User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hello Fortinet Community Users!As you have seen in recent banner updates, we are in the process of upgrading the Fortinet Community. Our long-term goal with this change is to provide a foundation for a more modern user experience that scales with all of us as we grow the Fortinet Community together. Phase 1 Starting the Week of April 13thPhase 1 migrates all the great Community content you have been a part of creating over the past 10 years. Future releases will add personalization, more localization options, and additional functionality to make it easier to create and consume content. Key dates and what to expectRead‑only window: The current Community will be read‑only starting the week of April 13 and will remain read‑only for ~6–7 days before the new site launches. We apologize in advance for this unavoidable part of this project. 2‑hour production test: We will switch to the new Community for 2 hours on April 16th from 10:00 AM PST to Noon PST. The new site will function normally
Hello,In our company we have an EMS instance currently deployed in Azure and we need to move it out to another cloud service. Due to the security requirements given to us, each EMS client must be authenticated with SAML to connect to EMS for management. In the past we have migrated EMS 7.2 to 7.4 Windows → Linux deployment and this caused all of our 2000+ connected users to be thrown out of EMS and needed to be onboarded again. Perhaps someone has already successfully tried EMS migration to another instance (keeping the same FQDN) with SAML authentication enforced? Looking for ways to execute a seamless migration so that endpoints would not need to be onboarded to EMS again. Note that our SAML authentication goes through FortiAuthenticator. Endpoints are ~99% on MacOS. Support has recommended restoring the database/configuration on the new instance but could not definitively say if SAML re-authentication would kick in.Thanks
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
We have become aware of the following security advisories regarding a vulnerability in FortiClient:https://fortiguard.fortinet.com/psirt/FG-IR-26-156https://advisories.ncsc.nl/2026/ncsc-2026-0296.htmlWithin our organization, we exclusively use FortiClient VPN-only for Windows. We do not use the full FortiClient client or FortiClient EMS.Therefore, we would like to know whether the vulnerability described in FG-IR-26-156 also affects the FortiClient VPN-only client.Additionally, we would appreciate clarification on the following:* Is FortiClient VPN-only affected by this vulnerability?* If so, which versions are affected?* Which version does Fortinet recommend installing to address the vulnerability?* Is an updated version of FortiClient VPN-only currently available?* Does the VPN-only client update automatically, or do we need to manually deploy the updated version to all our laptops?We would appreciate your clarification so that we can take the appropriate measures if necessary.Kind r
I asked for an extra IP from the ISP. For that they had given me /29 IP block.They said that they will work under the old pilot IP which was already given by ISP. That IP was configured WAN1 and internet are working well. But I need to use that additional IP under firewall.Because i am going to host one web application server. For that server i need to configure public IP directly.If it comes under the server means i can able manage and control who are all want access the app server. I am using FG101E.
Hi everyone,We are currently using ExtremeCloud IQ Connect Cloud to centrally manage our Access Points.Our current environment has the following characteristics:We are using ExtremeCloud IQ Connect Cloud for centralized AP management. The cloud platform centrally manages the Access Points. SSIDs and VLANs are configured and managed through the cloud platform. There is no on-premises Wireless Controller deployed in the environment. ExtremeCloud IQ Connect Cloud does not provide a dedicated Management IP that can be directly added to FortiNAC as a network device. We have tested adding an individual AP to FortiNAC using the AP's Management IP. FortiNAC was able to connect to the AP and retrieve information such as the SSID.We would like to clarify the following points:Can ExtremeCloud IQ Connect Cloud be directly integrated with FortiNAC, or is it necessary to add/manage each individual AP in FortiNAC? If individual APs need to be added to FortiNAC, can FortiNAC control client access base
dear im going to deployed FortiAuthenticator as external captive portal , guest user will connect to Aruba WLC please guide me to achieve this
i Download VM Forti 8 and istall it but license invalid
HelloOn FortiGate 30E with FortiOS v6.2.3 build 1066 (GA), the administrator user name and password have been changed.Unfortunatly the credentials have been lost.The default admin account is disabled or deleted.There is no other account.is there a way to recover the administrator access, without losing the configuration?Thanks for your help.Philippe
I am using FortiNAC-CA / FortiNAC-OS v7.6.5.0815 (GA) together with a FortiGate and I would like to implement a daily Internet usage limit for self-registered guest users.My requirement is:Guest connects to the Guest Wi-Fi. Guest self-registers through the FortiNAC captive portal. After successful authentication, the guest receives Internet access. The guest is allowed a maximum of 1 hour of Internet access per day. After the 1 hour is consumed, Internet access should be blocked automatically. The guest should not be able to regain access by disconnecting/reconnecting or registering again. After the daily 24-hour reset, the same user/device should receive another 1 hour of access. Ideally, the limitation should be based on the user or device/MAC address, so creating another self-registration session does not bypass the limit.I understand that FortiNAC has Account Duration and Reauth Period, but from the documentation it appears that Account Duration is not a recurring daily quota. For
Hi AllI would like to know if there is a method to export FGT Policies into Excel (csv) format.Please advise any available options. Am using FortiOS v7.4.12 Many thanks
mailfilterd stuck at ~100% CPU, FortiMail 8.0.0 build 183 — cause unclearFortiMail 8.0.0 build 183. mailfilterd sits at ~99.8% CPU continuously (not a spike), RSS grown to ~1.5GB (baseline is usually ~100MB). All other processes idle. Session count (24–50) and bandwidth are normal, so it's not a traffic flood.Enabled diagnose debug application mailfilterd level 8 + duration 30 and pulled the Trace Log. The only thing logged for 10 minutes was:FmailAIClient.cpp:931:ping():entryrepeating once a minute, on a single thread, with no other activity captured — looks like a routine heartbeat, not the actual hot path.I can't figure out what's actually causing the 100% CPU. Any help would be appreciated.
This update covers three connector releases. Microsoft Sentinel moves to a major version, Zscaler changes the APIs behind all its endpoints, and Proofpoint Threat Response picks up a fix. The table at the end links each release to its listing on the Content Hub, where you can review the full release notes.Microsoft Sentinel v2.0.0 introduces a Get Access Token configuration parameter, which supports Application Permission (Without a User), Delegated Permission (On Behalf of a User), and Certificate-Based Authentication. Proofpoint Threat Response v1.0.1 resolves an issue that caused the connector health check to fail. Zscaler v2.2.0 updates the APIs for all endpoints. See the connector documentation for details.The following table summarizes the changes since the last announcement. # Type Name 1 Connector Microsoft Sentinel v2.0.0 [Doc] 2 Connector Proofpoint Threat Response v1.0.1 [Doc] 3 Connector
I struggle to understand why this dataset query shows no result on my FortiAnalyzer instance:SELECT dstport, srcip, dstipFROM $logWHERE $filter AND ipstr(dstip) IN ('172.31.11.80', '172.31.11.83')GROUP BY srcip, dstip, dstportORDER BY dstport, srcipTo be sure, I am getting results if in the Log View I search for: dstip=172.31.11.80 or dstip=172.31.11.83Any hint?
In an Active-Active FGCP cluster, only the primary unit answers ARP requests using the HA virtual MAC address, while subordinate units retain their own physical/real MAC addresses.When the primary load-balances a session to a subordinate unit, could you confirm:Is the packet handed off to the subordinate over the same data/LAN interface (addressed to the subordinate's real MAC), or over the dedicated HA heartbeat link? Since the subordinate never responds to ARP requests, how does the upstream switch learn/populate its MAC table entry for the subordinate's physical MAC — is this purely through standard source-MAC learning when the subordinate transmits traffic (e.g., forwarding the processed packet to its next hop), or is there an additional FortiGate-specific mechanism (e.g., periodic announcement frames) to keep the switch's table populated? Does the subordinate's return/outbound traffic exit directly through its own interface to the destination, or does it always route back through
We currently have a FortiGate firewall running FortiOS version 7.2.11, and we are planning to upgrade the firmware to a recommended and supported version.Could you please share the recommended FortiOS version for our firewall model, along with the correct and supported upgrade path from FortiOS 7.2.11?
Hello Fortinet Community,We are currently experiencing an issue where users connecting through the FortiClient IPsec remote-access VPN do not receive their email OTP.Environment:FortiGate model: FortiGate 100F FortiOS version/build: v7.6.7 build3704 (Mature) VPN type: IPsec remote-access VPN Two-factor authentication: Email OTP Email service: fortinet-notifications.com Issue started: September 4–5, 2026 Impact: Multiple/all VPN usersThe VPN authentication process reaches the stage where the user is waiting for the email OTP, but no OTP email is received. This configuration was previously working normally.We enabled the following debug commands:diagnose debug resetdiagnose debug console timestamp enablediagnose debug application fnbamd -1diagnose debug application alertmail -1diagnose debug enableThe certificate authentication shown in the debug completes successfully with:Cert status: GOOD auth_cert_successHowever, we did not see an AuthCode being generated or an SMTP connection initia
Hi Team,I am facing an issue with my FortiGate VM running in my lab environment and would appreciate any guidance.Environment:FortiGate VM Image: FortiGate-VM64-KVM v6.2.3 EVE-NG installed on VMware Workstation License: Evaluation (Evolution) license installed via GUIIssue:The FortiGate VM was working normally before installing the evaluation license. After uploading and applying the license through the GUI, the VM initiated a reboot.Since then, the VM has been unable to boot successfully. Instead, it continuously crashes with a kernel panic (double fault) during startup and enters a reboot loop.Below is the console output:FortiGate-VM64-KVM #FortiGate-VM64-KVM # Requesting FortiCare Trial license, proxy:(null)The system is going down NOW !!Please stand by while rebooting the system.Restarting systemPANIC: double fault, error_code: 0x0Kernel panic - not syncing: Machine halted.CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P 4.19.13 #1Hardware name: Bochs Bochs, BIOS Boc
We host a Norwegian sports club website that FortiGuard classifies as Malicious Websites, High Risk, "strong confidence of malicious intent". We have submitted it three times through the Web Filter rating request form and each time received the same automated reply keeping the rating, with no evidence given. Hoping someone from FortiGuard Labs can take a look. Domains: kveldeil.no and www.kveldeil.no - both have identical rating history. Rating history, from your own Web Filter Lookup:07 Dec 2016 - added as Malicious Websites29 Mar 2017 - updated as Sports23 Jan 2019 - removed as Sports So the site was flagged in 2016, corrected to Sports in 2017, and in January 2019 the Sports rating was removed, which reverted it to the 2016 entry. There is no detection newer than December 2016 in the history. That suggests the current rating is inherited from old data rather than from anything recently observed. What the site is: Kvelde Idrettslag, an amateur sports club. It runs on our CMS platform
In DoS Policy » tcp_src_session option.if i set Threshold = 30Is it mean 30 session per 60 seconds ?
Hello, I am testing dynamic MAP-E connectivity on a FortiGate-100F running FortiOS 8.0.0 build 0167. The Internet service is So-net over the NTT East FLET'S network in Japan. The VNE service appears to be JPIX “v6 Plus.” DHCPv6-PD is working. The FortiGate receives a /56 delegated prefix and the WAN interface receives an IPv6 address derived from that prefix. The relevant WAN configuration is: config system interface edit "x1" set mode dhcp set role wan config ipv6 set ip6-mode delegated set dhcp6-prefix-delegation enable set ip6-delegated-prefix-iaid 1 set ip6-upstream-interface "x1" set ip6-subnet ::1/64 config dhcp6-iapd-list edit 1 set prefix-hint ::/56 next end end nextend After applying this configuration, the VNE diagnostic correctly recognizes the delegated prefix and WAN IPv6 address: end user ipv6 prefix: 240b:10:xx
Hey everyone, i'm sure the answer always depends but wondering who uses DARRP vs manual channel configuration. I've been using DARRP for a few years now and it works 'fine', but I have noticed sometimes it will over saturate a channel instead of using different ones. We typically reboot the AP and it will pick a different channel and things are fine. I've considered moving to a manual config. The only reason I don't is the obvious, it's manual and would love for DARRP to just work. For a scope we a few campuses and about 250APs.
https://fortiguard.fortinet.com/psirt/FG-IR-26-156FG-IR-26-156 (CVE-2026-70465) advisory states the fix is available in FortiClient Windows 7.4.4 / 7.2.12 and later. However, the free VPN-only agent has not received a new release since 7.4.3 (per the community note that v7.4.4–7.4.8 include no new free VPN-only build).Could you confirm: 1. Is FortiClient Free VPN-only 7.4.3 (build 4726) vulnerable to CVE-2026-70465? 2. If yes, will a patched free VPN-only build be released, or is upgrading to a licensed version the only path to remediation? Thanks in advance.
Hello,We are using the free FortiClient Windows VPN-only agent, version 7.4.3.Regarding Fortinet PSIRT advisory FG-IR-26-156 / CVE-2026-70465, the advisory lists FortiClient Windows 7.4.0 through 7.4.3 as affected and recommends upgrading to 7.4.4 or later. However, the FortiClient Windows release notes state that versions 7.4.4 through 7.4.7 do not include a new release of the free VPN-only agent, and that users can continue using the 7.4.3 free VPN-only agent. Could a Fortinet representative please clarify the following?Is the latest available free FortiClient Windows VPN-only 7.4.3 build affected by CVE-2026-70465? References:FG-IR-26-156: https://fortiguard.fortinet.com/psirt/FG-IR-26-156FortiClient 7.4.7 release notes: https://docs.fortinet.com/document/forticlient/7.4.7/windows-release-notes/683433/special-notices This is a request for clarification of the public PSIRT advisory’s impact and remediation path for the free VPN-only edition
I mean, they are easily powerful enough and fit out usecase. No technical problem at all but they were released in 2019 and go eol September 2031. It does not sound clever to me to lose more than half of its lifespan.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.