Mark a Best Answer
Fortinet Community
Recently active
With the rise of cloud adoption and the pace of technological change, building a holistic security architecture has never been more critical to protecting an organization’s assets in the cloud. In this blog post, we will explore the top five security principles for safeguarding your cloud applications, which we shared in the webinar “The Top 5 Principles for Successful Cloud Security”. At Fortinet, we are committed to helping our customers stay up to date with a comprehensive security strategy and the right tools to ensure their hybrid environment remains secure. Image 1 illustrates the five cloud security principles designed to guide your current strategy and deepen your understanding of the rapidly evolving cloud risks. Image 1 – 5 Cloud Security pillar 1. Identity and Access Management In today's cloud-centric environment, identities have become the new security perimeter. When you register with a cloud provider, a username and password are t
Hello everyone,I’m facing the following issue: when generating a traffic report for the previous month, the report also includes the first day of the following month. For example, when requesting traffic data for July, the report correctly shows all data for that month, but it also includes August 1st, although with a very low traffic volume.It’s worth mentioning that when running the SQL query directly on the dataset, the results are correct and only include data from the requested month.I’d appreciate any guidance to understand or resolve this behavior.FortiAnalyzer
This article describes how to send an email notification in an event one of the playbook steps failed. This is solution is not a global error_handler notification and thus should be configured on each playbook. For the purposes of this description, the usecase is blocking an malicious ip and sending an email notification on the list of blocked IPs.Prerequisites;i) Configure firewall connector - Give read-write permissions to the API userii) Configure SMTP connectorplaybookThe playbook logic:Start > block_ip > code snippet > Collect Failed Errors > Condition > Send mail notificationIn all your playbook steps enable ignore errors.In any of your playbooks that you intend to track failed steps, include two critical steps;(i) Set Variables Step The above variable playbook step is Collect Failed ErrorsThe variable name is failed_errors - The objective is to collect failed steps errors across the playbook.failed_errors jinja;{% if steps.block_ip.status != "Succes
Hi, suddendly, one of our FGT (7.2.11) cannot reach the internet. Both wan are up and gateway reachable. the default route is set to the sd-wan. One 2nd firewall on another site with the same rules (pushed from a FMG) is fine .all internal traffic is fine including to/from our IPsec vpn remote sites.SD-WAN SLA are all up including the ones testing external dns. But an execute ping 1.1.1.1(or any exeternal IP) from the FGT give a Network unreachable. default route is set to the sd-wanAny ideas ?
I configured three firewalls, with the HUB using a dial-up. One SPOKE can communicate normally with the HUB. However, after adding another SPOKE, although the IPSEC VPN tunnel was successfully established, the HUB's tunnel IP cannot be pinged. Could you please help identify what the issue might be? Thanks
Hi All, I have a user who uses FortiClient on iOS. For the past three months, they haven't been able to connect to the SSL VPN, receiving a 'VPN Authorization error: session expired' message. I've tested FortiClient on Android and Windows devices, and both connect without issue. The user's iOS version is 18.5, and their FortiClient version is 7.4.7.0183, FortiGate version is v7.4.8 Any idea for this case?Thank you
I have a RADIUS server under FortiGate A. I have created a tunnel between FortiGate A and FortiGate B. The tunnel is up. I want the same RADIUS server to be used on FortiGate B. i setup configuration, but it is not working.
Blank lines flagged as differencesHi!running FortiManager VM 7.0.11 - the Revision's "Device Configuration DB" "View Diff" is always showing blank lines and space at every change, despite "Config Sync" showing "Synchronized" - see screenshot. With so many changes, the GUI function's near useless (although, "Capture Diff to a Script" works OK).How to fix?Thanks!
Hi, I am running an SPA (JS) application behind fortiweb in monitor mode.When HTTP2 is activated, the https (http2) request keeps infinitely pending.This request has the header "text/event-stream" When bypassing fortiweb and accessing directly apache in HTTPS (HTTP2), everything is fine.Could it be that fortiweb (7.6.4) has some issue heandling SSE requests ?Thank you for your help RegardsThibaut
Hi everyone,I'm currently configuring SD-WAN on a FortiGate device, and I’ve noticed that the default routes (0.0.0.0/0) are not being generated automatically for all WAN interfaces as expected.I have four WAN links added as SD-WAN members, and SD-WAN is enabled. However, when I check the routing table, I only see two default routes. I was expecting FortiGate to automatically generate a default route per interface when SD-WAN is active.Here’s what I’ve done so far:Added all interfaces to the SD-WAN zoneAssigned gateways for each member (both working members are configured via DHCP)Checked SD-WAN rules and performance SLA (removed them just for debugging)Verified that all interfaces are up and reachable (adding a static route for my source IP, just to check ping over internet)Still, the routing table doesn’t reflect all default gateways. I suspect I might be missing a step or perhaps some specific configuration is required to force the routes.Has anyone faced this issue before? Should I
Do I need to configure the Fortigates directly in FortiManager, or can I configure them (directly in the box) and then upload the settings to the manager?Is there any documentation on how to do this?*I need to make some configurations on some Fortigates and I was unsure about this.
Hello, I'm trying to set up a VPN connection. At the moment I want to limit access because anyone can connect without a username or password. My users are in a group and I want to select the same group in order to authenticate. When I choose the option: "peer ID from dialg group" the pre-share key option disappears and I can't save because it gives an error: - 1 invalid lenght of value. Can anyone help me? I just want to authenticate with a list of users.Thanks.
Hello everyone,There is some study material on the training institute portal or here on the Fortinet support page regarding the configuration and functionality of a Fortigate used as an IDS/IPS probe.I would like to learn more about this and the admin guides just tell you step by step how to enable or configure a certain function.Thanks to all
I am facing the issue in FortiNAC guest self-registration user login connect captive portal. Can't access, and an error shows like Registration failed: Invalid Physical Address. In User&Host>Adapters, the MAC address learn and adapter are shown in a grey color. How to fix this issue.
Yall smart people know how to only allow split tunnel on a remote worker for a specific subnet? to let’s say 192.168.13.x. All other traffic (including internet ) go through the tunnel?
I modified the policy on FortiGate by adding a new port to it. Since traffic began to be forwarded through this port, I saw in FortiAnalyzer that traffic through this port falls under policy ID 0, meaning it is blocked. At the same time, I checked the source and destination IP addresses in the logs—they are specified in the policy.I found information that this is because the session is currently active, but I looked at the information in the policy, which showed the number of active sessions, and it dropped to 0, then rose again.Has anyone encountered something similar?I would be very grateful for your help.Version of FortiGate: 6.4.15
Hi Folks, i've deployed 3 ipsec dialup vpn tunnels and i'm facing the same issue for each one of them.The 1st time of the day you try to connect via forticlient, insert credential and receive the mfa push notification, the connection always fails, at the 2nd try instead, it works; and this happens for all my tunnels.Is there any particular configuration to be investigated?Fortigate version is 7.4.7 and forticlient 7.4.0.1658.I looked for some technical tips workaround but nothing was found.Is someone else facing the same issue? Thank youRegards
I have cause to pull some information from a device connected to one of our switches (FortiSwitch 124F-FPOE), which are connected to / managed by our ForiGate's. Commands such as diagnose lldprx neighbor summary work fine in the CLI of the FortiGate, however it then only see's the devices connected directly to it. If I open the CLI on the switch and run the same command I get. command parse error before 'lldprx'Command fail. Return code -61 I then tried to enable LLDP in case it was off and that was causing the first error, however I have tried going to both config system global and config system settings and running set lldp-reception enable but I just get a similar error. command parse error before 'lldp-reception'Command fail. Return code -61 Any idea what I'm doing wrong?
Dear all, In FAC 6.6.4I'm facing an issue while trying to sync remote LDAP user group with more than 500 user (510 exactly).The sync rule fails with error Unable to query remote LDAP server SRV_LDAP (ldap.xxx.xxx.xxx.com) for users to sync (rule xxxxxxxxx): ldap_search_ext_s search failed: Size limit exceededIs there a way to overcome this limit? What are the options to sync and use large LDAP groups? I didn't find anything in the documentation related to ldap group limit size. Thank you all! Best Denis
What is best sdwan strategy for my case below.I have 3 internet connections with bandwidth 100,200 and 300Mbps then i want to select link with low latency. If link with 100Mbps have lowest latency then this link will be used for all users, but in one side i want to utilize the other link if this lowest link is fully utilized.Which sdwan strategy suitable for my case?
Hello Fortinet Community,I am experiencing an issue where our FortiGate device is blocking access to Gmail.When users try to access Gmail, they receive a message stating Intrusion Prevention Triggered and their attempt is blocked.Here is the relevant message displayed:Your attempt to access the Internet resource is blocked by Intrusion Prevention.I have attached a screenshot for reference.Has anyone else experienced a similar problem with FortiGate blocking access to Gmail or other Google services?Any advice or guidance on how to troubleshoot or configure exceptions for this would be appreciated.Thank you!Edit: I have added 2 new screenshots with more details.
The LDAP configuration on FAC works fine when tested from the FortiGate, but after I enabled FortiToken on FAC, the VPN connection fails. Why is this happening?FAC version: 6.6.2FG version: 7.4.7FortiClient version: 7.4.3.1790
Hi everyone, we are currently exploring FortiPAM for use in a SOC environment and would appreciate any insights or recommendations from those with experience. Here are a few key questions w have : What are the best practices for integrating FortiPAM with third-party devices (firewalls, servers, etc.)? Is it possible to manage RDP/SSH sessions directly through FortiPAM without using FortiAuthenticator? Any real-world feedback on the scalability and performance of FortiPAM in high-volume environments? Are there any limitations or pitfalls to watch out for during the initial deployment phase ? Thanks in advance for your help !
Hello, has anyone experienced ipsec tunnel slower than the IPS? I have two sites and a Fortigate 400F with 148e switch and 1GB fiber circuit at each site. There's ipsec tunnel between them. Ran iperf through the tunnel and got about 36-40MBs bandwidth in both directions. Ran the same test from wan to wan (without tunnel) got similar results. Internet speed test shows 1GB symmetrical at both sites. There's no traffic shaping on either of the firewalls. All firewall policies are disabled for testing. The ISP says everything is fine nothing is wrong. Some internet sites say the ISP could have some traffic shaping on the circuits, not sure if that's true. Any troubling suggestions are greatly appreciated.
We have been told by Fortinet support that they will no longer support IKE1 in Forticlient 7.4.4 and greater. IKE2 does not support the X-auth functionality and so will not support RADIUS or LDAPS sources. If you use LdapS or RADIUS for your MFA to authenticate VPN users, this functionality could break your VPN logins or MFA and Fortinet will no longer provide you with support.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.