Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hello Fortinet Community Users!As you have seen in recent banner updates, we are in the process of upgrading the Fortinet Community. Our long-term goal with this change is to provide a foundation for a more modern user experience that scales with all of us as we grow the Fortinet Community together. Phase 1 Starting the Week of April 13thPhase 1 migrates all the great Community content you have been a part of creating over the past 10 years. Future releases will add personalization, more localization options, and additional functionality to make it easier to create and consume content. Key dates and what to expectRead‑only window: The current Community will be read‑only starting the week of April 13 and will remain read‑only for ~6–7 days before the new site launches. We apologize in advance for this unavoidable part of this project. 2‑hour production test: We will switch to the new Community for 2 hours on April 16th from 10:00 AM PST to Noon PST. The new site will function normally
How to generate a FortiAnalyzer report to get ISP uptimes?
Hello Fortinet Community,We recently upgraded our FortiGate to FortiOS 8.0.0. Before the upgrade, the device was running FortiOS 7.2.13 7.4.12 7.6.7, and we created a full configuration backup.After the upgrade, we experienced an unexpected internet outage. During the incident, the FortiGate had a high number of active sessions, and users lost internet connectivity. A reboot temporarily restored the service.At this time, we cannot confirm whether the issue was caused by FortiOS 8.0.0 or another factor. However, since the environment was stable before the upgrade, we are considering downgrading to the previous stable version while continuing our investigation.We would appreciate your advice on the following:Is it recommended to downgrade from FortiOS 8.0.0 to FortiOS 7.6.7, or would FortiOS 7.4.12 be a better long-term stable version?Since we have a configuration backup created while running FortiOS 7.6.7, can we safely downgrade and restore that backup?Are there any known issues or pre
Hello Techies i have 15 fortigate firewall that is getting authenticated by cisco ise tacacs, now i want to enable MFA for all firewalls is there any possibility to set asingle code for all firewalls.i have tried fortitoken but that require different otp for each firewall
overlay working but underlay under the members i dont see the physcial port 1 an port 2I have config SDWAN ADVPN 2.0 i was able to to setup the overlay SDWAN but when trying to config the undelay SDWAN, i have created a Zone for underlay, but when i am trying to add the ports to the underlay zone the ports which the ISP are connected dosent show (port13 and port14)
People on Fortigate 7.4.12 using FAC as the Captive Portal are all working fine, I built some new sites on 7.6.7 and the config is identical, only now they cant Authenticate, they hit the Exempt rule to get to the FAC on https, and they register and get approved, but they cannot authenticate when logging in to the page.I've never liked the logs on FAC, they are not helpful at all! but most of the messages are “Guest portal authentication request failed, then says please check the Radius Auth logs, but there are none! as they don't Auth! Has something changed in the way 7.6.X Authenticates now? The EAP-TLS is working fine for the other SSID, its just Captive portals (Once again!) even in debug mode there is nothing when I search for the failed user, its most annoying, I am using “set require message authenticator enabled” but on 7.4.12 its disabled as its disabled on the FAC, is this enforced now?In short it works on 7.4.12 but not 7.6.7. , Scowered the release notes and cant see anyt
Using the standard Portal templates, just adding custom logo etc, it isnt responsive to mobile phones, Apple or Android, I have tried to add extra CSS to the template for login, registration , disclaimer etc. but it just doesnt lay out right, Does Fortinet not have a fix for this or a guide for the best way to add viewport in the CSS? I did CHATGPT it, but it still not quite right, I mean this is standard stuff these days right?ForiAuth 8.0.3 Thanks
We have policy only device managed by Intune can be conenct to the network.In the intune i have host below, the endpoint only showing wirelesss mac address, but actually the endpoint have 2 mac address (wired and wireless). This make the user can’t access to the network because wired mac is detected not managed by MDM. Anyone know why?
Hi everyone, I'm experiencing a strange issue with an IPsec Dial-up VPN after migrating users from SSL VPN. The environment is FortiGate 400F with FortiClient VPN 7.4.3.4323 on macOS Sonoma 14.1. The problem only affects macOS clients; Windows clients using the same VPN configuration and user account work correctly. Split tunneling is enabled, and all firewall address objects are configured correctly as /24. However, after connecting from macOS, one of the split-tunnel routes is installed with an incorrect mask (for example, 10.10.10.0/24 becomes 10.10.10.0/31). If I remove that subnet from the split-tunnel group, the issue moves to the next subnet (10.10.11.0/24 becomes 10.10.11.0/31), so the problem follows the route order rather than a specific network. I also tested with a split-tunnel group containing only three networks, and everything works correctly on macOS. The production split-tunnel group contains around 190–200 routes. Has anyone encountered a similar issue or knows wheth
Hi all,just started my first FortiSwitchNMS deployment with about 50 FortiSwitch Rugged at a customer site and am now planning further steps to improve the whole setup.Since the product is quite new and community resources are limited, I wanted to reach out and see if anyone here has done something similar or already deployed the product in general.I'm planning to use ZTP via DHCP option 138 to onboard the switches.Has anyone actually used this in production? Curious whether it works reliably out of the box or if there are quirks to watch out for.I'm also trying to figure out what good day-to-day operations would look like or which features you like.There are functions for backup management that sound quite useful for device replacement scenarios, and I'm wondering how others handle firmware rollouts across a larger switch fleet without things going sideways.The VLAN management in the NMS web UI is a bit confusing and not as intuitive as I'm used to in FortiOS...But maybe I'm missing s
Hello.Working as a Telecom user, I can only use Putty and similar software for SSH and Telnet connectivity with the Dacon VPN, but not with the Planet VPN.From IAM support, they replied that I am enabled without hindrance with both SSH and Telnet.Can anyone help me? Thanks in advance.
Hello, we have an issue about forticlient application, 1. installed application2. imported configuration file successfully3. while entering username and password and click connect button, app does not do nothing, just clearing username and password also, tried to uninstall, clean reinstall of application with revo uninstaller pro, but didn't work, also trierd to debug on firewall and there was no any traffic matching. application version is 7.4.3.4726 We tried the same installer file and the same vpn configuration file on other desktop and it worked successfully, the main thing is that we can not reinstall windows but need to setup the forticlient vpn urgently.
Hi everyone,I'm currently setting up FortiXDR and I'm a bit confused about the required FortiAnalyzer configuration.Our environment consists of:FortiClient EMS Cloud FortiXDR license Local FortiAnalyzer VM (no FortiAnalyzer Cloud license)We do not have a FortiAnalyzer Cloud license, only a local FortiAnalyzer VM.My question is:For FortiXDR, where should the FortiClient logs (configured in the System Settings Profile) be sent?Should the FortiClients send their logs to a FortiAnalyzer Cloud instance, even though we don't have a FortiAnalyzer Cloud license? Or is it supported to send the logs directly to our local FortiAnalyzer VM while still using FortiXDR?Most of the users work from home, so we are currently using a DNAT with TLS configuration.Has anyone successfully deployed FortiXDR with EMS Cloud + local FortiAnalyzer?Kind regards,MG4
Hi TeamI have around 200 VPN users. It requires monthly administration tasks to ensure VPN access is revoked timely for resigned leavers, interns and staffs no longer require VPN access. It is for IT Audit Policies.On Fortigate firewall, this is not a helpful task. My Fortigate (FortiOS 7.2 & 7.4), have not that option of per-user vpn account expiry date !!However, on Cisco Meraki MX, it allows configuring an account expiration date on VPN users directly. This was very useful since 1st Covid 2020 to date.Are there any workaround?
Request to get pkg file of Forticlient VPN Only for MacOS to use with Intune in Download page it is online installer I cannot use with Intune I need to real file of it
Hello Fortinet Team,I would like to report a False Positive occurring in FortiClient. The antivirus engine is flagging and quarantining legitimate .jar files that belong to Microsoft Power Automate Desktop.These files are required by the Microsoft application to interact with Java-based interfaces for automation purposes.Software: Microsoft Power Automate Desktop Flagged Files: PAD.JavaBridge.jar PAD.JavaBridge.A11y.jar Some of the File Hashes (SHA256) involved: CF531D64F2445BD6149EF018D41C6B6EDC2185461100998DFF8204... 0887F61DB05200C724DF9E0700F63B98145E47C69FB98258323AB6... EB935EB8D28CDBA566CBACDA023E02FCD4A9DB0535893B5B8699E7... I have attached a screenshot ("Captura de pantalla 2026-07-20 110922.png") showing the multiple detections and the exact hashes provided by the FortiClient logs.Could you please review these files and update the definitions to whitelist them?Thank you.
I am considering changing the username of the default "admin" user on FortiGate.I understand that it is possible to create a new superuser and change the "admin" username, but will changing the default "admin" username affect other settings?
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
I have difficult to add switch Alcatel omniswitch 6860 can some one help.When I configure credential snmp is OK but CLI I can't connect it. When I test in fortinac console cli all is ok but in gui no.
Hi Fellas,I'm deploying FortiClient EMS 8.0 using Microsoft Intune (Win32 app) and have run into an issue.Environment FortiClient EMS 8.0.x Microsoft Intune (Win32 app) Deployment package generated from EMS with MSI Installer Files enabled EMS generated: forticlient.msi forticlient.mst PackagingBoth files were placed in the same source folder and packaged into a single .intunewin using IntuneWinAppUtil.exe.The install command in Intune is:msiexec.exe /i "forticlient.msi" TRANSFORMS="forticlient.mst" /qn /norestart /L*v "%ProgramData%\Microsoft\IntuneManagementExtension\Logs\FortiClientInstall.log"IssueThe installation completes successfully, but when FortiClient launches, it still displays the "Enter Invitation Code or IP Address" screen.Even when I manually enter the Invitation Code or the EMS IP address, the client does not register with EMS.Additionally, the folder:C:\Windows\FortiEMSInstaller_logsis not created, so there are no EMS installer logs to review.Expected B
Hi everyone,I have configured DNSBL under Profile > AntiSpam > AntiSpam on my FortiMail.I'd like to verify whether the DNSBL configuration is actually working as expected. Is there a way to confirm this from the FortiMail side?Specifically, I'm looking for answers to the following:Are there any logs or event logs that indicate DNSBL lookups are being performed? Is there a CLI command or diagnostic command that can be used to verify DNSBL functionality? What's the best practice for testing whether DNSBL is functioning correctly?If anyone has experience with this or can share the recommended verification steps, I would really appreciate it.Thank you in advance!
Hi,FortiClient VPN on Android 16 disconnects immediately after a successful IKEv2 certificate authentication against a FortiGate 101F running FortiOS 7.4.12.FortiGate debug shows:certificate validation succeededsignature verification succeededauthentication succeededmode-cfg assigned IPv4 address 10.242.221.100added IPsec SAtunnel up event assigned address 10.242.221.100 Immediately after that, the Android client sends:received informational requestprocessing delete request (proto 1)deleting IKE SAFortiClient Android only shows:START → STARTED → TUNNELLING → ERROR → DISCONNECTED No useful error is displayed. Logs show:authenticationFailure falseconnectionFailure falsefailureReason null The same VPN configuration works perfectly from Windows.DNS changes, send-cert-chain disable, and fragmentation changes did not change the behaviour. The FortiGate uses a wildcard server certificate. Client certificate authentication is successful.Has anyone seen Android 16 / FortiClient Android immediat
I would like to clarify the behavior regarding the display of warning and block screens in the Web Filter.We are currently configuring a system using FortiOS v7.6.7 and applying Web Filtering to internet-bound traffic.When a client device—with the CA certificate installed—attempts to access a site falling under a blocked category, the connection fails.* The error message "Your connection to this site is not secure (ERR_SSL_PROTOCOL_ERROR)" is displayed.We performed troubleshooting by changing the inspection mode setting for the relevant policy, with the following results:- Flow-based: The block page is not displayed.- Proxy-based: The block page is displayed.The Web Filter feature set within the security profile is configured for flow-based inspection in both cases.My understanding is that warning and block screens should normally be displayed even with flow-based settings in FortiOS v7.4.Have you encountered similar inquiries or issues?Also, could you provide any information regarding
HiHow many SSIDs are recommended?I read that only 3 are needed. Okay, I understand that one for IoT/External, one for Internal and one for Guest.My challenge is about the ssid pasword. I will have around 600 users using ssid External.How to manage if the password has been shared or leaked?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.