Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hello Fortinet Community Users!As you have seen in recent banner updates, we are in the process of upgrading the Fortinet Community. Our long-term goal with this change is to provide a foundation for a more modern user experience that scales with all of us as we grow the Fortinet Community together. Phase 1 Starting the Week of April 13thPhase 1 migrates all the great Community content you have been a part of creating over the past 10 years. Future releases will add personalization, more localization options, and additional functionality to make it easier to create and consume content. Key dates and what to expectRead‑only window: The current Community will be read‑only starting the week of April 13 and will remain read‑only for ~6–7 days before the new site launches. We apologize in advance for this unavoidable part of this project. 2‑hour production test: We will switch to the new Community for 2 hours on April 16th from 10:00 AM PST to Noon PST. The new site will function normally
What are these highlighted labels??? All testing passed???Seen after upgrading from 7.6.6 to 7.6.7 (Azure)
Hi,Environment: EMS 7.4.7, FortiClient mobile (iOS/Android) 8.0.0, FortiOS 7.6.7. ZTNA access proxy already used by Windows/macOS endpoints.ZTNA certificate signing works automatically for Windows/macOS on telemetry connect. For mobile, EMS only offers ZTNA certificate provisioning via MDM (Intune/Jamf/Workspace ONE, SCEP). We have no MDM for these users.Questions:1. Is manual (non-MDM) ZTNA certificate installation supported on FortiClient iOS/Android? If not, is it a hard limitation or roadmap?2. If supported, what is the correct procedure (cert format, storage location, how FortiClient uses it for ZTNA)?Thanks.
Using the standard Portal templates, just adding custom logo etc, it isnt responsive to mobile phones, Apple or Android, I have tried to add extra CSS to the template for login, registration , disclaimer etc. but it just doesnt lay out right, Does Fortinet not have a fix for this or a guide for the best way to add viewport in the CSS? I did CHATGPT it, but it still not quite right, I mean this is standard stuff these days right?ForiAuth 8.0.3 Thanks
Hi everyone, I'm experiencing a strange issue with an IPsec Dial-up VPN after migrating users from SSL VPN. The environment is FortiGate 400F with FortiClient VPN 7.4.3.4323 on macOS Sonoma 14.1. The problem only affects macOS clients; Windows clients using the same VPN configuration and user account work correctly. Split tunneling is enabled, and all firewall address objects are configured correctly as /24. However, after connecting from macOS, one of the split-tunnel routes is installed with an incorrect mask (for example, 10.10.10.0/24 becomes 10.10.10.0/31). If I remove that subnet from the split-tunnel group, the issue moves to the next subnet (10.10.11.0/24 becomes 10.10.11.0/31), so the problem follows the route order rather than a specific network. I also tested with a split-tunnel group containing only three networks, and everything works correctly on macOS. The production split-tunnel group contains around 190–200 routes. Has anyone encountered a similar issue or knows wheth
EnvironmentFortiGate: FG-60F FortiOS: 7.2.13 (Build 1762) FortiAP: FAP-231K-E (Brand New) Switch: Cisco Catalyst C1300 (L3 Switch)FortiGate 60F | |-->L3 P2P LinkCisco Catalyst 1300 (L3) (WIFI-VLAN gateway and DHCP configured here, interface vlan 30) |FortiAPCurrent BehaviourAP successfully receives an IP address from the Cisco DHCP server.AP can ping the FortiGate.FortiGate can ping the AP.No Local-In Policies are configured.Two different brand-new FAP-231K-E units have been tested.However, the AP never appears under WiFi & Switch Controller → Managed FortiAPs. Current BehaviourAP successfully receives an IP address from the Cisco DHCP server. AP can ping the FortiGate. FortiGate can ping the AP. No Local-In Policies are configured. Two different brand-new FAP-231K-E units have been tested.However, the AP never appears under WiFi & Switch Controller → Managed FortiAPs.diagnose wireless-controller wlac -c wtpTotal 0 WTPsget wireless-controller statuswtp-session-count: 0
Hi,FortiGate 7.6.7, IKEv2 dialup with EAP, mode-cfg and IPv4 split tunnel enabled. internal-domain-list is configured, but split DNS never takes effect: every DNS query from the client reaches the FortiGate, not only the two internal domains.config vpn ipsec phase1-interface edit "<tunnel>" set type dynamic set interface "<wan-if>" set ike-version 2 set peertype one set net-device disable set mode-cfg enable set ipv4-dns-server1 <internal-dns-ip> set internal-domain-list "domain1.local" "domain2.local" set eap enable set eap-identity send-request set ipv4-split-include "<split-group>" nextendVerified with: diagnose sniffer packet any "port 53" 4 0 l — public domains such as google.com show up as well. Same result on FortiClient (Windows) 7.4.3 and FortiClient mobile 8.0.0. VPN was fully reconnected after each change.Questions:1. Anything else required in 7.6.7 for internal-domain-
Hello Fortinet Community,We recently upgraded our FortiGate to FortiOS 8.0.0. Before the upgrade, the device was running FortiOS 7.2.13 7.4.12 7.6.7, and we created a full configuration backup.After the upgrade, we experienced an unexpected internet outage. During the incident, the FortiGate had a high number of active sessions, and users lost internet connectivity. A reboot temporarily restored the service.At this time, we cannot confirm whether the issue was caused by FortiOS 8.0.0 or another factor. However, since the environment was stable before the upgrade, we are considering downgrading to the previous stable version while continuing our investigation.We would appreciate your advice on the following:Is it recommended to downgrade from FortiOS 8.0.0 to FortiOS 7.6.7, or would FortiOS 7.4.12 be a better long-term stable version?Since we have a configuration backup created while running FortiOS 7.6.7, can we safely downgrade and restore that backup?Are there any known issues or pre
What am i missing with the configuration:I get the dialup VPN to connect(i.e i am connecting from the PC at port 5 and using 10.10.0.1 as my gateway in forticlient, and i can see that it assigns the correct VPN according to my mode cfg, but when i inspect the vpn logs for the vpn_user_site, there is no traffic traversing the vpn. And even if i do a packet capture of the s2s tunnel interface, or port 5 interface, or both port 1 interfaces on the firewalls, i get no instance of 10.101.101.254 as the destination address. I am new to this and don’t understand the tunnel within a tunnel concept really that well, hence the lab setup i have.To my understanding the only thin i need is a policy that allows the traffic from the remote access vpn to the LO0 interface? I am missing something (since it is not currently working haha, so if anyone has insights or can explain to me how this would be setup correctly. It would be much appreciated.
Today i check our users can’t connect to the fnac and i got this error. I check service connector to the entra is have pronle, where i test to poll and test connection but always loading. The i reboot the nac and the error was gone and the authentication is successful.Something wrong in my fnac?
HiHow many SSIDs are recommended?I read that only 3 are needed. Okay, I understand that one for IoT/External, one for Internal and one for Guest.My challenge is about the ssid pasword. I will have around 600 users using ssid External.How to manage if the password has been shared or leaked?
A couple days ago, I helped one of my clients with installing the FortiClient v7.4.5 on his computer using the FortiClientSetup_7.4.5_x64.exe file. But after the setup process was completed, we noticed that the domain name was not correct; it was showing the domain name of his current company that he works for instead of the domain name of his contractor’s company. So I tried to uninstall the program from Windows Control Panel → Programs and Features → Select FortiClient, but it did not let me uninstall the program. I tried clicking the Repair button, too, but it also did not work.I tried browsing to https://support.fortinet.com -> Support -> Firmware Downloads -> Products, but I got the following message: Sorry, you don't have any product covered by Fortinet support contract.Please contact Fortinet partners to purchase Fortinet support contract or Fortinet customer service team at cs@fortinet.com.And I asked my client if he knew who to contact to download the FortiClientTools
Hello to Everyone, I am playing with the trial VM and I am wondering except doing tcpdump packetsniffer what are the options to debug ssl hanshake issues like unsuppored ciphers ? I am interested for proxy mode rules and flow mode rules and if there is an option when you enable debug flow simillar to fortiweb (Diagnosing SSL/TLS handshake failures | FortiWeb 7.6.0 | Fortinet Document Library) to see such information? Maybe also a "debug application" option as mentioned in Solved: debug SSL inspection for flow based vs proxy based... - Fortinet Community as for proxy mode "wad" process is used. I am wondering for the ips and wad what debug to enable to see the ssl handshake. I enabled the options in Extended logging for SSL traffic - Fortinet Community and I see unsupported ciphers error for 7.2 that is the last trial VM version having flow and proxy mode and I see the issue with SSL failing for proxy mode. Maybe this is why it i
Hi allI have noticed a weird issue, client had a power outage over the weekend as the redid the server room UPS.Now my AP’s show “Connected VIA” my VOIP interface on the FortiGate, even tough they are connected via FortiSwitches and the LLDP Neighbors are correct, also the IP’s they get are from my DATA VLAN.They use to say connected via DATA VLAN and once rebooted they now show VOIP. all troubleshooting points to they are indeed connect via DATA VLAN.GUI BUG? FortiGate 7.4.12 , FortiSwitches 7.4.8 and FortiAP’s 7.4.6Please let me know if anyone has experienced this and why now all of the sudden?
Hi everyone,I'm just starting my journey with Fortinet and studying for the NSE4, so I'm still learning how some concepts differ from Cisco.I have a quick question:Is there a way to configure a physical interface as an access port, similar to Cisco switches using switchport mode access and switchport access vlan <VLAN_ID>?For example, can a FortiGate interface be configured to carry only a single untagged VLAN without using a trunk or VLAN subinterfaces? Or is the recommended approach always to use 802.1Q VLAN interfaces on top of a physical interface?I'd really appreciate any explanation or best practices. Thanks in advance!
Hello,If we need to deploy a cluster of two FortiGate firewalls as VMs without using the virtual MAC (vMAC), and instead use the hypervisor-assigned MAC address of each firewall interface, I would like to confirm whether this type of cluster configuration is supported.In other words, is it possible to operate a FortiGate HA cluster without using the vMAC mechanism and have each firewall use its own physical/virtual interface MAC address during a failover event?Thank you for your clarification.
Hi,I would like to just ask around (not going to open an official case with fortinet just now) if any of you have noticed something similar recently.I have a very low but increasing number of users that start up their laptops in the morning and the Forticlient ZTNA has lost it's license resp. the affiliation to the EMS cloud. No config left, not connected.The respective laptops do not show up in EMS any longer. When I enter a new invitation code in the Forticlient incl. User verification, it connects again and receives config and all is good.I can rule out that the user hit the "disconnect" button on the ems connection because that is password protected.The only thing common, that I think I identified, is that all affected users don't connect to the vpn daily.
Product: FortiGate-101FFortiOS Version: 7.6.6, build 3652HA Mode: Active-Active (A-A), ha-direct enabledCluster Members: Primary / SecondaryCluster Status: Healthy, in-sync, uptime 86+ daysSyslog traffic configured under config log syslogd setting is not reaching our syslog collector (10.0.0.151:514/UDP), despite the syslog daemon reporting successful log processing. No syslog packets are observed on any interface via packet sniffer, even though routing to the destination is confirmed correct and other traffic to the same host (ICMP, TCP/5986) is confirmed working.config log syslogd setting set status enable set server "10.0.0.151" set mode udp set port 514 set facility local7 set format default set priority default set interface-select-method auto set vrf-select 0endconfig router static edit 2 set dst 10.0.0.0 255.255.255.0 set gateway 10.37.81.2 set device "port4" next edit 3 set dst 10.0.0.151 255.255.255.255 se
I have 2 FortiGate 100F firewall setup in HA A-P and dedicated HA-MGMT interface is configured with dedicated OoB interface, I have a internal webproxy server in Layer 2 VLAN with DNS and FGT is also in the same VLAN and is pinging Proxy and I want to setup those firewall to use that proxy server to connect to fortiguard, I am trying to setup but it is not working through OoB interface. Appreciate support here.
Is anyone able to provide me with the firmware for a Fortinet 60F firewall?
Hello.Working as a Telecom user, I can only use Putty and similar software for SSH and Telnet connectivity with the Dacon VPN, but not with the Planet VPN.From IAM support, they replied that I am enabled without hindrance with both SSH and Telnet.Can anyone help me? Thanks in advance.
Hello,I need to grant a specific USER/IP access to a specific path, which is as follows:https://dl.k8s.io/release/v1.36.1/bin/windows/amd64/kubectl.exeI usually use STATIC URL entries, where I typically set the FQDN to “SIMPLE” and “MONITOR” modes—meaning I just use dl.k8s.io—but in this case, I’m required to ensure that only the specified source has access to the URL I’ve provided.Is there anything specific I need to do to achieve this?What are the correct “Type” and “Action” to use in this scenario?Do I need to take the “SSL/SSH Inspection” configuration into account?Thanks for your feedback.
I couldn’t find much information on enabling the all events portion of FortiClient EMS (I’m running 7.4.7). After a couple of weeks playing with it I finally got it working. But just a quick overview I wanted to post in case others have tried and failed at setting this up. So what you need to do is setup a Linux VM (I used Debian 13 Trixie) and install ElasticSearch. Then you have to make sure its reachable on the network by modifying the YML file. Then install Kibana and do the same for it. Kibana is the GUI management tool that makes working with ElasticSearch easier. Then you create an API Key for FortiEMS. Then you upload the http_ca.crt to FortiEMS. Then you run the emscli command for enabling ElasticSearch. That is pretty much the overall process.
Hello,I currently have SSL VPN active and I want to switch to IPsec VPN (IKEv2 Remote Access).Environment:FortiGate model: FG-101FFortiOS version: 7.4.11VPN type: IKEv2 IPsec Remote AccessAuthentication: FortiAuthenticator 6.5.6 build 1391 (GA) with OTPDirectory: LDAP users and groups from Active DirectoryClient: FortiClient 7.4.3 Hotfix 1 (7.4.3.8758)I am configuring an IKEv2 IPsec remote access VPN that authenticates users via FortiAuthenticator using LDAP credentials and OTP.The VPN connection is not successfully established from FortiClient.Phase 1 (SA_INIT) completes successfully, but the connection fails during user authentication (EAP phase).FortiClient shows the following error:Wrong EAP credentialsHas anyone encountered this issue when using IKEv2 with EAP authentication and FortiAuthenticator OTP?Any suggestions or troubleshooting steps would be appreciated.Thank you.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.