Mark a Best Answer
Fortinet Community
Recently active
Hello,I need to migrate an SSL VPN from a fortigate 7.2.10 to another fortigate 7.4.8, but the SSL VPN feature doesn't exist; I tried to enable it via CLI and it doesn't appear either set gui-sslvpn enable Fortigate 180F
Greetings, I am configuring RADIUS authentication on my Fortigate 101F running FortiOS Version 7.4.3. The Microsoft NPS Server has been configured according to this guide. My radius configuration is as follows: config user radiusedit "RADIUS"set server "172.16.9.3"set secret PSKset nas-ip x.x.x.xset auth-type ms_chap_v2set source-ip "x.x.x.x"nextend The connection between the Fortigate and the NPS is successful, but test user credentials test fails. The CLI test output is as follows: diagnose test authserver radius RADIUS mschap2 user passwordauthenticate 'user' against 'mschap2' failed, assigned_rad_session_id=1486429090 session_timeout=0 secs idle_timeout=0 secs! Running a packet capture between the Firewall and the Radius Server I get an access-reject response with the following MS-CHAP error Code: 3ID: 190Length: 42Auth: 91 C7 F9 28 0A 50 59 33 13 39 B3 75 58 04 AC EEAVP: l=22 t=Vendor-Specific(26) v=Microsoft(311)VSA: l=16 t=MS-CHAP-Err
We recently observed a concerning event on one of our endpoints involving the FortiClient Logging Daemon (FCDBLog.exe).While FortiClient is a trusted security solution in our environment, we are puzzled by this behavior. Typically, security tools monitor the hosts file for unauthorized changes—not modify it directly. The involvement of a scheduled task and the elevated privileges make this worth investigating further.Key Details:Process: fcdblog.exe (FortiClient Logging Daemon v7.4.3.1790)Parent Process: scheduler.exeAccount: SYSTEM / NT AUTHORITYCommand Line: FCDBLog.exe -s FC_{GUID}_000011Questions:Is this behavior expected in certain FortiClient configurations?Could this be part of a diagnostic or telemetry routine?Are there known cases where FortiClient modifies the hosts file intentionally?What steps can we take to verify the legitimacy of this action?Thanks in advance for your helpBRStephan
We have the below assets:Windows CAFortiNAC-VMFortigate-40FFortiSwitch-108F-POEFortiAP 221EWe are trying to setup the Corporate WiFi Access with FortiNAC, using a certificate. Flow:Users must Connect to an SSID with WPA2 Enterprise and FortiNAC confirms a user as corporate with certificate checking. We did all the steps we know and when a test pc try to connect in the Corporate SSID, we take the FortiNAC-RADIUS error below: Auth: (93) Login incorrect (RADIUS not enabled on device (Post-Auth)):What is the issue resolving path? Bests,PK
Hi,I've a Fortigate (version 7.2.11) that manage Hospitality access to internet with native Captive Portal features.For internal users I've configured LDAP server and all works correctly, but login expire day by day; every day ldap users must relogin. It's possibile to extend the expire timeout? Thank's Maurizio
I've installed EMS (v. 7.2.9 but I've also tried with 7.4.3) and activated a trial license on it as well as on my FortiGate-VM (v. 7.4.4). Trying to connect EMS with Fabric Connectors on FortiGate, the ping is going, it establishes a connection, I'm accepting the certificate and then I'm getting "FortiGate not authorized" notification. As I understood, I should authorize it from "Fabric&Connectors->Fabric devices" menu on the EMS, but the FortiGate doesn't appear there. What should I do and is this possible with trial license?
Hi there! So my company recently migrated from our old Cisco C170 Ironport to a FortiMail 400F. Ever since migrating to the new appliance, all our internal applications' emails to Google hosted domains are getting bounced back, complaining that our emails are not RFC 5322 550-5.7.1 compliant and they go further to either say that the 'From' header is missing or there are multiple 'To' or 'Cc' header. Emails sent from our users (desktop Outlook/webmail) to said Google hosted domains pass without issue. I'm half convinced that headers' manipulation is not working like how our Ironport did. May I know where can I check for said headers in the appliance gui? Regards,Ernest
Hello I have a FortiGate 40F, I am completely new to this system. Somewhere in it, it has VPN throttling set, but I don't know how that is configured, where it is, etc... I want to do some testing and familiarisation, by first finding where the existing user VPN throttling is set, and then try allowing a specific VPN application for smartphones and laptops through, to better understand how it works, so I can learn how to tune the system to meet user requirements. I appreciate it's a bit lazy to rock up and just ask like this, but if anyone could give me a steer to start familiarising with VPN settings on the web interface, I would be extremely grateful. Thank you.
Dear community member, I have searched a lot to solve the issue and read a comments but not helped much - unable to add fortigate to Fortimanger. Fortigate vm version - 7.0.15 (trail)Fortimanger vm version 7.2.10 (trail) I can ping from Fortigate to Fortimanger vice versa. Below services are enabled at fortigate interface.........FMG, security febric, http, https, ping. Please suggest what I am missing, I have also attached snapshot.
I am running a Virtual server on my Fortigate 1500D with the following healtcheck:config firewall ldb-monitor edit "PatroniMaster" set type https set interval 10 set timeout 2 set retry 3 set port 8008 set src-ip 0.0.0.0 set http-get "/master" set http-match "200 OK" set http-max-redirects 0 next endThe healtcheck is polling a Patroni service that runs with HTTPS with certificates signed by a private CA.The private root CA has been loaded to the Global scope of the Fortigate for trust purposes.The healtcheck is failing due to certificate verification issues. Tried a few different setups:1. Server certificate without chain2. Server certificate with chain3. Root CA with and without intermediate CA Tested the Patroni solution with curl from a remote PC and it works as expected:curl -k $PATRONI_HOST/replica --> returned: curl: (60) SSL certificate problem: unable to get local issuer certificate cur
I could use some help. The basic firewall policies of Allowing all, any, any out of the LAN to WAN1 and Denying all , any, any from WAN1 into the LAN works for about 2 seconds (I can ping 8.8.8.8 with 100% replies), then there's no internet access. The DHCP service is running perfectly issuing correct assigned private IP addresses, the test environment can ping the other device. Is there a possibility I could get some guidance, a view and critique of a basic firewall policy such as above?
I'm currently setting up an email infrastructure with FortiMail acting as our gateway, and I could use some guidance to refine my configuration for better security and functionality. Here's a brief overview of my setup and the issues I'm facing:Setup Overview:No private DNS server or LDAP.Backend testing with CWP (Postfix, Dovecot, Roundcube + Outlook, Thunderbird as mail client).Two domains to manage.SMTP authentication created on the same mail server.FortiMail in gateway mode with a DNAT VIP redirecting mail.Can send and receive emails inbound and outbound.Issues:Firewall Policies:I need help configuring firewall policies to ensure that SMTPS and HTTPS traffic goes to FortiMail, while IMAP, POP3S, and other services (webmail, etc.) go to the backend mail server.I have only one public IP, so any recommendations for port forwarding at FortiGate to manage services better would be appreciated.SMTP Authentication and Relay:I want to use the SMTP authentication created on the same mail ser
Hello, everyone. I've recently installed FortiClient VPN only v7.2.4 in MacOS Sonoma 14 and tried to restore a configuration file extracted from a Windows device generated on a previous version (v7.2.3) but ran into the "Error importing configuration file" message box. I've noticed some of the xml lines are different from the Windows and MacOS version so I had modified them but as it turns out neither a newly generated backup file from the MacOS installed client seems to be working by restoring it right after being generated. Has anyone of you been in this situation? I've thought about manually creating each VPN but I'm missing most of the PSKs of the IPsec tunnels. Is there any known workaround or method to restore configurations? Thanks!
Team,I need a clarification on how this fortilink can be used. I have fortigate rugged series 70F model. It has 4 Lan ports and 2 WAN Ports with FortiOS 7.0.11. In my case, HA configuration is required. For this, 2 ports can be utilized. As per customer's requirement 16 Channels I have to consider in Rugged series firewall. Since it has port limitations thought of using Fortilink as port extension. Use cases:1. Whether these add on switch FSR-424F-POE will act as firewall.2. How this can be configured?3. How will this handle failover? Any inputs would be appreciated!!!
I do not care what format, it just needs to be better than the "full configuration" human-readable format. on a Juniper SRX , you can typeshow config | display XML job doneI need to get my hands on the Fortigate config in a similar format. I've googled it, and the GUI I'm looking at it does not seem to have the "export as YAML option. Is there a way to view the configuration in the CLI as XML or anything else?RegardsSimon PS also tried to post in this forum and failed. I get thisPost flooding detected (community received posts of a unique message more than one time within 3,600 seconds)It makes it impossible to post here, trying again after one hour.
I am migrating from a FortiGate 200F to another FortiGate 200F.I did the initial Logging and then created an admin password.then i used the restore function to restore the previous config to the new one.the issues now are that, I am not able to log in using the admin Login i created or any of the login credentials from the restored.Is there something else i should have done ?
Hello. We have an Active/passive cluster setup with 200F devices that interface with a redundant LAN network. During the setup there were issues with loops occurring that were blocked by STP in the LAN network. The cluster LAN interfaces on the firewalls function as a transit LAN with VLAN sub-interfaces below it for our network hosts.The network loops were mitigated by removing redundant links into the firewalls and the LAN network settings on the Ubiquiti switching equipment. We are not currently experiencing loop issues. But we are now trying to figure out how to fix the problematic setup to remove the STP loops and allow a redundant network.The root cause of the loops looks like software switches on the FortiGate LAN interfaces. Per this link (https://community.fortinet.com/t5/FortiGate/Technical-Tip-Building-redundant-paths-to-switch-network-from/ta-p/279038), they are identified as not participating in STP. And the software switches are also not monitored if a LAN inte
internal DNS to access some of our internal services this used to work though, and today it doest .... what could have changed? Behind a Fortinet SSL VPN
I just ran the FortiClientInstaller for the VPN-only client, and it crawled for at least 40 minutes on a very good connection. What is this thing doing, and why? I see no excuse for not simply posting a disk image.
We have the google FQDN's opened per their suggestion ( https://support.google.com/a/answer/2589954?hl=en ) and ( https://support.google.com/drive/answer/6163291 ) the kids have discovered a number of gaming sites on google homepages, all seem to be named "unblocked games" i.e.https://sites.google.com/site/unblockedgames4mehttps://sites.google.com/site/unblockedgames77https://sites.google.com/site/punblockedgames/ The problem is that blocking google by address doesn't seem to work as every request seems to use a different one, and I don't know why but I don't seem to be able to block by name. I put in a simple IPV4 policy, source = any, Destination = "sites.google.com/site/unblockedgames4me", blockand it doesn't work. because it is a block there is no SSL inspection or anything like that.... When I look at the log there is nothing that says "sites.google.com/site/unblockedgames4me" just "encrypted-tbn1.gstatic.com" but I don't want to blo
I am using forticlient.forticloud.com/ems Version 7.4.3 build1926. I have deployed FortiClient 7.4.3.1790 to my endpoints. I haven't found a way to access my on site DC.
Hello team, I have seen this before, but did not care, however now I need to solve this.Yesterday I have tried to upgrade 2 Fortigates 60F, from 7.4.5, to 7.6.3The recommended path is 7.4.5 -> 7.6.1 -> 7.6.3I could reach 7.6.1, by uploading manually the file, but when I tried to upgrade from 7.6.1 to 7.6.3, this option was not possible in 7.6.1. I dont have any option to upgrade from file now.I tried to upgrade, following the upgrade wizard, but both Fortigates remained in "Downloading" for about 15 minutes, until appered as "Failed", no more information.I have tried this 3 times in each Fortigate, with the same issue.Both Fortigates 60F are in Argentina.Is this possible to upgrade from 7.6.1 from a file?Is there a way to avoid the Fortiguard/Fortinet servers limitations during the maintenance window? Thanks in advance.Regards,Damián
Hi Fortinet Community, I want to add multiple DCs on FortiClient EMS. I tried this via GUI and failed. Does anyone have information on how to do it? Best Regards, İsmail Ürek
The fortigate firewall detected the attack OpenSSL.TLS.Heartbeat.Information.Disclosure? How do I block it?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.