Mark a Best Answer
Fortinet Community
Recently active
HiCould you help me solve this problem, the following image appears when I want to make a VPN-SSL connection through forticlient on a MacOS computer, from what I see it may be issues of permissions to a process, but if someone can help me explain more in depth why the problem occurs, I would appreciate it Reggard
I’m currently considering transitioning our firewall and VPN solution to Fortigate. I’ve used Fortigate VPN in the past and found it to be reliable. However, a colleague recently mentioned that the VPN client may not perform as well on macOS and Linux systems compared to Windows.I’d appreciate hearing about your experiences with Fortigate VPN, particularly on macOS:How stable is the client on MacOS?Have you encountered any compatibility or performance issues?What has your experience been like managing the client on both Windows and macOS systems?Any additional feedback or insights would be greatly appreciated.
The problem on the macbook on the M1 Mac OS. During the connection, a message that Forti asks for access to the Key of the System and so, cut it up to the MFA and three times after, terribly annoying the same password 6 times. Tell me how to fix it?
In my case, I installed the application on a separate server. Follow the instructions to install ithttps://www.elastic.co/docs/deploy-manage/deploy/self-managed/installing-elasticsearch Change the Elasticsearch server settings in the file:/etc/elasticsearch/elasticsearch.yml=========Replace the values:node.name: nameofyourhostcluster.initial_master_nodes: ["nameofyourhost"]network.host: 0.0.0.0http.port: 9200add the line:action.auto_create_index: .monitoring*,.watches,.triggered_watches,.watcher-history*,.ml*==========Add the password. Create the file with password in any good directory (create the directory)nano /opt/elasticsearch_password/elasticsearch_password.txt change user access to the file:chown elasticsearch:elasticsearch /opt/elasticsearch_password/elasticsearch_password.txtchmod 600 /opt/elasticsearch_password/elasticsearch_password.txt restart the service:sudo systemctl set-environment ES_KEYSTORE_PASSPHRASE_FILE=/opt/elasticsearch_password/elasticsearch_password.txtsudo sy
Hi everyone,I’m working with FortiADC 7.6.4 and would like to ask about a couple of CLI commands. If anyone has information, I’d appreciate your help. 1. Checking interface link status Is there a CLI command that shows the actual link status of an interface? According to the documentation, the command "get system interface" only provides the enabled/disabled status, so I understand it does not show the real-time link state. I also looked at the following command: "diagnose hardware get deviceinfo nic-detail" which appears to offer detailed NIC information, but it does not show the link status for aggregated (LAG) interfaces. 2. Deleting backup configuration files I know that configuration backups can be created using: "execute restore config disk <name>" However, I haven’t been able to find a CLI command that deletes configuration backu
Hi!I’ve been testing Fortinac 7.6.7 in lab. It seems, that they did major changes to the RADIUS configurations. Changes are welcome, if you have not implemented Fortinac yet, but for existing installation, it might cause some work.I have been told, that nothing changes when I’m using Fortinet only devices (Fortigate, Fortiswitches and FortiAPs).That’s not true, if you are using RADIUS (in practise 802.1x)Or we can say, that nothing changes in 7.6.7 for existing devices, but if you are going to add new devices, you have to use the new selector based method. And later you have to migrate all existing devices.(https://docs.fortinet.com/document/fortinac-f/7.6.7/support-for-radius-only-devices/276659/overview)You have to migrate all existing devices to the new method before future release, because the support for the legacy method will be removed. There is a great migration tool, but it creates individual configurations for every device. It works, yes, but is quite a big mess.Missing best
Hi Team,We are using FortiClient EMS-managed IPsec Remote Access VPN (IKEv2) with split tunneling.Our FortiGate Phase 1 is configured with:mode-cfg enableipv4-split-include containing only RFC1918 networksNo full-tunnel configurationAfter connecting, the Windows routing table shows two default routes:0.0.0.0/0 -> 192.168.1.1 Metric 40 (Local Gateway)0.0.0.0/0 -> 10.68.1.14 Metric 9001 (VPN Gateway)The local gateway has the lower metric, so Internet traffic should continue to use the local ISP, which appears to be working correctly.However, we occasionally observe some Internet-bound traffic in the FortiGate traffic logs from VPN users, even though only RFC1918 routes are configured in the split tunnel.My questions are:Yes, this is expected behavior. FortiClient installs a secondary default route with a very high metric as part of its standard IKEv2/IPsec split tunneling implementation. This route acts as a fallback or "trap" route and does not override the primary local ga
Environment: FortiGate-VM64-OPC on OCI, FortiOS 7.6.7, A-P unicast HA, ha-mgmt-status enabled on port1 (reserved management interface, config ha-mgmt-interfaces with its own gateway).Two related issues, same root cause suspected:1. FortiToken Cloud MFA fails when logging into a unit directly via its own management IP - works on one unit, fails on the other. Traced to: the unit whose management interface needs to reach FortiGuard/FortiToken Cloud for validation has no outbound path. Confirmed via execute ping-options source <port1 IP> + ping 8.8.8.8 -> 100% loss, on both HA members (tested independently, not just the HA secondary).2. Separately, our OCI SDN connector (used for HA VIP failover) never completes the "refreshing IP info of instance / checking secondary ip" step in its debug output - it finishes generic resource inventory and just loops, never attempting the actual private IP move. Wondering if this is related to the same interface/routing gap.What we've confirmed:-
Hi everyone, The UniFi OS GUI currently has limitations regarding routing traffic coming from an inbound VPN tunnel into an outbound VPN tunnel (VPN-to-VPN routing). If you have a Route-Based IPsec (VTI) tunnel and want to route its traffic through an outbound WireGuard client connected to a VPS/VPN provider, the standard Traffic Routes won't catch it. After some debugging via `iptables` and `tcpdump`, I've managed to build a reliable solution using Linux **Policy-Based Routing (PBR)** and `systemd` persistence that survives UDM Pro reboots and firmware updates. Here is a step-by-step guide on how to achieve this. --- ### Prerequisites Before starting, connect to your UDM Pro via SSH and find your exact interface names:1. **Inbound IPsec VTI Interface:** Run `iptables-save | grep vti` to find it (e.g., `vti64`).2. **Outbound WireGuard Interface:** Run `wg show` to find it (e.g., `wgclt1`).3. **Inbound Subnet:** The network behind your IPsec tunnel that needs internet access through Wi
Hi Community,I noticed that the new FortiGate 400G (FG-400G) has recently appeared on the latest Q3 price list, but the official datasheet and full product documentation do not seem to be available on Fortinet's website or the Document Library yet.We are currently working on upcoming sizing and refresh projects and would like to confirm the formal datasheet release.Does anyone (or Fortinet team members) have visibility on:When the official FG-400G datasheet and product page are expected to be published publicly What the estimated General Availability (GA) shipping timeframe looks like for this modelAny insights or updates from local SEs/account teams would be greatly appreciated.Thanks in advance!
Hi,Is there a way to get report through fortianalyzer about rules on the firewall, not the usage of those rules?We have shared firewall for some users, and customers would like to receive reports of rules associated with their networks.It seems I can only get them to the report if there is either all logging enabled on the rules, or MTU filters record the event. I would like to have just rows of the rules, but afaik it isn't possible what I have searched?All loggin is the only way?
Is there any way to set/push a formulated (by a Jinja template) hostname to a secondary FGT in a-p HA from FMG WITHOUT flipping the HA?Or, simply impossible because FMG doesn’t hold the unique part of secondary devices, like host name, ha config?Toshi
Team i dont no why, but we keep on loss sync, yesterday we work with support up and get up working, just this morning the pri firewall is out-of-sync with the sec firewall any idea
Hi everyone,We are observing an issue on a FortiGate running FortiOS 7.6.7.Whenever an administrator logs into the firewall GUI, warning-level event logs are generated with the following message:"CMDB get request for sensitive information table"Immediately after these events, we observe a noticeable increase in CPU utilization on one or more CPU cores.The behavior is consistently reproducible during admin login sessions.Observations:FortiOS Version: 7.6.7 Warning log generated during GUI login activity. CPU core utilization increases shortly after the log is generated. No significant configuration changes were made prior to the issue. The behavior appears to be related to GUI access and CMDB queries.Any insights or recommendations would be greatly appreciated.
Download links for FortiClient EMS invitations are not working because the filename in the invitation are Initial Cap, while the filenames are all lower case. Running version 7.4.8. This was working up to yesterday.
Hello All,I am currently using switches from another vendor, where all default gateways for the end-user VLANs are configured on the switches. The switches have a default route pointing toward the FortiGate.I am planning to replace these existing switches with FortiSwitches. However, my concern is that when using FortiLink, the recommended Fortinet design is to place the VLAN default gateways on the FortiGate.Is it possible to use FortiLink to manage the FortiSwitches while keeping the existing design, where the default gateways for all end-user VLANs remain on the FortiSwitches, with the FortiSwitches using a default route toward the FortiGate?I would like to understand whether this design is supported and, if so, what limitations or configuration considerations I should be aware of.
We recently started investigating roaming behaviour on a customer environment using FortiAPs with WPA3-Enterprise and an external RADIUS server.The initial observation was that roaming did not appear to behave like a Fast Transition (802.11r) roam. During movement between access points, clients seemed to perform a complete authentication process again instead of using a fast handoff. This resulted in noticeable delays compared to what we would normally expect from an 802.11r-enabled deployment.To validate this, we captured both beacon frames and association traffic on the customer environment. In the captures, we noticed that clients were performing normal WPA3-Enterprise authentication exchanges after roaming. When we examined the beacon frames more closely, we found that the WPA3-Enterprise SSID advertised only the standard WPA3 Enterprise AKM. We could not find any indication of FT over IEEE 802.1X or a Mobility Domain (Tag 54) element.To rule out environmental factors, we rebuilt t
Hello Fortinet Community,I am currently configuring email-based MFA on a FortiGate running FortiOS 7.4.11 as part of a POC.I am using Brevo as the external SMTP service. SMTP authentication works, but I am having an issue with the sender/from address. The FortiGate appears to use the same email address configured as the SMTP authentication username, and I have not found a way to configure a different sender address.Has anyone encountered this behavior?Is there any workaround in FortiOS 7.4.11 to specify a different From/Sender address? Has anyone successfully implemented FortiGate email MFA using Brevo or another external SMTP relay? Would Microsoft 365 SMTP be a better alternative for this scenario? Has anyone successfully configured it for FortiGate MFA emails? Are there any recommended SMTP services or configurations for this use case?Any guidance or working configuration examples would be appreciated.Thanks in advance.
I have mac ip phone with mac addr 00:21:A0:2C:22:33 and if i test manually profiling then the rule is matchThe DPR will automatic register and move the device to role IPPHONEBut when i check on the host then i can see the role is empty, seem the DPR is not running event the rule will run ‘On Connect’ and every 5 minutes. Anyone know how to solve this?
Hi,Been digging through the EMS REST API on 7.4.8 and 8.0.0, and it looks like a wall, but better to ask before building the wrong thing.The need is simple enough: individual security events from endpoints — a malware hit, a web filter block, a vulnerability finding — each with its own timestamp, to pull into our SOC tooling.What exists is /api/v1/endpoints/index with the event_type filter (antivirus, antiransomware, webfilter, vulnerability, quarantined, pua, and the rest). Genuinely useful, but it answers "which endpoints have an antivirus event" rather than "what happened, and when". Great for a posture dashboard, less so for feeding alerts. The CSV export looks like the same view with the same filters, just asynchronous.All 15 modules in the API reference turned up nothing event-shaped. So: is there an endpoint hiding somewhere, or is this simply not what the EMS API is for? And if it isn't, is syslog out of EMS (or going through FortiAnalyzer) how everyone else solves this? One mo
Hi all,I’m troubleshooting a remote access IPsec issue on a FortiGate 200F running FortiOS 7.4.12 and wanted to see if anyone else has run into something similar.When NAT-T is enabled, remote users get noticeable packet loss / stalls over the tunnel during normal traffic — pings, file transfers, throughput tests, that kind of thing. When NAT-T is disabled, it gets a lot better.A few things I’ve already confirmed:the tunnel comes up fine the issue is reproducible when NAT-T is enabled the issue improves significantly when NAT-T is disabled I tested with NPU offload both enabled and disabled with offload enabled, tunnel error counters were higher on the problematic tunnel with offload disabled, those RX errors were much lower or zero in my captures, but the user-visible stalls still weren’t fully explained by the lower-level counters PDQ snapshots looked balanced during testing HPE dropping stayed at 0 in the snapshots I collected anomaly-drop output was empty we also contacted our ISP a
I am trying to create a FortiAnalyzer report that displays Sent and received interface bandwidth utilization over time for the Fortigates.The existing reports available in FortiAnalyzer provide data utilization using 5-minute averages, but they do not clearly identify the utilization for each individual interface.Below are multiple topics in the community:https://community.fortinet.com/support-forum-92/need-bandwidth-utilization-report-between-two-fortigate-devices-specific-interface-time-range-224155https://community.fortinet.com/fortianalyzer-6/technical-tip-how-to-generate-throughput-utilization-billing-report-98335https://community.fortinet.com/support-forum-92/fortianalyzer-how-to-generate-a-report-for-real-time-bandwidth-out-to-in-33756https://community.fortinet.com/support-forum-92/generate-bandwidth-utlization-report-for-specify-interface-in-faz-197578?tid=197578&fid=92As a possible solution, I enabled performance statistics on the FortiGate. FortiAnalyzer is now receiving
Hi everyone,We are running a FortiClient ZTNA Access Proxy deployment for our UAT environment and have run into a persistent connection loop immediately following the latest Fortinet ZTNA update. We are looking to see if anyone has hit this specific behavior or has a confirmed Bug ID/Workaround.🚨 The Symptoms Error Encountered: ZTNA Application Not Found (Error Code: 022) with the message Client certificate is not provided. Device Information: N/A. Behavior: It only affects users connecting from external networks (off-fabric). Internal corporate network connections work fine. The Loop: When we perform clean reinstalls or manual re-registrations, it works perfectly for exactly 2 hours, and then abruptly drops back into Error 022. 🛠️ Troubleshooting & Root Cause Analysis Done So FarWe have thoroughly mapped out the behavior and ruled out basic configuration errors: The 2-Hour Pattern & Compliance Discovered: * The 2-hour survival window strongly pointed to a periodic server
Hi there, I’m having issue with matching Fortigate Proxy Policies against user group membership using AD DC2. Currently I have Active Directory with 2 DC’s. I have separate ldap connections to them (because of scale of organization, and the need to granulary test the migration between them. Fortigate is configured to use Explicit Proxy and we are allowing AD groups to access specific websites in Proxy Policies.When users workstations use DC1 as primary DNS server - everything works (they can access sites allowed in polices) but after switching them to DC2 - they can’t access any website specified on Proxy Policies and fall to implicit deny. We tried switching massively - didn’t work, and we tried switching single/few groups with same result. How we perform the tests on dedicated workstation:Test workstation is joined to Domain Test workstation switches DNS server from DC1 to DC2 (currently for more than 3 weeks the station has DC2 setup as primary DNS without any other DNS servers) Tes
Hello,We are experiencing an issue in our environment with FortiNAC and would like to understand the root cause.EnvironmentFortiNAC Aruba Access Switches 802.1X enabled on switch ports Printers and endpoints authenticated through FortiNAC Wired environmentIssue DescriptionWe have several devices, including network printers and some user laptops, that intermittently lose network access.Symptoms:Device works normally for a period of time. After some time (sometimes a couple of days), the device loses network connectivity. The switch port remains physically up. Reconnecting the cable does not resolve the issue. As soon as we manually perform "Register as Device" (or re-register the host/device) in FortiNAC, connectivity is immediately restored. No switch configuration changes are required for recovery.This behavior affects both:Printers Wired laptopsObservationsDuring troubleshooting, we noticed that some affected hosts show:Last Modified By: Systemshortly before or around the time the de
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.