User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
How to generate a FortiAnalyzer report to get ISP uptimes?
Hi FAZ、FMG created same ADOM name for manage FAZfollow this guidehttps://docs.fortinet.com/document/fortimanager/7.4.0/examples/289359/adding-fortianalyzer-to-fortimanager at FAZ, ADOM name ”ADOM_v74” have one device at FMG, have same ADOM name”ADOM_v74”, and same devicebut in this ADOM, the left sidebar doesn't even have a Log View or FortiView to check traffic or other logs.only “FAZ” ADOM have Log View and Forti View
Hi everyone, I have this issue with a FortiManager I have deployed in Eve-NG. It’s just used for labbing and playing around with config etc, so its intended to be very simple at the moment.It’s a brand new deployment and licensed using the free license with FortiCloud. Yesterday I was able to log into the manager with no problem, worked fine and then I started experiencing the issue with logging in and getting the ‘Rejected’ message. I have done the basic config such as routing and admin access.The same creds work via the CLI. It is a local account, with no trusted hosts or 2FA.My next thoughts are to just wipe the config and redo the deployment as there is nothing of value on it at the moment and it is probably just easier, but thought it would be worth asking and getting this on the community incase anyone else has the issue.
Hello,I've a newly deployed Fortigate 200F in my LAN. I've an internet souscription bandwith of 16M.Recently I've been realizing that my bandwith is constantly saturated, but Fortiview doesn't show me the applications that saturate the bandwith. As you can see on the images above, the total bw of the internet applications displayed by the firewall (4Mbps) is much lower than our subscription (16Mbps) but it still displays our bw saturated, and the internet service is slow.Please note that this is not permanent. It happens constantly.When look to the security report, the firewall doesn't indicate any malicious attack.Please any help will be very appreciated.Thanks
People on Fortigate 7.4.12 using FAC as the Captive Portal are all working fine, I built some new sites on 7.6.7 and the config is identical, only now they cant Authenticate, they hit the Exempt rule to get to the FAC on https, and they register and get approved, but they cannot authenticate when logging in to the page.I've never liked the logs on FAC, they are not helpful at all! but most of the messages are “Guest portal authentication request failed, then says please check the Radius Auth logs, but there are none! as they don't Auth! Has something changed in the way 7.6.X Authenticates now? The EAP-TLS is working fine for the other SSID, its just Captive portals (Once again!) even in debug mode there is nothing when I search for the failed user, its most annoying, I am using “set require message authenticator enabled” but on 7.4.12 its disabled as its disabled on the FAC, is this enforced now?In short it works on 7.4.12 but not 7.6.7. , Scowered the release notes and cant see anyt
Hi allI have noticed a weird issue, client had a power outage over the weekend as the redid the server room UPS.Now my AP’s show “Connected VIA” my VOIP interface on the FortiGate, even tough they are connected via FortiSwitches and the LLDP Neighbors are correct, also the IP’s they get are from my DATA VLAN.They use to say connected via DATA VLAN and once rebooted they now show VOIP. all troubleshooting points to they are indeed connect via DATA VLAN.GUI BUG? FortiGate 7.4.12 , FortiSwitches 7.4.8 and FortiAP’s 7.4.6Please let me know if anyone has experienced this and why now all of the sudden?
Hi TeamI have around 200 VPN users. It requires monthly administration tasks to ensure VPN access is revoked timely for resigned leavers, interns and staffs no longer require VPN access. It is for IT Audit Policies.On Fortigate firewall, this is not a helpful task. My Fortigate (FortiOS 7.2 & 7.4), have not that option of per-user vpn account expiry date !!However, on Cisco Meraki MX, it allows configuring an account expiration date on VPN users directly. This was very useful since 1st Covid 2020 to date.Are there any workaround?
Hello, we have an issue about forticlient application, 1. installed application2. imported configuration file successfully3. while entering username and password and click connect button, app does not do nothing, just clearing username and password also, tried to uninstall, clean reinstall of application with revo uninstaller pro, but didn't work, also trierd to debug on firewall and there was no any traffic matching. application version is 7.4.3.4726 We tried the same installer file and the same vpn configuration file on other desktop and it worked successfully, the main thing is that we can not reinstall windows but need to setup the forticlient vpn urgently.
Hi Everyone,I have a FortiSIEM HA deployment with the following architecture:3 Supervisors (with DB) in HA 2 Workers 2 CollectorsI have a few questions regarding backup and disaster recovery:Which nodes should I back up? Do I need backups of all Supervisors, Workers, and Collectors, or only specific nodes? Which databases are critical to back up (CMDB, PostgreSQL, ClickHouse metadata, etc.)? My Event DB is already stored on NFS. Is an NFS backup sufficient for Event DB, or is any additional backup required? If a VM crashes, can I deploy a new VM with the same FortiSIEM version and restore the backup, or must it be restored on the original VM? What are the most critical components to back up in FortiSIEM (configuration, CMDB, ETCD/Keeper, custom parsers, rules, dashboards, reports, certificates, license, etc.)? Does anyone have a recommended backup/restore SOP or best practices for a FortiSIEM HA deployment?
Hi Fortinet Team, Good day! We’d like to confirm behavior of DOS policy on fortigate, we have initially created a policy from internal network to public with set the UDP_Flood as blocked, initially set the threshold to 5000 and is reached. what are the expected experienced
What can i do if endpoint ip address on the device inventory and on the adapter showing wrong ip?actually the endpoint get ip 10.100.50.168
Request to get pkg file of Forticlient VPN Only for MacOS to use with Intune in Download page it is online installer I cannot use with Intune I need to real file of it
HiHow many SSIDs are recommended?I read that only 3 are needed. Okay, I understand that one for IoT/External, one for Internal and one for Guest.My challenge is about the ssid pasword. I will have around 600 users using ssid External.How to manage if the password has been shared or leaked?
Can we identify how many users is active and authenticated to fortinac?
I would like to clarify the behavior regarding the display of warning and block screens in the Web Filter.We are currently configuring a system using FortiOS v7.6.7 and applying Web Filtering to internet-bound traffic.When a client device—with the CA certificate installed—attempts to access a site falling under a blocked category, the connection fails.* The error message "Your connection to this site is not secure (ERR_SSL_PROTOCOL_ERROR)" is displayed.We performed troubleshooting by changing the inspection mode setting for the relevant policy, with the following results:- Flow-based: The block page is not displayed.- Proxy-based: The block page is displayed.The Web Filter feature set within the security profile is configured for flow-based inspection in both cases.My understanding is that warning and block screens should normally be displayed even with flow-based settings in FortiOS v7.4.Have you encountered similar inquiries or issues?Also, could you provide any information regarding
We have policy only device managed by Intune can be conenct to the network.In the intune i have host below, the endpoint only showing wirelesss mac address, but actually the endpoint have 2 mac address (wired and wireless). This make the user can’t access to the network because wired mac is detected not managed by MDM. Anyone know why?
Hello Fortinet Community,We recently upgraded our FortiGate to FortiOS 8.0.0. Before the upgrade, the device was running FortiOS 7.2.13 7.4.12 7.6.7, and we created a full configuration backup.After the upgrade, we experienced an unexpected internet outage. During the incident, the FortiGate had a high number of active sessions, and users lost internet connectivity. A reboot temporarily restored the service.At this time, we cannot confirm whether the issue was caused by FortiOS 8.0.0 or another factor. However, since the environment was stable before the upgrade, we are considering downgrading to the previous stable version while continuing our investigation.We would appreciate your advice on the following:Is it recommended to downgrade from FortiOS 8.0.0 to FortiOS 7.6.7, or would FortiOS 7.4.12 be a better long-term stable version?Since we have a configuration backup created while running FortiOS 7.6.7, can we safely downgrade and restore that backup?Are there any known issues or pre
Hello Techies i have 15 fortigate firewall that is getting authenticated by cisco ise tacacs, now i want to enable MFA for all firewalls is there any possibility to set asingle code for all firewalls.i have tried fortitoken but that require different otp for each firewall
overlay working but underlay under the members i dont see the physcial port 1 an port 2I have config SDWAN ADVPN 2.0 i was able to to setup the overlay SDWAN but when trying to config the undelay SDWAN, i have created a Zone for underlay, but when i am trying to add the ports to the underlay zone the ports which the ISP are connected dosent show (port13 and port14)
Using the standard Portal templates, just adding custom logo etc, it isnt responsive to mobile phones, Apple or Android, I have tried to add extra CSS to the template for login, registration , disclaimer etc. but it just doesnt lay out right, Does Fortinet not have a fix for this or a guide for the best way to add viewport in the CSS? I did CHATGPT it, but it still not quite right, I mean this is standard stuff these days right?ForiAuth 8.0.3 Thanks
Hi everyone, I'm experiencing a strange issue with an IPsec Dial-up VPN after migrating users from SSL VPN. The environment is FortiGate 400F with FortiClient VPN 7.4.3.4323 on macOS Sonoma 14.1. The problem only affects macOS clients; Windows clients using the same VPN configuration and user account work correctly. Split tunneling is enabled, and all firewall address objects are configured correctly as /24. However, after connecting from macOS, one of the split-tunnel routes is installed with an incorrect mask (for example, 10.10.10.0/24 becomes 10.10.10.0/31). If I remove that subnet from the split-tunnel group, the issue moves to the next subnet (10.10.11.0/24 becomes 10.10.11.0/31), so the problem follows the route order rather than a specific network. I also tested with a split-tunnel group containing only three networks, and everything works correctly on macOS. The production split-tunnel group contains around 190–200 routes. Has anyone encountered a similar issue or knows wheth
Hello.Working as a Telecom user, I can only use Putty and similar software for SSH and Telnet connectivity with the Dacon VPN, but not with the Planet VPN.From IAM support, they replied that I am enabled without hindrance with both SSH and Telnet.Can anyone help me? Thanks in advance.
Hello Fortinet Team,I would like to report a False Positive occurring in FortiClient. The antivirus engine is flagging and quarantining legitimate .jar files that belong to Microsoft Power Automate Desktop.These files are required by the Microsoft application to interact with Java-based interfaces for automation purposes.Software: Microsoft Power Automate Desktop Flagged Files: PAD.JavaBridge.jar PAD.JavaBridge.A11y.jar Some of the File Hashes (SHA256) involved: CF531D64F2445BD6149EF018D41C6B6EDC2185461100998DFF8204... 0887F61DB05200C724DF9E0700F63B98145E47C69FB98258323AB6... EB935EB8D28CDBA566CBACDA023E02FCD4A9DB0535893B5B8699E7... I have attached a screenshot ("Captura de pantalla 2026-07-20 110922.png") showing the multiple detections and the exact hashes provided by the FortiClient logs.Could you please review these files and update the definitions to whitelist them?Thank you.
I am considering changing the username of the default "admin" user on FortiGate.I understand that it is possible to create a new superuser and change the "admin" username, but will changing the default "admin" username affect other settings?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.