User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
I setup 1VM (FMG V8.0.0) and FW(V8.0.0) and trying to onboard fortigate firewall to manager but getting below error , is there any bug or do i need to make further changes in the configuration considering both VM Mgt subnet are in same subnet. Error “The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number.”
Hi, how do you set up a VXLAN when you have two locations? We're using FortiSwitches at both locations, and VLANs are also in use there.But we now have another location, and I'd like to know if it's possible to set up a VXLAN using the FortiLink VLAN as well?
Hi all,I am looking for FAZ resources which cover real world use cases or lab based scenario, I have checked on YouTube but not much available, checked their Fortinet Video Lib as well, I would appreciate you recommend some resources, thanksNote : I am focusing on FAZ, FSM
vpn ssl stop working but internet is reachable,my topology is a sdwan connection to internet from two wan sub interfaces joined as sdwan members into a sdwan-zone, we are using the fortigate lower models and firmware are 7.4.0 and 7.2.4, internet connection are asymmetric, home-residential massive internet. SLA health check is active but ramdonly after a couple of days internet connection is up but vpn ssl sub interface is down, no echo-ping goes back and sniffer also doesn´t show anything, only remote solution is to reset port and after that sub interface goes up again. Following current sdwan config edit 3 set interface "subinterface-primary-vpn" set zone "sdwan-to-remote-hub" next edit 4 set interface "subinterface-backup-vpn" set zone "sdwan-to-remote-hub" next... edit "vpn-health-check" set server <remote-looback-ip> set interval 1000 set failtime 10 set recoverytime 10 set source <local-lan-ip-all
I try to send CoA to the endpoint but we can see from below picture the CoA is failed, and from tcpdump there is no traffic to port 1700. Also in the cisco switch i already enable CoA debug but not receive any message. This mean the fortinac not send the CoA message?
Hi everyone,I have the topology below using Fortigate HA Active -Active Cluster Everything works normally until SW1 (the current STP root) is rebooted or powered off.After SW1 comes back (or after the topology reconverges), the topology does not recover correctly. One or more FortiSwitches may randomly become Offline, even though the physical links are up.The only workaround is to disable and enable FortiLink Split Interface, after which all FortiSwitches immediately come back online and the topology is rebuilt correctly.FortiOS 7.6.7 / FortiSwitchOS 8.0.0
We have 2 internet connections terminated to our firewall with spare IPs, and SD-WAN is already configured outbound for load-balance/failover.We have a specific outbound service (SMTP) that we want to attach to a dedicated outbound IP address.Setting an outbound NAT policy with an IP Pool was easy enough, and that's working, but we only have it setup for one of the internet connections at the moment.How can we set this up with a dedicated outbound IP for each internet connection and have it failover if the main internet connection goes offline? (active/passive)
Hi everyone,I'm trying to integrate FortiWLC 8.6-5 build-8 (FortiWLC-500D) with Aruba ClearPass Guest (ClearPass Policy Manager 6.12.7.308288 on C3010 platform) as an external captive portal.Current setupFortiWLC 8.6-5 build-8 External captive portal: Aruba ClearPass Guest Authentication type: RADIUS Captive Portal External Server Type: Fortinet-Presence External URL: https://<clearpass fqdn>/guest/guest_register_3.phpThe captive portal profile is configured as:Authentication Type: radiusCaptive Portal External Server Type: Fortinet-PresenceSuccess Redirect URL: https://<default redirect url>Login flowClient connects to SSID.FortiWLC redirects the client to the ClearPass Guest portal.The login page receives all FortiWLC parameters correctly, including:magicusermacuseripserveripapmacapidapnodeidssidpost=https://<controllerip>:8081/vpn/loginUser? User enters username/password.ClearPass successfully authenticates the user against the authentication source.After successf
Hello team, I have interesting situation. there are 4xFg900G in cluster. there is FTP server in vlan 100.L3 DG address for that vlan 100 is on Fortigate.When secondary 900G FGs from cluster want to reach ftp they can not.We also have cluster of 4xFG 400F for additional services, and they can all reach ftp server , no matter primary or one of 3 secondary FGs How to solve this situation?My final aim is to upgrade one of secondary FGs regarding MVC (Multi-version cluster) option, set upgrade-mode local-only, and upgrade one of secondaries and then reset ha uptime so that upgraded one become primary. Reason for that is because we must not have any downtime, and we want to take test after upgrade if all services are ok
Had multiple issues when adding a FortiGate using discover device. It always said device serial number does not match Only once I updated to 7.4.11 did it finally add First post here and its the end of my day so I’ll add more later, just don’t want someone to lose an entire day to this like I did.
hi,i’d like to setup a remote syslog server to collect NAT 5 tuple logs (source/dest IP, source/dest port and service/app).i have a multi VDOM FGT and would like to setup syslog server config in a non root/MGMT VDOM.my VDOM setup is i have an upstream ‘internet-gw’ VDOM and several downstream ‘nat-client’ VDOMs.goal is to setup syslog in ‘internet-gw’ VDOM and ‘nat-client-a’, ‘nat-client’b’ VDOM to send NAT log that’s filtered based on 5 tuple info.can someone advise on this? my google search only points to non VDOM FGT syslog and i already configured/enabled syslog in ‘global’ VDOM.
Hi Community, As per title “How to get Fortinet higher up to review related TAC Manager ticket”In ticket (11996986), we had factually proven the issue and the TAC Manager do acknowledge on it.Suddenly the TAC Manager (Jonathan) twist the fact on what discussed.Luckily we had video call recorded. How can we further submit to Fortinet higher up to review this TAC Manager whether these action is being approved? Thank You Best Regards,YK
After correct configuration ddns for DynDNS (not Forti-DDNS) is there any CLI-command to check the status for this service ? My firmware version = 5.0.1.
For FortiEdge Cloud, how do you assign different user accounts to have access to different networks?I believe this used to be accomplished using the Multi Tenancy license and sub accounts, correct?Since this can’t be ordered anymore and is going away, how do you do it using the new organization method?
Private by Design: Security That Comes to Your Data, Not the Other Way Around Most cloud security tools that inspect your workloads and your data have a dependency baked into their architecture: to analyze your information, they first make a copy of it in their cloud. Disk snapshots get exported to the vendor's account. Objects from your storage buckets are copied out and classified somewhere else. This works, but it means the most sensitive data you own now lives in two places instead of one, and the second place is outside your control.That tradeoff is exactly what FortiCNAPP was built to avoid. Two of our major product capabilities, Agentless Workload Scanning and Data Security Posture Management (DSPM), are Private by Design. The scanner comes to your data; your data never comes to the scanner. Analysis happens inside your own cloud account, and only the results ever leave. What "Private by Design" MeansPrivate by Design is a simple architectural commitment:Scanning runs inside you
Dear Community, We have this case where we want to configure two different IP Addresses as destination for our fortigate to be monitored as part of our link health monitoring. Our Cariteria is like this:First Destination is the next hop ISP IP AddressSecond Destination is our Server on the Internet Now we want the link to monitor both IP Addresses and if any of these two IP Addresses are not reachable then the link should be detected as down. Can anyone help me how to do this one.I have also read this on the internet can you all confirm if this is true?Someone suggested using the OR logic and configure two separate SDWAN performance SLA one for each Destination Server and if an interface participates in multiple Performance SLA (health-check) probes, it's only considered "up" if it passes ALL of them. So failing even one the interface marked down = SD-WAN swings traffic to the Backup. This is exactly the OR-failure logic you want. Best Regards,Shah.
Hello, Trying to understand what happened and how to prevent it in the future: - Running FortiGate-VM in an Azure VM.- This FG has a custom site-to-site IPSec tunnel to on-prem. This effectively connects the virtual data centre to the on-premises data centre. Tunnel is initiated from Azure.- Suddenly, the tunnel no longer works. Phase 2 will not go up.- The first sign of trouble is this: Unavailable : Live Migration (Unplanned)At Thursday, October 13, 2022 at 7:29:19 PM EDT, the Azure monitoring system received the following information regarding your Virtual machine:This virtual machine was paused for 0.675000 seconds due to a memory-preserving Live Migration operation. No additional action is required from you at this time. Recommended StepsNo action is required - A couple of minutes after this, alerts start going off that connectivity has been lost.- After some trouble shooting, pinging, checking routes, connectivity, rebooting, firmware upgrade,
Hello, installation of FortiClient VPN ends in an error "FortiClient VPN Wizard ended prematurely because of an error." I am running Windows 11 home on my new surface 11 pro. I executed Installation .exe as Administrator, i disabled Windows Defender temporarily. Any further ideas?
EnvironmentPlatform: FortiGate (hardware appliance)HA mode: Active / PassiveFortiOS current version: 7.4.8Target version: 7.4.10HA priorities:Unit A (Master): priority 200Unit B (Slave): priority 100Expected upgrade behavior (normal case)Based on Fortinet documentation and past experience, the expected HA upgrade sequence is:Firmware upgrade starts on the slave unit (B).Slave reboots and temporarily disconnects from HA.Cluster fails over to the upgraded slave.Firmware upgrade is then applied to the former master (A) in background.Final failback occurs according to HA priority (unit A becomes master again).Observed behavior / Issue descriptionDuring the upgrade from 7.4.8 to 7.4.10 (firmware uploaded via GUI using .out file downloaded from fortinet official source):The upgrade process took more than 20 minutes, significantly longer than usual.HA became disconnected, and unit B (slave) was no longer visible from the cluster GUI.Accessing unit B directly via Console & Management
I have many event like below picture, can we troubleshoot from where the mac address is come? On my L3 switch i can’t see this mac.
Hi Fortinet Support,We're looking for guidance on deploying and configuring the FortiClient VPN application on Apple iOS devices managed through SOTI MobiControl.Our Android devices are working as expected, where the VPN configuration and authentication are deployed through SOTI. However, the process appears to differ on iOS, and we're looking for the recommended approach.Specifically, we'd like to know:Whether the FortiClient VPN configuration can be deployed automatically through SOTI MDM on iOS. Whether VPN profiles and authentication settings can be pre-configured using Managed App Configuration or another supported method. If there are any limitations on iOS compared with Android regarding deployment or user interaction. Whether there is any official Fortinet documentation or best practice guidance for deploying FortiClient VPN on iOS using SOTI MobiControl.Our environment:MDM: SOTI MobiControl Devices: Apple iPhone and iPad (iOS/iPadOS) VPN Client: FortiClient Android deployment
It seems IPSEC MFA via FortiToken requires FortiClient 7.4.4 when using LDAP, so no free FortiClient version then.Are there any other options for MFA with FortiClient VPN Only 7.4.3? Does it still work with SAML, or Radius via Windows NPS perhaps?
How to generate a FortiAnalyzer report to get ISP uptimes?
Hi FAZ、FMG created same ADOM name for manage FAZfollow this guidehttps://docs.fortinet.com/document/fortimanager/7.4.0/examples/289359/adding-fortianalyzer-to-fortimanager at FAZ, ADOM name ”ADOM_v74” have one device at FMG, have same ADOM name”ADOM_v74”, and same devicebut in this ADOM, the left sidebar doesn't even have a Log View or FortiView to check traffic or other logs.only “FAZ” ADOM have Log View and Forti View
Hi everyone, I have this issue with a FortiManager I have deployed in Eve-NG. It’s just used for labbing and playing around with config etc, so its intended to be very simple at the moment.It’s a brand new deployment and licensed using the free license with FortiCloud. Yesterday I was able to log into the manager with no problem, worked fine and then I started experiencing the issue with logging in and getting the ‘Rejected’ message. I have done the basic config such as routing and admin access.The same creds work via the CLI. It is a local account, with no trusted hosts or 2FA.My next thoughts are to just wipe the config and redo the deployment as there is nothing of value on it at the moment and it is probably just easier, but thought it would be worth asking and getting this on the community incase anyone else has the issue.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.