Your feedback drives change, make your voice count
Fortinet Community
Recently active
Hi, I have FortiGate-VM64 v7.6.7 running on VMware Workstation. When I access the GUI the page loads (no timeout) but it's completely white/blank.In Chrome DevTools Console I see:401 Unauthorized on all /api/v2/ calls Events websocket closed unexpectedly Reconnecting attemptsCLI works perfectly fine, I can login and configure via console. The interface has allowaccess http https ssh ping configured on the management port.VM has no active license (eval). Could this be causing the blank GUI?Anyone seen this before?
Ho we can make endpoint enter to isolation network if the persistent agent have fail result? And how often the persistent agent will doing the compliance scan?
So we recently migrated our SSLVPN users to IPSEC IKEv2 over TCP443, and so far no major issues, been quiet, outside of some small issues that we have been resolving pretty quick.Except a weird one popped up today that was being that I’m drawing blanks on. I had about 230+ users logged in, no problem, then all of a sudden when a user was trying to login for the first time or reconnect, any user who was trying to connect if they were handed the 172.26.2.180 IP, they would connect and then within seconds the Fortigate would delete the tunnel, and I don’t know why. If two people were connecting at the same time, one person would connect because they got a different IP, but the other user would have their tunnel deleted because they got the 172.26.2.180 IP. Makes no sense to me.Ran debugs for multiple users and you could see phase1 came up, phase 2 came up, and then within seconds the Fortigate would delete it only when it has that specific IP. Other IPs in that subnet no problem, no issue
Currently we have one main Internet line hosting many IPSec tunnel to AWS and other cloud providers.We plan to make use of the 2nd Internet line to create redundant IPSec tunnel to AWS.Will the traffic automatically swing over to the 2nd Internet line if the main line goes down or under maintenance ?
Hi Everyone, I have been having issues with IOT devices maintaining their registration with Apple HomeKit.Problem:I have several Smart Bulbs, thermostats, and TVs which I have registered with Apple HomeKit. I was initially able to get all the devices working where I was able to control them. After the Fortigate reboots, most of the time only 1 or maybe 2 devices will work after a reboot. It’s 8 IOT devices in all.Topology & Configuration:I have a 70G, 110G, FAP231F, and two FAP23JK. The AppleTV that acts as the Hub is on the same SSID as the IOT devices. The SSID is also configured in tunnel mode.Troubleshooting:I have disabled any kind of suppression functions for the SSID, I have a multicast rule allowing mDNS even though the devices are on the same SSID. I have Multicast Enhancement enabled. I have removed the devices and attempt to re-register them. I have enabled IPv6 using non-routable range. I don’t have any features enabled that would interrupt the _tcp.local DNS lookups fo
Hi. I am new to FortiClient EMS (and its Rest API).It looks like the Rest API could let us get a list of vulnerabilites for each endpoints.I have created my “EMS API Access” key but can’t seem to find a way to use it. Not even able to login!Does anyone have a PowerShell sample to get me started?
Hi All, I have the following situation: I configured a guest SSID with Disclaimer Only authentication. I would like to configure the session timeout to 3 hour, and the renewal frequency to 1 hour (after the session time out, the user can not authenticate to the ssid until 1 hour). Is it possible to configure that?I tried to configure this field from FortiManager: captive-portal-auth-timeoutBut it looks like this field doesn't exists on our Fortigate. Environment: Fortigate40F with FortiOs 7.2.2Fortimanager 7.2.1 OSFortiAP 231F 7.2.1 OS Thank you! Best Regards,Istvan
Hello everyone,I would like to request your support in understanding how to proceed with the following situation. I recently took a Fortinet certification exam through Pearson VUE in the online proctored modality. However, when checking the exam status, it appears as “Voided.”So far, I have not received any email from Pearson VUE or Fortinet explaining the reason for this cancellation, so I am unsure of the cause or the next steps to take.Could someone please guide me on how to proceed in cases like this?
Hi FNAC adminsFortiNAC-F 7.2.9.Do you know a way to show/set device model configuration in CLI or via Linux shell (enter-shell).
Can we put the url to download the persisten agent on captive portal than the agent downloaded automatically?
now i want to identify the printers with its specific mac addresses in Fortinac and if there is another mac address unless i identify put it in quarantine vlan.how can i achieve that?
Hello all,we have an Exchange Hybrid setup with all our mailboxes on-prem. We need to let graph send emails via Exchange Online but we would need to relay these emails via our Fortimail appliance. So the Exchange Online environment does not send these itself without going through the Fortimail first. We found this in the cookbook:How to integrate FortiMail into Microsoft 365 | FortiMail Appliance and VM 7.4.0 | Fortinet Document LibraryAnd this technical guideline:Technical Tip: Office365 Secure Relay via FortiMail to avoid unauthorized email relay | CommunityAnd it seems like we can’t let graph talk directly to our on-prem Exchange servers:https://learn.microsoft.com/en-us/graph/hybrid-rest-support So we wondered how does the Technical Tip from fortinet make sure that we are not risking the relaying of unwanted emails. The authenticated part in the technical guideline does not apply here, no? Because our user mailboxes are all on-prem? And regarding the cookbook: our concern is that w
Hi all, I'm rather new to FortiMail and Fortinet products. Trying to configure same wildcard cert (e.g. *.domain.com) for both Exchange and FortiMail, using an internal Windows CA. The topology of email is like: exch.domain.com > fml.domain.com > outside While HTTPS connection is cool, FortiMail keeps complaining "unsupported certificate purpose" when it receives email from the internal Exchange server (FML acts as a server in this case in terms of TLS connection). But when outside sends email into domain.com, FortiMail happily forwards it to Exchange server (FML acts as a client in this case) How do I start troubleshoot this case? If I were to use Secure TLS Profile to enforce, outbound mails would be rejected. Thanks in advance.
Hi everyone,We are facing an issue where FortiGate email notifications are not being received by Outlook.com email accounts (Outlook, Hotmail, Live).Our SMTP configuration is working correctly because all email notifications, including SSL VPN OTP emails and other system notifications, are successfully delivered to our company email accounts.However, when the recipient is an Outlook.com email address, the emails are never received, including the Junk/Spam folder.Has anyone experienced this issue? Is there any known compatibility issue, Microsoft filtering policy, or SMTP configuration that could cause Outlook.com to reject or silently drop emails sent by the FortiGate?Any guidance or troubleshooting suggestions would be greatly appreciated.FortiGate Model: 1101EFortiOS Version: v7.4.11 build2878 (Mature)
Can we hide the captive portal address bar when the endpoint connect to isolation network on fortinac? I dont want user knowing the url of captive portal.
Hello FortiGate Community,Does FortiGate Natively Support mTLS/SPIFFE?If SPIFFE has to be integrated with FortiGate, what is the recommended approach? if you have any integration guides, please provide.I couldn't find any public information regarding this integration.Thank you in advance.
Na
I’m trying to setup LACP between Fortigate HA Active-Active cluster and another device (switch or another fortigate). On Fortigate HA, only one link to the primary is active and passing traffic. There is documentation for HA Active-Passive to prevent sending traffic to the slave(“set lacp-ha-secondary enable” ). Is there any m-lag configuration option on Fortigate HA ?. Thanks,
Hi,I wanted to update a Fortigate 50G from v7.6.6 to 7.6.7 via GUI but the button is grayed out. I read some articles that it could be about scheduled fabric updates. But I am unable to cancel it. Why does that happen? Why is a simple update so complicated now? FG is licensed and registrered.
we have FortiGate 91G firmware version is 7.4.12, SSL-VPN is not in GUI and also in feature visibility since it supports SSL-VPN how can be active to see in GUI?
Dear community, I need you support on the following itemsI have been asked to configure link health monitoring for our networks, now I have already setup the Performance SLA using ICMP Ping to check if the link is up and/or down. this will check if the link is up alright, now if the link goes down then using the SD-WAN rules the connection should swing the other ISP link and avoid any distruptions that might happen or it should not require manual switch.Now first question is here that what do you suggesst be the minimum link status to avoid any kind of routing issues later Now the second issue is that when configure SD-WAN rules which interface selection strategy should I use because when I read through the docs they mentioned to use the Manual but it does not allow for selecting any SLA rules you have configured, now out of the Best Quality and Lowest cost which one should I use?Can you please advise on this as well. I am looking forward to hearing from you. Best Regards,Shah.
Forti voice is 7.4.1 Is there a way to mass or change the 4 digit caller ID when doing local calls to other 4 digit extensions?i.e. I have 2 front Desk Phones both have Primary Extension (Main Phone and Aux Phone) 1234 and then have the Departments line 4444 has a SLA.When they call from these phones to just a 4 digit internal extension Caller ID shows ‘Desk Phone 1234’, I would like to hide the 1234 and just have Desk Phone show up, since everyone knows to just call 4444 locally to get to the front desk. Having 1234 show up can be confusing. I cant make the 2 desk phones just 4444 because placing calls on hold doesn't show up on AUX phones or any other phones that might also have that SLA mapped. We also plan to always have call forwarding enabled on 1234 to 4444, but I still would like to completely hide the number if possible.
Dear Security Team,We respectfully request that you review our domain and remove it from your blacklist if appropriate.We have completed a comprehensive security audit of our website and have fully resolved all previously identified security issues. All malware, malicious files, and any potentially harmful content have been completely removed.In addition, our website has been scanned by multiple trusted security services, all of which confirm that the site is clean and free of malware, phishing, and other malicious activity. Google Safe Browsing also reports our domain as safe and does not detect any security threats.We kindly ask you to re-evaluate our domain based on its current clean status and update its reputation accordingly.Thank you for your time, consideration, and assistance. We appreciate your review and look forward to your response.Best regards,Website Administratorhttps://dorottyanadorfi.com/ https://lantosfestes.com/ https://dirdurr.eu/ https://balanceyourlife.hu/ ht
I have a bridged AP that is tied to the DATA interface that cannot get to the Internet. The DATA interface works for the ports on the switch with no problem.
Does Fortitoken MFA support the server that running on Windows server 2012?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.