User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
We encountered some issues accessing some URLs after upgrading from 7.2.12M to 7.4.12M using FGT401E on HA.applications like MS Teams get disconnected suddenly and users reported that access to some external portal become very laggy.upon checking the traffic log, we noticed that the Application name was classify as 2x which is a service group in our firewall.under this group, there is HTTP, HTTPs, TDP, 2X publishing agent port and 2X terminal server agent port.due to the many issues encountered, we have rollback to 7.2.12M
We have identified duplicate endpoint entries in our EMS console and, to manage them, we created two separate groups: one group in Domain and another group in Workgroup.We are able to delete the endpoints that are listed under the Workgroup group without any issues. However, for the endpoints that are present in the Domain group, we do not see an option to delete them. Additionally, we are unable to move these endpoints from the Domain group to the Workgroup group.Could you please let us know:Is there a way to delete the endpoints that are currently listed under the Domain group in the EMS console? What is the recommended process for moving endpoints from the Domain group to the Workgroup group?Any guidance or best practices to resolve these duplicate entries would be greatly appreciated.Thank you.
When i have a new ipphone connected to the network then fnac will move this ipphone to registration vlan before device profiling is running. After device profilling run then i can see the ipphone move to host role ‘IP Phone’ and registered’But after the devices was profiled then how the vlan can be changed automatically to voice vlan? The only way the ip phone get the voice vlan after the ip phone registered by profiling is reboot the ip phone.
Hi everyone,I am attempting to set up a new IPsec VPN connection using the standalone FortiClient VPN only v7.2.1.0779 app, but several configuration options appear to be missing from the user interface: Missing Single Sign-On (SSO): When creating an IPsec VPN profile, there is no option or toggle for Single Sign-On (SSO / SAML) anywhere in the GUI. Missing Mode Config Parameters: Under Address Assignment, selecting Mode Config does not reveal options for Encapsulation, IKE UDP port, or IKE TCP port. Any insights or guidance would be greatly appreciated. Thanks!Missing option in my appSSO setting i expectedMode configuration setting i expected
My Fnac license 106 is in use, how we can know detail which endpoint is consume the license?
hello everyone,i am setting up a home lab and recently acquired a fortigate 60d rugged.i tried to reset it using coolterm on my mac and after the proccess it just got stuck on system halted, now its “bricked”i am trying to find a way to get it back up and running and i am fully aware that this product is an end of life model. tried also customer service and dident help. any help will be great!
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
Hi, we were an on-prem only company. Earlier this year we went hybrid with 365.For VPN earlier we had our clients connecting through forticlient with AD credentials leveraging RADIUS. No MFA.We then configured a parallel setup using IPSec ike v2 and authentication with EntraID, adding the MFA feature then.My question is: is this the natural approach that most of the former on-premise companies adopt once moved to Cloud or are there other suggested setups, maybe leveraging already existent on-premise RADIUS infrastructure?
We can select 802.1x authentication set to user or computer if we use wired. How about for wifi? There is no option to select that option on the wireless card properties.
Hello Community,We are currently encountering a known limitation with the standalone (unlicensed) FortiClient app on Android. When attempting to connect to an IPsec IKEv2 VPN using a Pre-Shared Key (PSK) alongside EAP user authentication, the client fails to render the username and password prompt during the connection sequence.This behavior aligns with the issue documented in the following Fortinet Knowledge Base article:Troubleshooting Tip: FortiClient VPN without license on Android has missing username and password promptDeploying FortiClient EMS or reverting to deprecated IKEv1 for a single mobile endpoint is not feasible for our environment. As a result, we are looking for advice on the following: Alternative Client Apps: Are there recommended third-party IPsec IKEv2 clients for Android (e.g., strongSwan, native Android VPN setup) that can successfully handle PSK + EAP/XAuth user authentication against a FortiGate without modifying the core gateway configuration? Configuration W
This week's updates center on new solution pack content in FortiSOAR™, extending automation into network operations and virtualization management alongside a set of new and updated connectors.Three new solution packs arrive this week. NetOps - FortiManager ZTP v1.0.0 brings zero-touch provisioning workflows into network operations scenarios, while VM Lifecycle Management v1.0.0, paired with the new Proxmox VE Hypervisor connector, establishes automation coverage for virtual machine provisioning and lifecycle tasks. A further remedial pack, Outbreak Response - WP2Shell RCE v1.0.0, extends the Outbreak Response framework to help teams counter this vulnerability.On the connector side, Fortinet FortiSIEM v6.2.0 continues the refinement of Fabric integration for security monitoring workflows. Two additional integrations join the ecosystem, Forcepoint NGFW SMC for firewall management and the Ping connector for network reachability checks within playbooks. Updates across mobility management,
I have DPR to set host role new ip phone to role IPPHONE then after the device profiled why the vlan is not changed? The ipphone still sit on isolated network except i replug the phone. Isn't when the host role changed then the policy will be evaluated automatically?
Hi everyone,I'm currently setting up FortiXDR and I'm a bit confused about the required FortiAnalyzer configuration.Our environment consists of:FortiClient EMS Cloud FortiXDR license Local FortiAnalyzer VM (no FortiAnalyzer Cloud license)We do not have a FortiAnalyzer Cloud license, only a local FortiAnalyzer VM.My question is:For FortiXDR, where should the FortiClient logs (configured in the System Settings Profile) be sent?Should the FortiClients send their logs to a FortiAnalyzer Cloud instance, even though we don't have a FortiAnalyzer Cloud license? Or is it supported to send the logs directly to our local FortiAnalyzer VM while still using FortiXDR?Most of the users work from home, so we are currently using a DNAT with TLS configuration.Has anyone successfully deployed FortiXDR with EMS Cloud + local FortiAnalyzer?Kind regards,MG4
can we get a proper captive portal instead of showing the default page.https://<controller-ip>/vpn/auth_web_ok.htmlwe tried changing the auth_web_ok.html inside custom captive portal under maintenance. but still its loading the default fortinet page as shown below.
If we use computer authentication then can service connector get record grom device group? I want to make dynamic vlan assigment based on entra id with computer authentication.
Hi Everyone,We have a fortigate firewall with HA and FortiOS is 7.4. also laid few client based FortiGate SSL-VPNs accounts.Now we have to upgrade either 7.6 or 8.0, where as not support the client based FortiGate SSL-VPNs accounts. So, what is the best practice for moving to 7.6 or 8.0 version?.Before upgradation can we use any migration tool only for SSL-VPN accounts to IPsec or any other?.MY SSL-VPN purpose is providing the RDP access & Web based internal urls. Anyone guide me for best practice for without any production impact?.Thanks in advance.
Our internal tools use FMG API to manage it and we were looking to create a Threat Weight Template using API.I have checked:https://fndn.fortinet.net/index.php?/documents/file/521-fortimanager-76-json-api-full-reference/https://how-to-fortimanager-api.readthedocs.io But did not find the API endpoints.If someone has done it before or has any API collection they can share ?
When we use DHCP fingerprint for device profiling then we need to add ip helper on L3 interface. How if the L3 using fortigate, there is no ip helper command?
Can anyone help me with the issue where LAN failover is not occurring between the FortiGate HA pair and the Cisco VSS switches?[ Cisco VSS Logical Switch ](Switch 01 + Switch 02)/ \[Po101] [Po101]/ \ / \(Eth1/3) (Eth2/3) (Eth1/4) (Eth2/4)| | | |[ x1 ] [ x2 ] [ x1 ] [ x2 ][FortiGate-01] [FortiGate-02](ACTIVE) (PASSIVE)| |TRAFFIC <----------- NO TRAFFICThe Cisco switch is configured with an EtherChannel (Port‑Channel 101) that bundles four interfaces—Eth1/3, Eth2/3, Eth1/4, and Eth2/4—operating in active mode, as shown in the diagram.The FortiGate firewalls are deployed as an HA pair, with ports X1 and X2 connected to the Cisco VSS switches. Port X5 is connected to the Internet link (Cisco Wan Router) and is also configured as an HA‑monitored interface.Additionally, the X5 port is part of the WAN_Aggregate interface, which is assigned to VLAN 50. VLAN 50 serves as the Internet_VLAN SVI, and the default gateway for the Internet_VLAN resides on the Cisco router.When the X5 interfa
Hi everyone,I operate a small autonomous system. There is not much throughput, maybe 200Mbit/s peak.I'm wondering if a 80E has enough RAM for peering at 2 IXPs+receiving a full table from a transit provider.Anyone with experience in that regard?
Hello, apologies if this has been posted before, but I could not find anything in the forums.We are a K-12 that recently switched to a FortiStack (Gate (100F), switches (148FPOE), WAPs (231G and K series). We are coming from Cisco Meraki and missing a big feature (or cannot find said feature) that I’m hoping to duplicate with FAZ. Being K-12, we have students lose devices on campus. We were able to log into the Meraki portal., look up a device hostname/mac and see what access point that endpoint last connected to. This helped students track their lost device.I cannot find anything simliar in the FortiWorld. I've piecemealed a dataset in FAZ from the Gate Event logs that gives me the client mac, last connected AP, and the last_seen time. I’ve parsed that along with a query based off Gate > Application Control > aware-New-Endpoint-Devices dataset. It looks like it would be what I need but I think the last_seen time is when it was FIRST connected to a particular access point. I real
Hello, My ISP delegates an IPv6 prefix but, unfortunately, it's dynamic and changes weekly. It works though and two LAN interfaces successfully have prefixes. Great!I would now like to add a ULA to an interface but cannot see a way to add a second IPv6 address if the interface is set dynamically. For testing (please excuse the short ULA), I switched from the interface itself having a prefix delegated to having a ULA: config ipv6 set ip6-address fdfc:c::40/64 set ip6-allowaccess ping https set ip6-send-adv enable set ip6-other-flag enable config ip6-prefix-list edit fdfc:c::/64 next end config ip6-delegated-prefix-list edit 1 set upstream-interface "wan1" set delegated-prefix-iaid 1 set subnet 0:0:0:1::/64 set rdnss-service default next end end I have (accidentally) stumbled upon a solution. It seems to work but is this actually valid configuration?Many thanks for reading
Just ran into this issue and I cannot find the reason: I connect a dialup ipsec vpn using FortiClient VPN successfully.I then have internet via the vpn (no split tunneling enabled).Which is wanted behaviour.Now I tried to download a zip file from github.com and I got blocked.The Firewall Policy that allows internet from out of this VPN does have UTM Filters on but none is set to block .zip.In FortiAnalyzer I see my traffic but I see no UTM block here. The session details in FAZ only show 2-3 security event that are all of type “pass”. This is because APP Control is set to monitore quite a lot here.So no block here but in Chrome via that VPN I still do get some Fortinet blocking page saying this is blocket because of the filetye. I have no clue what causes this. Do you have any thints or tipps on this?
Hello,I would like to share some information I found: FortiMail VM no longer has a memory limitation. I tested versions 7.4.2 and 7.6.5 in the lab, and neither has the memory limitation (this likely applies to other earlier versions as well). This can be confirmed using the `get system status` command:FortiMail VM01 with more than 4GB RAMRegards,Vitor Luz
I am having an issue with the FortiClient IPsec IKEv2 VPN connection on Android. I entered all the required information correctly and tried many configuration changes, but the issue still persists. When I attempt to connect, I receive a “Null” error message.At the same time, I tested the same VPN configuration on my iPhone, and the connection works perfectly without any issues. Iphone Settings Android Phase2 Settings Andorid VPN Settings
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.