 managed FortiClient 7.4.7 using FortiTokken.after first time enter user and password details it don’t ask again user credential only fortiTokken.But as per compliance i have to configure like fortiClient ask everytime user password .i already disable the option save pasword and auto login. still same and in fortiClient (Save login) grayed.
HelloI completed the NSE 2 course successfully, but my NSE 2 certificate/badge is still not showing in my account.More than 48 hours have passed since I completed the course.Thank you.
Hi I am using ssl inspection on my lab.I have downloaded the certificate from fortigate and installed it on windows trusted store and on Firefox.but still have the certificate warning problem ! What do i miss?
have a FG 70G 7.4.12 and a windows client with free VPN 7.4.3.4726I have followed the doc:https://docs.fortinet.com/document/fortigate/7.4.12/administration-guide/785501 but when I try to connect, the client says “Timeout while connecting” I have diagnose sniffer packet wan1 "udp and port 500" running, and see 4 packets every time I try to connect like:19.844532 1.247.132.25.1012 -> 214.153.140.239.500: udp 668The odd part (to me) is that I do not see anything in the GUI System Events > VPN Logs >Memory.I’ve made sure the proposals match on both sides.I’ve done this before multiple times on 7.2 and older, and never had these kinds of problems.Any suggestions?
Hello buddies,I’m new to the Fortinet community and would like to start learning how to properly configure and manage FortiGate.My goal is to set up a small hands-on lab where I can learn about firewall policies, VLANs, VPNs, web filtering, and basic network security without affecting the production environment.Could you recommend a learning path, course, documentation, or lab setup suitable for beginners? Would FortiGate-VM be suitable for this purpose? What networking knowledge should I have before getting started?Thanks for any guidance or recommendations here.
Hi FWB adminsFortiWeb 8.0.6, I set it up as SP.When I try run SAML debug as documented in admin guide and perform SAML authentication, I get redirection to SP but I get nothing in debug output.diagnose debug application samld -1 (or 7)diagnose debug enable<output empty>Is there something else to enable in order to make SAML debug work? Any help would be appreciated.
I have configured a FortiSwitch Dynamic Port Policy (DPP) to allow only 3 specific MAC addresses on a switch port. When one of the legitimate MAC addresses is connected, the DPP identifies the device and assigns the configured dynamic VLAN successfully.However, I am experiencing an issue when the legitimate device is disconnected and an unauthorized device is connected to the same port shortly afterward.My test scenario is:Connect legitimate device (Test_MAC1). DPP identifies Test_MAC1 and assigns the dynamic VLAN. Test_MAC1 is disconnected from the switch port. Within a few seconds, connect an unauthorized device (Test_MAC4). Test_MAC4 is not included in the DPP allowed MAC list. However, Test_MAC4 still receives an IP address from the previously assigned dynamic VLAN and can access the network.It appears that the dynamic VLAN assignment/state is not being flushed immediately when the legitimate device is removed from the port.Is there any way to Fix this?Dynamic port policy Configura
Some users need to access Tor, so I created a rule and set the destination to the Fortinet Internet Service Database (ISDB) associated with Tor. We tested it and saw that they could access Tor pages via the web. However, when the user tries to access the "tor.browser" application, it doesn't load. These users have internet access, but only through HTTP and HTTPS ports. Wasn't the TOR.BROWSER application part of the Fortinet Internet Service Database (ISDB)? Or is it necessary to add the ports used by TOR.BROWSER to the internet access policy? Do you know which ports that application uses, tor.browser?
.
Hi I'm trying to collect Palo Alto logs into FAZ.If I want to view the normalized logs, do I have to use the log parser?cause I use Log View --> Log Browse, it only showing raw log.
I would like to understand whether the following design is possible and, if so, how it can be configured on a FortiGate 200F or 600F.Current Topology:FortiSwitch 124F ── FLINK_INET_1 ────┐ FortiGate 200FFortiSwitch 548D ── fortilink ───────┘FortiSwitch 124F-POEVLAN 700 configured with IP address 11.11.11.1/30Connected to FortiGate 200F via a FortiLink-enabled interface i.e FLINK_INET_1.FortiGate 200FConnected to both FortiSwitches using separate FortiLink-enabled interfaces.Requirement is to configure VLAN 700 as a Layer 2 bridge only, without Layer 3 routing on the FortiGate.FortiSwitch 548D-FPOEVLAN 700 configured with IP address 11.11.11.2/30Connected to FortiGate 200F via another FortiLink-enabled interface i.e fortilink.RequirementI need VLAN 700 traffic to pass transparently through the FortiGate 200F, effectively allowing the two FortiSwitches to communicate as if they were on the same Layer 2 VLAN.QuestionHow can VLA
Hello,is there any way to get prepared for NSE1 other then Fortinet Learning Center ? Thanks
We are using the free version of FortiClient VPN, and I have found that with both an older version of FortiClient, both 7.4.3.1790, and the latest version, 7.4.3.4726, I am getting the error in the attachment occasionally when fortiauth,exe loads to prompt for credentials to connect. It even does this after I removed and re-added Net 4.8 as a windows feature. Any thoughts? That I know of it is just my machine, but I work fully remote, so I really need to get this resolved.
Dear Security Review Team, I am writing on behalf of IASC Ltd. (Indian Applied Science Corporation) regarding the security classification and/or blocking of our institutional domain: https://newiasc.com IASC Ltd. is an independent institution operating in the maritime security, competency, technology, research and engineering domain. Our website provides institutional information, professional publications, maritime research, technical material and related professional services. We have been informed that newiasc.com is currently subject to an adverse security or reputation classification within external security and website reputation systems. We respectfully dispute any such classification and request an immediate formal false-positive review of our domain. The domain is operated and controlled by IASC Ltd. and is not operated for phishing, fraud, malware distribution, scams, spam, gambling, adult content or other malicious activity. We have conducted server-side verification of our
Hi,I’m using fortimanager provisionning template to manager my IPSec VPN.I’m create a template.In this template I create a IPSec tunnel (Phase 1 and phase 2) with a name like myipsec_model.To create a second Ipsec tunnel, I’m click on clone option. A new tunnel it created with this name : clone_myipsec_model.I can’t rename the new IPSec configuration. I cleck on rename button change the name but this one is not change.I’m use fortimanager 7.6.7.Thanks you for your helpRegardsStéphane
Hi,For one of our customer, I have got the FortiGate 200G firewall as rented device as we are yet to receive our own new firewalls due to lead time. Meanwhile after changing the device password, firewall is asking for Forti care registration which I don't have as this been rental device, is there any way forward for this, I tried skipping the registration from bios but firewall does not boot further with error - Failed to boot the system.
I have two 5G modem with same IP ranges 192.168.0.1/24. When i change modem IP ranges, internet speed 1 out of 100 and very poor. I need solution to connect both modems to use as 50/50 weight. kindly guide me the steps. really i am fresher for network setup.
want download fortiauthenticator vm
Hi, I have a couple of related questions about FortiSIEM Windows Agent architecture:Is it possible to install the FortiSIEM Windows Agent and configure it to send event data directly to the Supervisor, without going through a Collector? Does an All-in-One Supervisor deployment have built-in Collector capabilities? In other words, can the Supervisor itself receive uploads from Windows Agents, or is a dedicated Collector node always required for Agent-based log collection? If a separate Collector is mandatory, is there any workaround for small/single-node deployments, or is a Collector required regardless of environment size?
I'm facing a strange issue with a new FortiGate VM instance running on Proxmox.EnvironmentHypervisor: Proxmox VE FortiGate: FortiGate VM Disk image: fortios.qcow2 Access: Web GUI over HTTPS Version: FortiGate-VM64-KVM v8.0.0.build0167.260420 (GA.F)IssueI created a new FortiGate VM using the fortios.qcow2 image.The VM boots successfully, and I can access the FortiGate GUI login page. I can also enter the admin credentials and authentication is successful.However, immediately after successful login, I am logged out and redirected back to the login page.So the behavior is:FortiGate GUI Login ↓Enter credentials ↓Authentication successful ↓GUI starts loading ↓Immediately logged out ↓Redirected back to Login pageThere is no normal session timeout involved because the logout happens immediately after login.Troubleshooting already attemptedI also tried increasing the administrator timeout:config system global set admintimeout 30endHowever, this did not res
Can you link your fortinet work account with your personal account so that the NSE’s transfer, kind of like microsoft’s way?Does it work all the time or does it depend on different factors, if so, what are the factors that make the process difficult or complicated?
Hello Fortinet Community,I have installed FortiGate-VM64 FortiOS 8.0.0 in my EVE-NG lab environment.The FortiGate VM boots normally, and I am able to access the GUI login page.Current IssueI can successfully enter my credentials and the GUI appears to authenticate successfully. However, immediately after login, I am logged out and redirected back to the login page.In other words:Open FortiGate GUI. Enter username and password. Authentication appears successful. GUI starts to load. Immediately after that, the session is terminated and I am returned to the login screen.EnvironmentPlatform: EVE-NG Device: FortiGate-VM64 FortiOS: 8.0.0 Build: 0167 Image: FGT_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm.zip Deployment: KVM/EVE-NGLicense StatusThe FortiGate license is showing Up to Date / Active, so there does not appear to be an obvious licensing issue.What I have checkedFortiGate VM is booting normally. GUI is reachable. Username/password are accepted. License status shows up to date. The
Would it be possible to get more info logged on the reason why the disposition was deferred? is ther a setting in the configuration that regulates this? Can a whitelisted sender also be “blocked” like this? Would whitelisting of the domain or sender by the user be sufficient to avoid this? Could the receiver be informed when there is a mail stuck as "Accept; Defer disposition"? With the reason why?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.