Mark a Best Answer
Fortinet Community
Recently active
Hi, would like to ask if the forticare license can be purchased regardless of fortigate version, if there is no some constraint while making the order in base of the device model/version? Many thanks
I have a Fortigate-400E and a 4G Router. About the 4G RouterThis router has an IP address of 192.168.x.x. To get internet access, all I have to do is plug in a LAN cable from the 4G Router to a PC. That simple. About the FortigateThis firewall has a 10.10.x.x IP address range. My QuestionHow do I set the 4G Router to the firewall? Right now I have plugged in a LAN cable from the 4G router to firewall physical interface 10. What configurations do I make? Do I change the role of the interface to LAN or WAN? What else needs to be done? Create a VLAN? Once this part is done, I can create a policy, that part I is not a problem. Could someone provide a step by step configuration guide? It is so simple without the firewall but I have no clue how to get it done thru the firewall.
We are attempting to run the following on my 70G but it is returning the following error. I was wondering if there is something we are doing incorrectly to try and enable the fips-cc mode. Any help would be greatly appreciated. FortiGate-70G # config system fips-cc FortiGate-70G (fips-cc) # showconfig system fips-ccendFortiGate-70G (fips-cc) # set status enablecommand parse error before 'status'Command fail. Return code -61FortiGate-70G (fips-cc) #
Hi,I have the first time the issue that the Fortigate is not Responding to snmp Request (tested v2 and v3)Monitoring worked for 2 weeks, since today the fortigate is ignoring the snmp,Ckecked that the Fortigate receive the snmp requests Interface has enabled snmp added also a local in policy to be sure that the monitoring server can reach the demon debug of snmpd show also snmpd: trap (1003) masked for “user” also debug flow shows - monitoring Server to Fortigate (correct ports) and iprope_in_check () check failed on policy 0, dropso i am sure that the config is correctHas someone also faced a similar issue?
Is there any temporary extension, grace period, or interim support option available for our FortiGate 100E while we are waiting for the FortiGate 120G delivery? Can Fortinet verify whether there is an active order for the FortiGate 120G through our vendor or distributor and provide an estimated delivery status? Is there a Trade-Up option available from our existing FortiGate 100E to the FortiGate 120G? If a Trade-Up is available, can any applicable services or remaining entitlements be transferred to the new device?
Hello, I need your consultation and help. I want to install FSSO AGENT on my AD server so that Fortigate can see users. There are several installation options for this program:FSSO_Setup_5.0.0289_x64.exeDCAgent_Setup_5.0.0289_x64.exeTSAgent_Setup_5.0.0289.exeCould you explain the differences between them and which one is best? Also, if successful, how can I use web filtering to prevent users from accessing specific websites?#FortiGate
New customer here. We are testing always-on IPSec VPN (split tunnel) on macOS 26 Tahoe.I have all the recommended MDM profile payloads deployed to my test Macs (SEXTs, TCC/PPPC, Notifications, Content Filters, Login Items, etc). But Im still seeing a couple issues, including these 2:1 How do I suppress this user-facing pop-up: "FortiTray" Would Like to Add VPN Configurations All network activity on this Mac may be filtered or monitored when using VPN.2 Once approved (which is required for some reason), a virtual ‘VPN’ interface is INSTANTLY created in macOS Network Settings. Yet this interface is literally unusable, and never becomes active. And users are able to remove it manually if they so desire (i.e. it’s not locked). If a user does NOT allow this VPN, this pop-up will appear persistently until action is taken.How can I remove this pop-up and related interface? I dont want end-users to see this in the UI since it isnt ‘real’ and will just lead to confusion and frustration.See (2)
Hello everyone,I need to configure a single PC to connect via SSL-VPN with MFA to my company's infrastructure, which is currently running on firmware version 7.0.Since I only need to manage 1 PC, I do not have an active FortiClient EMS contract to access the legacy downloads section in the Support Portal. I only need the free standalone VPN client (FortiClientVPNSetup_7.0.x).Could someone please provide an official or temporary download link for the FortiClient VPN version 7.0 installer for Windows 10, with 32 bits arquitecture? Thank you in advance for your help!
Hello,I wonder if the Extender standalone supports the feature “Routing Behind Mobile Station”, that is RADIUS attribute 22 / framed route in a company 5G mobile network.I could not find anything regarding this in the docs. If yes, anyone here used this feature already?best regards
Hi all... I was using FortiClient VPN on MacOS Sequoia and all was working fine, but after update for MacOS 26 Tahoe, I'm experiencing several issues on applications that not recognizes the VPN. For example, I have a Java development environment configured on my Mac, but after update, when I start a Spring Boot backend application, it does not can reach database on Azure. Same for older Java applications using Wildfly 17. Error massage points to my local IP, not for VPN IP. VPN is connected, routes appears as result for netstat command, but I can't connect do my databases because allways returns erros saying my local IP is not on firewall. Anyone has an idea to solve this? Regards,Bruno
Hi,I've already set up my FortiNAC scenario with FortiGate and FortiSwitch in the lab, where it worked. Now I'm doing the same in production, but it doesn't want to work no matter what I troubleshoot.I have access value VLAN 31 for my guest network, where I want all users that have MAB to fall into.I have correctly configured the RADIUS attributes, and the logical networks are mapped to VLAN IDs in FG Virtualized Devices > Model Configuration. My host in Policy Details matches the MAB policy, and the logs show that it is matched to go under VLAN 31.My FortiSwitch port has Group Membership Role Based Access and Reset Forced Registration. I've also tried adding Forced Registration/Forced Authentication, and it doesn't work. In my RADIUS logs, I don't know if it's bugged, but FortiNAC RADIUS keeps sending VLAN 1 even though it should match VLAN 31. Why is that happening? REST-HTTP-Status-Code = 204, REST-HTTP-Status-Code = 204, REST-HTTP-Status-Code = 200, Tunnel-Type = VLAN, Tunnel-
Hello everyone,Can anyone confirm whether FortiNAC-F fully supports (or has been successfully integrated) with the following:Aruba 1930 switches TP-Link TL-SG1016PE switches Sophos AP55C access points UniFi U6 Mesh Pro access pointsSpecifically, I’m interested in understanding:Level of support (CLI/SNMP/API… etc) Visibility and control capabilities (profiling, enforcement, VLAN assignment, etc.) Any known limitations or required workaroundsThanks in advance.
Hi everyone, I am trying to add a Fortigate VM eval, generated via the FortiCloud account to the FortiManager VM eval, also generated via the FortiCloud account. So, both units are "self-generated" evals. I am not talking about evals obtained through the local supplier. It is not working!!! From the debug output on FGM, it seems like the FG is not sending any certificate to the FGM while trying to setup communication via FGFM. This is a debug output from the FGM:2025-02-11 06:44:29 Use cert idx=0 by peer_ca = 1 2025-02-11 06:44:29 __info_callback,993: role=svr,state=23, TLSv1.3 SSLv3/TLS write certificate 2025-02-11 06:44:29 __info_callback,993: role=svr,state=40, TLSv1.3 TLSv1.3 write server certificate verify 2025-02-11 06:44:29 __info_callback,993: role=svr,state=36, TLSv1.3 SSLv3/TLS write finished 2025-02-11 06:44:29 __info_callback,993: role=svr,state=46, TLSv1.3 TLSv1.3 early data 2025-02-11 06:44:29 __info_callback,993: role=svr,state=46, TLSv1.3 TLSv1.3 early da
Using Automatic Patching for any vulnerabilities found but it never actually patches anything. Tried even from the actually desktop inside the forticlient to select the vulnerability and then "installed selected", it starts and scan and asks for a reboot but nothing changes/installs. Any help would be greatly appreciated FortiClient
We’ve setup Fortitoken for VPN users. The Ldap authentication suceeds and the fortitoken works when the user enters username as listed in useraccount section. However its failing when the user enters a mixed case username. I’ve read on previous bugs/issues that this is a bug. is this still the case in 7.4.12 (FGT90G) Local user : Testuser Testuser works, fortitoken mfa is presented and the vpn connects. testuser does not work, 2fa token window is presented but when you enter the token (EAPtoken error) is this bug still present in the new version? is the only way to make it work is by making sure users login correctly?
Good day Please assist , I have installed fortigate vm64 version 7.6.7, when trying to access the gui and logging in it says license is being validated I can ping google , dns working fine What could be the issue
Fortiwifi 30E is about to end of support, So can I continue without license. Is any issue will come.
Hi,I have device FG100E which will end of live on this August, but the firmware still old v6.0.2. From upgrade path i did not see currently firmware i used, it’s only show v6.0.18.The question, it’s safe upgrade direct to v.6.0.18 and then follow the upgrade path? Thank you and appreciate
Privileged Access Management keeps getting more demanding. Between hybrid cloud sprawl, contractor and vendor access, and regulatory pressure to prove least-privilege everywhere, PAM platforms have to do a lot more than just vault a password anymore. Fortinet's latest release,FortiPAM 1.9.0, reflects that shift — it's a substantial update that touches secret launching, Just-In-Time privilege, identity federation, network architecture, and hardware scale all at once.Here's a breakdown of what's actually new, and why it matters if you're running (or evaluating) FortiPAM.Secret Launch & Session ImprovementsThe bulk of this release is focused on how secrets get used — not just stored.TCP forwarding for native RDP. Native RDP launches can now route through TCP forwarding instead of the standard native path. This exists mainly to work around real-world friction: certificate revocation check failures, legacy/3rd-party RDP servers that only speak plain-text RDP, and RDP protocol changes th
UNAUTHORIZED Your account cannot be found. Your email address () is not associated with our Customer Service and Support site account. Make sure you use the correct email address or register your account on our Customer Service and Support website by clicking the "Create new customer account" button below. Code: A02E03-151 I want to learn, but my account doesn't exist, yet it lets me log in, and I can't even create another account.
Is anyone able to provide me with the firmware for a Fortinet 60F firewall?
Hello buddies,I’m new to the Fortinet community and would like to start learning how to properly configure and manage FortiGate.My goal is to set up a small hands-on lab where I can learn about firewall policies, VLANs, VPNs, web filtering, and basic network security without affecting the production environment.Could you recommend a learning path, course, documentation, or lab setup suitable for beginners? Would FortiGate-VM be suitable for this purpose? What networking knowledge should I have before getting started?Thanks for any guidance or recommendations here.
I hve a FortiGate 60F and when I console to it I have a message that Password reset functionality is disabled. WhenI try using maintenance mode or the hard reset button it does not working. What options do I have to get in this device? If I have to reset it fully I will as long as I can get into it.
Securing AI at Runtime: Closing the Gap Between AI Adoption and SecurityAI adoption is accelerating across the enterprise. Organizations are using private AI and large language models (LLMs) for software development, research, workflow automation, customer engagement, and other business-critical applications.But as AI moves from experimentation into production, security teams face a growing challenge: traditional security controls were not designed to understand how AI applications process prompts, data, and model responses. Organizations need a security approach that can protect AI workloads while allowing teams to continue adopting the technology at scale.AI Adoption Is Creating New Security RisksMany organizations begin with small AI pilots before expanding AI into critical workflows. As deployments grow, however, the security requirements become more complex. Security teams need to understand who is using AI, what information is being submitted, what the model can access, and what
Hey everybody I'm new . currently I'm working as a desktop engineer and I'm planning to start studying. In a fortigate firewall now can anyone tell me where to start this course any free resources youtube channel n all.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.