Your feedback drives change, make your voice count
Fortinet Community
Recently active
Now i have Fortinac with version 7.6.5 Fortinac-os and i have agent is 9.4.0.93 i need to know if this is most suitable version for agent or not and if i plan to upgrade it what should i do if i made in the scan policy check latest persistent agent and i also edit the registery key of LoginDialogDisabled
I use persistent agent to checking antivirus on the client before the client can connect to the network.My question is what parameter will be checking by PA? Is antivirus realtime protection is on/off, is antivirus batabase signature updated or not, or something else?
Hello dears,I hope you are all doing well.I am facing an issue with FortiClient VPN in our organization. Every time an employee tries to open FortiClient, they are prompted to enter administrator credentials.Has anyone encountered this issue before or knows how to resolve it?
Hello,I am connect to mobile hotspot rogers and my internet speed is very very good no doubt. I did every thinh minimize the wifi MTU in laptop. disable ipv6 and other stuff but still after 98% it restarted.Need urgent help in that please. Thank you,
good morningThe requirement is to create two physical ports for the firewall: one dedicated to the entire internal network, from which all data flows, and the other one dedicated solely to the Fortigate firewall's settings, updates, databases, and communications with its servers and online services.How can I properly isolate these two ports to prevent any data leakage from the first port to the second? Can I get a detailed, practical guide to the process?
Hello everyone,I'm experiencing an intermittent issue with an IPsec Remote Access VPN.The VPN tunnel establishes successfully (IKE and IPsec SAs are up), and the client authenticates successfully. However, in some cases:TX (sent) packets increase normally. RX (received) packets remain at 0 bytes / 0 packets. No internal resources are reachable.One interesting observation is that the issue depends on the ISP. If I switch to another Internet provider, the VPN works immediately.A few months ago, I had a similar issue that was resolved by setting the MTU to 1350, but this workaround no longer solves the problem.I have reproduced the same behavior with:FortiGate 7.4.x FortiGate 8.0.0This makes me suspect an MTU, fragmentation, or ISP-related issue, but I'm not sure where to investigate next.Has anyone encountered a similar behavior?
Setting up new Fortigate and prefer to start from scratch as old gate was breached several times most recently during the SSO vulnerability and changes were made. Instructions that I could find recommended deregistering and wiping configuration on the old gate and resetting and programming on the new gate or transferring the relevant configuration to the new gate. Is it possible to leave everything as is on the new gate, wiping switch and ap (resetting) and then attach to the new gate and setting up from scratch or will the fact that it is still set up on the old gate interfere with the process? Would just prefer that I have the option to put them back on the old gate if I run into difficulties with the new set up. Clearly not a network engineer! Rolling back to 7.4.12 on new gate because of glitchiness on 7.6.7 and switch is on 7.6.6 and ap is on 7.6.5 - should I drop back firmware on switch and ap when I transfer them?
Forticloud Support gave me this as a solution: Well, this did NOT work. Could anyone here provide a solution/fix for this?Can this be ignored?Will it have impact on performance?How can one reduce the amount back to max 110?How can i prevent further growth? N.B. I am seeing weird variations of a work email address, with different characters added in the email address itself thus creating multiple copies. For example: jbrown@work.edu.ca is the official email address. Now i am seeing in the FM cloud active user mailbox list j-brown@work.edu.ca, jbrown123@work.edu.ca , j.brown@work.edu.ca and it goes on and on for others. This is unacceptable.
Hi guysFGT A with WAN 1 and WAN 2 interfaces with direct public addressFGT B with only WAN1 Created nr 2 tunnel ipsecTunnel 1 = FGT A WAN1 to FGT B WANTunnel 2 = FGT A WAN2 to FGT B WAN Created policy and static route with administrative distance = 10 (Tunnel 1) and = 20 (Tunnel 2) When tunnel 1 is DOWN I get strange output on routing interface.Picture 1, static route works, I can reach LAN on FGT BPicture 2, static route doesn’t work, I can’t reach LAN on FGT B. I get strange IP address on static route, 10.0.04 is not public IP of FGT B Someone can suggest me any other checks?What could it be?
The FortiEMS server is running version 7.4.7, while the client version on the workstations and servers is 7.4.5.We plan to upgrade soon.In the clients' "Notifications" tab, I see many "Patching Failed" alerts.The installers were never created with the "Auto update to the Latest Patch" option enabled."Automatic Patching" is also disabled in the Vulnerability Scan settings.We never perform upgrades or patching automatically; we prefer to manage that process ourselves.So, what is triggering these "Patching Failed" alerts?Thanks
URL: https://incoso.co.za/>> This is a false positive. incoso.co.za is the legitimate website of INCOSO (Inhouse Conference Solutions), an established South African event-management company operating since 2007, based in Bellville, Western Cape. The site contains standard business content only: company profile, services, portfolio, testimonials, and a basic name/email contact form. It has no login area, no password fields, and no payment processing, so there is no phishing surface.>> We believe the detection originated from Avast Web Shield running on the machine of the web administrator who deployed the site. During go-live there was a brief window before the site was fully configured and secured, and we believe Avast automatically sampled the site in that state and submitted it to your cloud database, classifying it before the finished, live site existed. The live production site has been complete and secure since launch.>> Avast/AVG is flagging both the homepage a
Hi community,i have in office Fortigate with ip public 87.xx.xx.xx, policy created for internet, I created in windows (PC office)- vpn client conection l2tp other ipsec for conect to mikrotik(home) ip public 193.xx.xx.xx .Issue is when i try to conect vpn windows(client) to mikrotik(server l2tp/ipsec) this conection is down ,but when i try conect pc office to hotspot vpn l2tp/ipsec conection is successfully to mikrotik.Can anybody help with this issue,why my pc canont conect l2tp/ipsec to mikrotik? beetwen MIKROTIK and FORTIGATE not set ,not config any vpn,mikrotik is outside, is in my home.
Hello Community, I hope you're well I stay in process to deploy Fortiweb 400 F, but I have doubts about whether it is advisable to place the Frontend and Backend interfaces in separate VLANs, and if you recommend this topology for a future deployment of Adoms, or if the design should be rethought.I attach the Topology.Greetings!!!!
Can anyone confirm me if FortiGate 70G Firewall requires a separate license to operate or does the product comes with a base license when purchased new.
Hi FWB adminsAccording to FWB’s CLI ref we can access to traffic logs and attack logs via CLI.https://docs.fortinet.com/document/fortiweb/7.6.6/cli-reference/561209/logThe user is admin and its profile is prof_admin (has all rights).However when the mentioned command seems not available.fwb01 # diag log all startParsing error at 'log'. err=1Command fail. CLI parsing error.Any idea?
We manage a multi-branch network with FortiGates centrally managed via FortiManager, all running the same policy package. At specific branches, users attaching 2-3MB files to email through OWA (Outlook Web) experience 20-30 minute upload delays, while other branches on the identical policy are unaffected.Our SSL/SSH Deep Inspection profile already exempts the Finance & Banking and Health & Wellness categories, plus around 20 Microsoft/Outlook-related FQDNs. We confirmed via FortiManager that this exempt list is identical across affected and unaffected branches. Setting the policy to "No Inspection" resolves the issue immediately, confirming deep inspection is the cause.Since the exempt list is the same everywhere but the problem is branch-specific, we suspect some URLs or hostnames used by OWA for attachment upload (possibly Microsoft's Azure Front Door / M365 substrate/CDN endpoints, not just outlook.office.com) are missing from our exempt list and differ depending on branch e
I'm lab testing a few different ADVPN setups and noticed the Cross-regional spoke to hub shortcuts:https://docs.fortinet.com/document/fortigate/7.6.0/sd-wan-architecture-for-enterprise/242856/using-ibgp-between-regions-with-inter-region-advpnThe docs are missing at lot of details so I'm wondering if anyone knows how this dynamic tunnel from Branch 1 (Region A) to HUB in region B is created? Which tunnel interface is used on Region B HUB.Does the static VPN tunnel between the hubs need any ADVPN specific config rather than just standard static tunnels?I have dynamic tunnels working ok within the same region so I have a basic understanding of how the tunnel is formed. Just not clear on when it comes to Multi region, specifically the SPOKE to the HUB in the other region.
Hello, I opened a case with support asking about a 7.4.4 version of Forticlientvpn only for windows , they suggested we post here. My questions are:1) Is there a version of forticlient vpn only 7.4.4 coming out for windows?2) If no can you verify if forticlient vpn only 7.4.3 for windows is not susceptible to https://fortiguard.fortinet.com/psirt/FG-IR-25-685 Thanks!
We use the fortiPAM solution, but it only works in a web browser (so it won’t work on servers and will most likely be useless in this situation).Is there another way to grant access directly from the Linux console? For example:Would it be possible for the company to install FortiClient on Linux (Red Hat or Oracle Linux) and configure FortiGate to grant them access only to selected subnets?It’s the simplest idea I’ve come up with recently. Since FortiPAM is useless for running on a server without a UI, I suppose this would be the best solution.The only question is, will FortiClient work in such an environment?
current version start from 6.0.18My current version of FG-60E is 5.6.10 how can I upgrade this to 7.4.11?there is no path of 5.6.10~6.0.18
My Fortigate device is out of support, and is currently running 7.4.8.It has started to attempt upgrading to the latest patch (7.4.9) as per the new upgrade mechanism: https://docs.fortinet.com/document/fortigate/7.4.0/new-features/320693/automatic-firmware-upgrades-for-fortigate-appliances-with-invalid-support-contracts-or-that-have-reached-end-of-support-7-4-8 However it keeps failing and sending emails that it has failed.logdesc="A federated upgrade could not be completed by the root FortiGate" msg="Federated upgrade failed after reaching state downloading" reason="download failed" Its sent that one a few times, is now also sendning emails regarding the schedule being changed: logdesc="Automatic firmware upgrade schedule changed" user="system" msg="System patch-level auto-upgrade new image installation (re)scheduled to between local time Thu Oct 23 01:42:23 2025 and local time Thu Oct 23 04:00:00 2025. This installation is forced and cannot be cancelled." Do
Is it possible to send traffic from Fortigate-1 InterVDOM to Fortigate-2 InterVDOM ?. I have LACP routed interface between Fortigate 1 and Fortigate 2, both firewalls can ping each other.Both are running FortiOS 7.4.11. Fortigate 1,all lan ports are LACP with multiple VLAN uplinks from switches. Fortigate 2,multiple interVDOM links created between rootVDOM and cust-1 to 3 VDOMs. interVDOM link interface for rootVDOM is configured as 0. customer VDOMs, static routing & firewall policies are created to respective interlink. root VDOM, static routing and firewall policies are created to Fortigate 1 and other VDOMs on this Fortigate. When i try pinging from customer VDOM to Fortigate-1 VDOMS, it keeps on looping on InterVDOM link of respective customer VDOM. In a nutshell, can’t reach between VDOMS of both Fortigates. I’m using “ethernet” instead of “ppp” and segments from APIPA range((169.254.0.0/16) for interVDOM link. What i’m trying to achieve, is it supported ?. Am i missing any
I have a FortiGate 600F firewall, and I would like to configure logging and reporting so that all logs and reports remain within my organization's infrastructure and are not stored or processed outside the organization (e.g., in the cloud).What is the easiest and most appropriate solution to achieve this? Could you please explain the recommended approach and provide the implementation steps?Thank you.
I have already completed the configuration of my FortiGate firewall. However, I now need to enable and configure VDOMs and divide the firewall into multiple VDOMs.Will enabling and configuring VDOMs at this stage affect my existing firewall configuration, policies, interfaces, routes, or other settings? Or can this be done safely without impacting the current configuration?Are there any important considerations, best practices, or precautions that I should be aware of before enabling and configuring VDOMs?Thank you.
Has anyone seen this on a 6300F or 6500F? Looking for a cleaner fix than rebooting the FPC.Specifically wondering:1. Is this a known bug in 7.6.x with a fix in a later build?2. Is there any way to reclaim kernel slab memory without rebooting the FPC?We had an incident last night where FPC1 on our 6300F started dropping packets after about 16 days of uptime. The other 5 FPCs were completely fine. Rebooted FPC1 and everything came back to normal immediately. The log message we saw:fw_forward_handler line=788 msg="The system is in extreme-low-memory state. Drop the packet."When we dug into it with diag hardware sysinfo memory we found the problem — SUnreclaim on FPC1 had grown to 22GB while every other FPC was sitting at around 600MB. MemFree on FPC1 was down to 2%. At incident:FPC1 - SUnreclaim: 22,029,000 kB :warning: - MemFree: 692,292 kB (2%)FPC2 - SUnreclaim: 626,632 kB - MemFree: 21,902,960 kB (66%)FPC3 - SUnreclaim: 621,352 kB - MemFree: 21,918,292 kB (66%)FPC4 - SUnrecla
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.