Mark a Best Answer
Fortinet Community
Recently active
Hello,In our company we have an EMS instance currently deployed in Azure and we need to move it out to another cloud service. Due to the security requirements given to us, each EMS client must be authenticated with SAML to connect to EMS for management. In the past we have migrated EMS 7.2 to 7.4 Windows → Linux deployment and this caused all of our 2000+ connected users to be thrown out of EMS and needed to be onboarded again. Perhaps someone has already successfully tried EMS migration to another instance (keeping the same FQDN) with SAML authentication enforced? Looking for ways to execute a seamless migration so that endpoints would not need to be onboarded to EMS again. Note that our SAML authentication goes through FortiAuthenticator. Endpoints are ~99% on MacOS. Support has recommended restoring the database/configuration on the new instance but could not definitively say if SAML re-authentication would kick in.Thanks
Hi everyone,We are currently using ExtremeCloud IQ Connect Cloud to centrally manage our Access Points.Our current environment has the following characteristics:We are using ExtremeCloud IQ Connect Cloud for centralized AP management. The cloud platform centrally manages the Access Points. SSIDs and VLANs are configured and managed through the cloud platform. There is no on-premises Wireless Controller deployed in the environment. ExtremeCloud IQ Connect Cloud does not provide a dedicated Management IP that can be directly added to FortiNAC as a network device. We have tested adding an individual AP to FortiNAC using the AP's Management IP. FortiNAC was able to connect to the AP and retrieve information such as the SSID.We would like to clarify the following points:Can ExtremeCloud IQ Connect Cloud be directly integrated with FortiNAC, or is it necessary to add/manage each individual AP in FortiNAC? If individual APs need to be added to FortiNAC, can FortiNAC control client access base
I am using FortiNAC-CA / FortiNAC-OS v7.6.5.0815 (GA) together with a FortiGate and I would like to implement a daily Internet usage limit for self-registered guest users.My requirement is:Guest connects to the Guest Wi-Fi. Guest self-registers through the FortiNAC captive portal. After successful authentication, the guest receives Internet access. The guest is allowed a maximum of 1 hour of Internet access per day. After the 1 hour is consumed, Internet access should be blocked automatically. The guest should not be able to regain access by disconnecting/reconnecting or registering again. After the daily 24-hour reset, the same user/device should receive another 1 hour of access. Ideally, the limitation should be based on the user or device/MAC address, so creating another self-registration session does not bypass the limit.I understand that FortiNAC has Account Duration and Reauth Period, but from the documentation it appears that Account Duration is not a recurring daily quota. For
This update covers three connector releases. Microsoft Sentinel moves to a major version, Zscaler changes the APIs behind all its endpoints, and Proofpoint Threat Response picks up a fix. The table at the end links each release to its listing on the Content Hub, where you can review the full release notes.Microsoft Sentinel v2.0.0 introduces a Get Access Token configuration parameter, which supports Application Permission (Without a User), Delegated Permission (On Behalf of a User), and Certificate-Based Authentication. Proofpoint Threat Response v1.0.1 resolves an issue that caused the connector health check to fail. Zscaler v2.2.0 updates the APIs for all endpoints. See the connector documentation for details.The following table summarizes the changes since the last announcement. # Type Name 1 Connector Microsoft Sentinel v2.0.0 [Doc] 2 Connector Proofpoint Threat Response v1.0.1 [Doc] 3 Connector
I struggle to understand why this dataset query shows no result on my FortiAnalyzer instance:SELECT dstport, srcip, dstipFROM $logWHERE $filter AND ipstr(dstip) IN ('172.31.11.80', '172.31.11.83')GROUP BY srcip, dstip, dstportORDER BY dstport, srcipTo be sure, I am getting results if in the Log View I search for: dstip=172.31.11.80 or dstip=172.31.11.83Any hint?
Hi Team,I am facing an issue with my FortiGate VM running in my lab environment and would appreciate any guidance.Environment:FortiGate VM Image: FortiGate-VM64-KVM v6.2.3 EVE-NG installed on VMware Workstation License: Evaluation (Evolution) license installed via GUIIssue:The FortiGate VM was working normally before installing the evaluation license. After uploading and applying the license through the GUI, the VM initiated a reboot.Since then, the VM has been unable to boot successfully. Instead, it continuously crashes with a kernel panic (double fault) during startup and enters a reboot loop.Below is the console output:FortiGate-VM64-KVM #FortiGate-VM64-KVM # Requesting FortiCare Trial license, proxy:(null)The system is going down NOW !!Please stand by while rebooting the system.Restarting systemPANIC: double fault, error_code: 0x0Kernel panic - not syncing: Machine halted.CPU: 0 PID: 1 Comm: initXXXXXXXXXXX Tainted: P 4.19.13 #1Hardware name: Bochs Bochs, BIOS Boc
Hey everyone, i'm sure the answer always depends but wondering who uses DARRP vs manual channel configuration. I've been using DARRP for a few years now and it works 'fine', but I have noticed sometimes it will over saturate a channel instead of using different ones. We typically reboot the AP and it will pick a different channel and things are fine. I've considered moving to a manual config. The only reason I don't is the obvious, it's manual and would love for DARRP to just work. For a scope we a few campuses and about 250APs.
https://fortiguard.fortinet.com/psirt/FG-IR-26-156FG-IR-26-156 (CVE-2026-70465) advisory states the fix is available in FortiClient Windows 7.4.4 / 7.2.12 and later. However, the free VPN-only agent has not received a new release since 7.4.3 (per the community note that v7.4.4–7.4.8 include no new free VPN-only build).Could you confirm: 1. Is FortiClient Free VPN-only 7.4.3 (build 4726) vulnerable to CVE-2026-70465? 2. If yes, will a patched free VPN-only build be released, or is upgrading to a licensed version the only path to remediation? Thanks in advance.
Hello,We are using the free FortiClient Windows VPN-only agent, version 7.4.3.Regarding Fortinet PSIRT advisory FG-IR-26-156 / CVE-2026-70465, the advisory lists FortiClient Windows 7.4.0 through 7.4.3 as affected and recommends upgrading to 7.4.4 or later. However, the FortiClient Windows release notes state that versions 7.4.4 through 7.4.7 do not include a new release of the free VPN-only agent, and that users can continue using the 7.4.3 free VPN-only agent. Could a Fortinet representative please clarify the following?Is the latest available free FortiClient Windows VPN-only 7.4.3 build affected by CVE-2026-70465? References:FG-IR-26-156: https://fortiguard.fortinet.com/psirt/FG-IR-26-156FortiClient 7.4.7 release notes: https://docs.fortinet.com/document/forticlient/7.4.7/windows-release-notes/683433/special-notices This is a request for clarification of the public PSIRT advisory’s impact and remediation path for the free VPN-only edition
I mean, they are easily powerful enough and fit out usecase. No technical problem at all but they were released in 2019 and go eol September 2031. It does not sound clever to me to lose more than half of its lifespan.
We are testing FortiClient WebFilters and we are trying to test incognito mode extensions. It works on Windows browsers, but not macOS. Windows users get a pop-up asking to approve the new extension. (see example).None of my browsers have any FC extensions. Does this work on macOS?Bonus question: Can this pop-up be suppressed?
We received a notification last Friday regarding the need to upgrade our FortiEMS system. As per the schedule, we initiated the upgrade on Saturday at 1:00 AM.However, since Monday, we have been unable to access FortiEMS. The system continuously displays an "upgrade in progress" status, and refreshing the browser every 10 minutes has not resolved the issue.
We are a 100% cloud-based org using M365. We are 85% Windows and 15% Mac. We use FortiClient EMS Cloud to manage/publish ZTNA and VPN connection profiles to users. We have the FortiClient EMS configured with Domain Authentication and connected to our Entra ID tenant. The appropriate groups are assigned, and registration is seamless and it works. I fully understand that Mac OS is very different and does not support Entra ID authentication with EMS. The Fortinet EMS admin guide says, “FortiClient (macOS) does not support native Entra ID integration with EMS. For the integration to work, macOS endpoints must be managed by Intune or JAMF and enrolled to company portal using Entra ID.” Adding an Entra ID server | FortiClient 7.4.5 | Fortinet Document LibraryThat last sentence says it’s possible to use Entra ID integration for Macs. Our Mac machines are registered to Intune through JAMF PRO and enrolled to Company Portal. Domain Authentication will not work, and I know that. Which registrat
Hi everyone,We would like to ask for assistance regarding CVE-2024-21762 on a FortiGate FG-100F currently running FortiOS 7.2.8.Our customer is requesting us to remediate this security vulnerability.Could anyone please confirm whether FortiOS 7.2.8 has already addressed CVE-2024-21762?If not, what is the recommended action and remediation procedure to fix this vulnerability?This is an important security issue and needs to be addressed as soon as possible. Any official guidance or recommendations would be greatly appreciated.Thank you for your support.
SymptomsWe were configuring FortiClient EMS invitations using Domain/LDAP authentication.The environment appeared to be correctly configured:The Active Directory domain was successfully imported into EMS. Users were visible in EMS and could be selected when creating an individual invitation. No errors were reported in the AD Connector logs. EMS synchronization with AD appeared healthy.However, when users attempted to authenticate through the Domain/LDAP invitation workflow, they entered their AD credentials and the authentication window would remain in a continuous loading state indefinitely, without returning any error message. TroubleshootingInitially, no obvious issues were visible in the EMS GUI or AD Connector logs.To investigate further, we enabled Debug Log Mode on EMS and reproduced the issue.The debug logs revealed the following message:Authentication error: User not found in DBThis was unexpected because:The user existed in Active Directory. The user had already been imported
Hello, While I'm trying to install policy package to device, the copy of the package is working fine and then when it enters the state of "Install package to device from commit" the management tunnel goes down for some reason and I'm receiving the following error message "fgfm install run script error(st=2,logsz=150,errno=0 No response from remote" Updating the device, it goes online again but with a Config Status "Conflict" Any advise please?
Hello,I currently have SSL VPN active and I want to switch to IPsec VPN (IKEv2 Remote Access).Environment:FortiGate model: FG-101FFortiOS version: 7.4.11VPN type: IKEv2 IPsec Remote AccessAuthentication: FortiAuthenticator 6.5.6 build 1391 (GA) with OTPDirectory: LDAP users and groups from Active DirectoryClient: FortiClient 7.4.3 Hotfix 1 (7.4.3.8758)I am configuring an IKEv2 IPsec remote access VPN that authenticates users via FortiAuthenticator using LDAP credentials and OTP.The VPN connection is not successfully established from FortiClient.Phase 1 (SA_INIT) completes successfully, but the connection fails during user authentication (EAP phase).FortiClient shows the following error:Wrong EAP credentialsHas anyone encountered this issue when using IKEv2 with EAP authentication and FortiAuthenticator OTP?Any suggestions or troubleshooting steps would be appreciated.Thank you.
Hello everyone,I’m looking for the best way to review configurations and rules on FortiGate Firewall and FortiWeb. Are there any tools available for this, or benchmarks to follow?Any suggestions would be greatly appreciated!Thank you!
Our company is transitioning from SSL-VPN to ZTNA. We currently have Microsoft conditional acess policies allowing certain public IP addresses configured for SSL VPN allowing the public IP of the VPN firewall. Is there anyway for this to work with ZTNA? Currently, the microsoft logs are showing the public IP of individual users instead of the firewall.
I’ve been straining my brain for weeks on this. It seems like it should be so simple. Is anyone aware of any bugs with Remote IPSEC VPN and 8.0? I have followed this documentation but i’m obviously missing something. I’m attempting to use the Forticlient cert (i was doing my internal pki, but found to check EMS tags i needed to present the EMS cert) and i keep getting hung up here:[1742] fnbamd_auth_session_done-Session done, id=84988985766011[1209] __fnbamd_cert_auth_run-Exit, req_id=84988985766011[1785] create_auth_cert_session-fnbamd_cert_auth_init returns 0, id=84988985766011[1698] auth_cert_success-id=84988985766011[1321] fnbamd_cert_auth_copy_cert_status-req_id=84988985766011[1329] fnbamd_cert_auth_copy_cert_status-Matched peer user 'Remote-Employee_peer'[1458] fnbamd_cert_auth_copy_cert_status-Cert st 210, req_id=84988985766011[356] fnbamd_comm_send_result-Sending result 0 (nid 672) for req 84988985766011, len=2776[360] fnbamd_comm_send_result-Failed send reply (2788, errno 101)
Bonjour,Impossible de charger une licence d’essai dans GNS 3 au dessus de la version 7.0.12, apparemment Forti ne laisse plus faire.Est-ce que quelqu’un aurait cette image FGT_VM64_KVM-v7.0.12.M-build0523-FORTINET.out.kvm.qcow2 ou une version inférieure ?Merci de votre réponseMike.
HI FNAC adminsFortiNAC-F 7.2.9.I have this scenario:A new AD users (not added to FNAC yet) connects to SSID managed by FNAC from a client having NAC agent FNAC adds it automatically to user DB (created from RADIUS connection) , and it adds it not as “Loaded from Directory”, but just like local user, and remains the same even after AD sync As it didn’t add it as “Loaded from Directory” it doesn’t match my UHP neither my access policy, so it is dropped in isolation So I have to remove the user manually and let it created by LDAP automatically after sometimeMy question:Is there a way to force AD user override existing user created from RADIUS connection Otherwise is there a way just to preload all ad users to FNAC user DB even before any user connects Or any other flexible/automatic solution
Hi Team,We currently restrict our FortiGate SSL VPN access to users connecting from the UAE region using GeoIP restrictions.However, some vendors are based in Egypt and may RDP into their office PC located in the UAE, and then establish the FortiClient VPN connection from that UAE PC.Is there a way to configure FortiClient EMS to restrict VPN access based on the client’s public IP or location, so that if the actual client is connecting from outside the UAE, the VPN connection is denied?Any recommended configuration or best practice would be appreciated.
Hi Community,I’m experiencing performance issues with FortiAP FAP-231G and would appreciate some advice from anyone who has deployed this model in a high-density environment.When the AP has more than approximately 30 clients connected, especially during Microsoft Teams meetings, I experience the following: Some clients are unexpectedly disconnected from the FAP-231G. Clients are sometimes forced to roam/reconnect to a much farther AP, even though the FAP-231G appears to have good signal strength. The issue is more noticeable during Teams meetings and other traffic-intensive activities. With fewer clients, the AP appears to perform normally.I would like to understand whether this could be related to FAP-231G capacity, radio configuration, client load balancing, roaming thresholds, airtime utilization, or FortiAP/FortiGate configuration.My environment is using FortiGate-managed FortiAPs.Has anyone experienced similar behavior with the FAP-231G? If so:1. What is the recommended number of
Currently, the FortiGate 60F is experiencing an inconvenience when there is an electrical power outage and the equipment starts operating using the UPS.When the power change is produced, the FortiGate apparently falls down and stops allowing network traffic, both incoming and outgoing.The way it has been used to restore the service is to physically disconnect the FortiGate and reconnect it to electrical power. After carrying out this procedure, the equipment normally starts correctly and allows network traffic again.However, on one occasion the FortiGate did not start correctly even after disconnecting and connecting it again, which increases concern about the cause of the problem.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.