Mark a Best Answer
Fortinet Community
Recently active
I’ve been straining my brain for weeks on this. It seems like it should be so simple. Is anyone aware of any bugs with Remote IPSEC VPN and 8.0? I have followed this documentation but i’m obviously missing something. I’m attempting to use the Forticlient cert (i was doing my internal pki, but found to check EMS tags i needed to present the EMS cert) and i keep getting hung up here:[1742] fnbamd_auth_session_done-Session done, id=84988985766011[1209] __fnbamd_cert_auth_run-Exit, req_id=84988985766011[1785] create_auth_cert_session-fnbamd_cert_auth_init returns 0, id=84988985766011[1698] auth_cert_success-id=84988985766011[1321] fnbamd_cert_auth_copy_cert_status-req_id=84988985766011[1329] fnbamd_cert_auth_copy_cert_status-Matched peer user 'Remote-Employee_peer'[1458] fnbamd_cert_auth_copy_cert_status-Cert st 210, req_id=84988985766011[356] fnbamd_comm_send_result-Sending result 0 (nid 672) for req 84988985766011, len=2776[360] fnbamd_comm_send_result-Failed send reply (2788, errno 101)
Bonjour,Impossible de charger une licence d’essai dans GNS 3 au dessus de la version 7.0.12, apparemment Forti ne laisse plus faire.Est-ce que quelqu’un aurait cette image FGT_VM64_KVM-v7.0.12.M-build0523-FORTINET.out.kvm.qcow2 ou une version inférieure ?Merci de votre réponseMike.
HI FNAC adminsFortiNAC-F 7.2.9.I have this scenario:A new AD users (not added to FNAC yet) connects to SSID managed by FNAC from a client having NAC agent FNAC adds it automatically to user DB (created from RADIUS connection) , and it adds it not as “Loaded from Directory”, but just like local user, and remains the same even after AD sync As it didn’t add it as “Loaded from Directory” it doesn’t match my UHP neither my access policy, so it is dropped in isolation So I have to remove the user manually and let it created by LDAP automatically after sometimeMy question:Is there a way to force AD user override existing user created from RADIUS connection Otherwise is there a way just to preload all ad users to FNAC user DB even before any user connects Or any other flexible/automatic solution
Hi Team,We currently restrict our FortiGate SSL VPN access to users connecting from the UAE region using GeoIP restrictions.However, some vendors are based in Egypt and may RDP into their office PC located in the UAE, and then establish the FortiClient VPN connection from that UAE PC.Is there a way to configure FortiClient EMS to restrict VPN access based on the client’s public IP or location, so that if the actual client is connecting from outside the UAE, the VPN connection is denied?Any recommended configuration or best practice would be appreciated.
Hi Community,I’m experiencing performance issues with FortiAP FAP-231G and would appreciate some advice from anyone who has deployed this model in a high-density environment.When the AP has more than approximately 30 clients connected, especially during Microsoft Teams meetings, I experience the following: Some clients are unexpectedly disconnected from the FAP-231G. Clients are sometimes forced to roam/reconnect to a much farther AP, even though the FAP-231G appears to have good signal strength. The issue is more noticeable during Teams meetings and other traffic-intensive activities. With fewer clients, the AP appears to perform normally.I would like to understand whether this could be related to FAP-231G capacity, radio configuration, client load balancing, roaming thresholds, airtime utilization, or FortiAP/FortiGate configuration.My environment is using FortiGate-managed FortiAPs.Has anyone experienced similar behavior with the FAP-231G? If so:1. What is the recommended number of
Currently, the FortiGate 60F is experiencing an inconvenience when there is an electrical power outage and the equipment starts operating using the UPS.When the power change is produced, the FortiGate apparently falls down and stops allowing network traffic, both incoming and outgoing.The way it has been used to restore the service is to physically disconnect the FortiGate and reconnect it to electrical power. After carrying out this procedure, the equipment normally starts correctly and allows network traffic again.However, on one occasion the FortiGate did not start correctly even after disconnecting and connecting it again, which increases concern about the cause of the problem.
Hi, Has anyone had any luck getting FortiClient vpn working on Tahoe? so far iv had 0 success .All windows based clients work fine however
nslookup v4-aws.api.intuit.com 96.45.45.45Server: dns1.fortiguard.netAddress: 96.45.45.45*** dns1.fortiguard.net can't find v4-aws.api.intuit.com: Server failednslookup v4-aws.api.intuit.com 96.45.46.46Server: dns2.fortiguard.netAddress: 96.45.46.46*** dns2.fortiguard.net can't find v4-aws.api.intuit.com: Server failed
Hello everyone! Recently we upgraded our Fortigate (120G HA Active-Passive cluster) from 7.2.11 to 7.4.11, and different problems started to occur.Some users spontaneously lose access to the Internet with ERR_TUNNEL_CONNECTION_FAILED (we use explicit proxy with Kerberos authentication and deep ssl inspection). It happens at random times and with random users, lasts usually up to 2-3 minutes, then works as usual.FortiGates started to randomly reboot with the message "Fortigate had experienced an unexpected power off!", there's no CPU/RAM issue, usually mem is around 40%, and proc is around 10-12%. Due to fast HA failover users don't feel the interruption, but it's definitely not a good sign. Before the update both NGFW had worked for 367 days.Anyone experienced similar issues? Any workarounds? Or should I just be rolling back to 7.2.11?Any advice and help will be appreciated. Thank you in advance!
Hi everyone,I’m planning to migrate from SSL VPN to IPsec VPN. Here’s the situation:The FortiClient app is already installed on users’ devices, and I need a way to deploy the IPsec VPN profile to those devices via Intune (all devices are managed by Intune).I’m currently using the VPN-only version of FortiClient, and as far as I know, deploying VPN profiles centrally requires an EMS license.Could you please advise if there’s any alternative solution in this case?Thanks
i have newly created VIP rule to publish local microsoft dynamic test server to the internet to access anywhere, but the vip rule not hit any packets.attached the rule screenshot and policy, any help from the community team would be appreciated
I have a VIP IP address defined on my Fortigate Firewall, and I'm using Cloudflare with a proxy enabled. When I log the source on the firewall, I only see the Cloudflare IP address. Is it possible to see the incoming VIP traffic as if it were the real IP address?
Hi,I would like to know if anyone else is experiencing similar issues with FortiEndpoint EMS Cloud and the integrated FortiEDR feature.Our environment is currently running:FortiClient EMS Cloud: 7.4.7 build 2194 (Mature) FortiClient: 7.4.7 Windows 11 25H2: Build 26200.8875 FortiEDR Engine assigned by EMS: 5.2.8.0044Originally, we noticed that some endpoints using the same EMS policies and profiles had FortiEDR working and connected, while others showed FortiEDR Disabled in FortiClient and Disconnected in FortiEDR Cloud.Both working and affected endpoints are operating in the same environment and network, which makes the different behavior seem questionable. We are also seeing the same issue on endpoints in customer environments, so it does not appear to be limited to a single device or network.We also tested multiple FortiClient versions, including 7.4.4, 7.4.5, and 7.4.6, but the behavior remained the same.On affected endpoints, the Collector reported:FortiEDR Detected incompatible ma
We are currently evaluating our options and already have a quotation prepared for a licensed FortiClient solution, which is awaiting final approval and signature. Our organization has two FortiGate firewalls with active licenses and has been using FortiClient VPN Free Edition 7.4.3.4726 as our VPN client.Approximately 20 days ago, one of our security partners advised us to remove or upgrade FortiClient VPN 7.4.3 due to a reported vulnerability. As a result, we upgraded to FortiClient VPN 7.4.8. However, we later discovered that this version appears to require FortiClient EMS for ongoing management, leaving us uncertain about the most appropriate temporary solution.We have been unable to determine whether FortiClient VPN Free Edition 7.4.3.4726 remains secure for continued use. The software is still available for download, and discussions in community forums appear to reference different CVEs than the ones currently under review.As part of our evaluation process, we would like to unders
I am currently using MACOS Sonoma when I use FortiClient and connect to the client but I have no access to my internet. I even tried using the router to add a new wheel and nothing worked I can't ask the client to change their settings outside. I need a solution I saw a video on the internet saying that Sonoma has a VPN problem. Link youtube: watch?v=F60PBFlhjMQ&t=30s But is it really Sonoma?
So, MS Surfaces and Forticlient VPN have been one of my Nemesis' at a specific site for a specific user. Previously when we upgraded his Surface Pro a few years ago, when he'd connect via SSL VPN, internet connectivity would slow way down, at that time we were using the free Forticlient and got permission from Fortinet to get a trial version of the paid client to see if issue was FC related. After a lot of back and forth, the issue was resolved and I and the user was happy. I am going to review that ticket again and make sure there wasn't some kind of work around put in place that may be affecting this. Fast forward to the beginning of June, we replaced his Surface and used our typical tool (TransWiz) to transfer his existing Windows profile to new machine, he was happy. A few days later I get advised that when FortClient Free VPN is connected ALL internet traffic that's not across the link stops, example if I have a remote session with him I loose connectiv
I have a brand new out of the box Fortigate 90g. I’m setting it up, and I get to Network → DNS, and I enter Comcast’s DNS servers (Since it’s on a comcast line). The firewall immediately says the IPs are unreachable, however, I also told the device to run a dhcp server, and hand out comcast dns as the dns on the leases. The clients are fine, they can resolve addresses all day, no problem it’s something with the fortigate itself, it can’t “use” these addresses. It’s also saying it’s unable to connect to FortiGuard servers for support info.I tried doing the execute ping command from the cli, it dropped a few packets at first, then was 100%. Is there some filter or something I should turn off (web filter on the WAN interface, maybe? ) that’s causing this? the IP addresses I’m using are 75.75.75.75 and 75.75.76.76 thanks.
dear mam/sir, i need to upgrade the firmware of the fortinet this is my client’s fortinet to repair fortinet i want firmware of FWF40C3912006020 fortiwifi -40c thank you Tejesh Maharjan
Hello,We are moving store suites and AT&T is changing their IP address.So we need help updating the new IP address configurations.The move occurs this Saturday, 29th at 5 PM PST.Can we schedule a time to make changes?
We have a FortiGate-VM running on a trial/evaluation license that expired on July 2 (about 2 months ago). We're planning to deploy a new FortiGate-VM instance (same IPs) and push the existing configuration backup to it, then license the new instance properly.Is it possible to restore a config backup taken from an expired trial VM onto a newly deployed VM instance with a different serial number?
My FortiGate 100F, has been damaged by lightning. We have purchased a new FortiGate 100F. We want to transfer the license (2 years subscription) from the damaged FortiGate 100F to a new one FortiGate 100F. I wanted to transfer the license directly, but unfortunately I have already registered the new FortiGate 100F on my account, so I can't transfer the license.Can anyone help me?Many thanks.
My customers are can connect our VPN using their Windows PCs, Android Phones , MacOS PCs successfully. iPhone users also were could be connecting but for a while, I guess after latest update on App Store, they cannot connect to our VPN.We have a custom TOTP authentication server with Radius.All the other FortiClient VPN users on other devices still connecting , and also we have not changed anything in our Forti or Radius.Just Apple iPhone FortiClient VPN users cannot connecting.
Hi EMS adminsOn EMS 7.4.3 I was able to configure NTP via OS config files (chrony).But on 7.4.4 there is no access to sh/bash and I can't find anywhere some command to set it up with emscli.In emscli cmd ref I just found this command but nothing said about setting time server.https://docs.fortinet.com/document/forticlient/7.4.4/ems-cli-reference/239339/execute-timeAny useful info would e appreciated.
Hi everyone,I’m looking for some answers and a quick sanity check on my technical interpretation of the FortiGate 120G datasheet. I am currently evaluating this model against specific project requirements and need to be absolutely sure about how the performance metrics translate in a real-world scenario.Here are the requirements I'm looking at and my interpretation of the specs. Could you guys confirm if my line of thinking is technically sound?1. Requirement: SSL Inspection (DPI) throughput of at least 2.5 Gbps (HTTPS decrypted with IPS and AV enabled) My interpretation: The official FG-120G datasheet lists SSL Inspection Throughput at 3 Gbps and Threat Protection at 2.8 Gbps. According to Fortinet’s enterprise mix methodology, Threat Protection is measured with Firewall, IPS, Application Control, and Malware Protection (AV) simultaneously enabled. Given the cascaded processing architecture of the SPU (SP5 chip), my logic is that the resulting throughput for decrypted HTTPS traffic su
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.