Mark a Best Answer
Fortinet Community
Recently active
Hi all, Recently I've noticed that IKEv2 VPN connections from Europe to FortiGate boxes in the U.S. no longer work. In the past, one could use SSL VPN to get around this issue, but with all the problems using SSL VPN and it being phased out, what are folks using as an alternative? Thanks
Hello,we would like to try FortiDeceptor and FortiData.We have XCP (XEN) as our hypervisor. I see that ESX and KVM are hypervisors supported by Fortinet for these VMs. If I can import the VM for the KVM hypervisor in XCP, will the service still be supported by Fortinet?Or any type of support, does it decline? Thank you, Alex
I need to place some cloud servers inside a DMZ;The topology is 2 fortigates in different locations;each unit has 2 ISPs;The question is, do I need to create 1 DMZ for each ISP?How would I make this DMZ to use the 4 ISPs?
I'm looking for a way to create a Threat Summary Report. The audience is more business focused or executives not technical. Has anyone had success in doing this with FortiSIEM?
Hi everyone!I'm facing a specific need and would appreciate some help to understand the best way to configure this in FortiGate.I need to completely block internet access for a specific IP range, and then allow access only to certain websites as needed.Currently, I'm handling this using a Web Filter with the URL Filter option. Within the URL Filter, I have a rule that blocks all access, and above it, I add the URLs that need to be allowed. This Web Filter profile is applied to a firewall policy for the range.This setup is working fine to allow access to sites for the entire range, but now I need to allow a specific site for only one IP, without affecting the rest of the IPs in the range, which must remain blocked.My question is: what’s the best way to implement this kind of per-IP exception using Web Filter, without affecting the general rule that is already working for the rest of the range?Thanks in advance for any help!
Hi all,I am trying to remove two obsolete objects( see https://community.fortinet.com/t5/FortiGate/Technical-Tip-Obsolete-Microsoft-Teams-ISDB-objects-in-debugging/ta-p/362107 )FW1 (internet-service~ame) # show | grep Microsoft-Teams.Published.Worldwideedit "Microsoft-Teams.Published.Worldwide.Optimize"edit "Microsoft-Teams.Published.Worldwide.Allow" When deleting I get an error:FW1 (internet-service~ame) # delete Microsoft-Teams.Published.Worldwide.OptimizeInternet Service default entry Microsoft-Teams.Published.Worldwide.Optimize could not be deleted.command_cli_delete:7024 delete table entry Microsoft-Teams.Published.Worldwide.Optimize unset oper error ret=-651Command fail. Return code -651How can I resolve this ?Background info : Firewall OS was at 7.2.7 we upgraded via 7.2.9, 7.2.11 to 7.4.8MBoth objects are not being referenced anymore.
Hello,i have a strange behavior. We have a nextcloud in a DMZ. The DMZ uses a 192.168.x network and a Virtual IP on the WAN is configured for the Nextcloud. From the LAN we access the Nextcloud with the 192.168.x address directly. When trying to uplad a file from WAN that is larger than 100 MB the upload freezes at perhaps 10%. When uploading a 99 MB file the upload works with no problems. When uploading from LAN, i'm able to upload files larger than 700 MB without problems. So in my view it can't be a problem with the Nextcloud. I'm trying to upload from my home and i'm at the same provider, i have only 5 hops to the destination, but from other sources have the same problem. What can i check on the Fortigate, to search for the source of this problem? I have done already a packet trace and a debug flow trace, but here i wasn't able to see a problem, only that the packets stops after a few sec. Thank you!
Hi,I tried to restore an image from an http server withexecute restore image url http://192.168.1.100:8844/firmware.outand it does not work. (according to help the FTP protocol understands the syntax <ftp server>[:ftp port]) I don't even see a connection attempt when monitoring it with tcpdump on the webserver. I can however download the file on my pc with firefox. (FGT, Webserver & PC all in the same network)For test I activated port 80 on the webserver and thenexecute restore image url http://192.168.1.100/firmware.outworks. So it looks like it only works when the server runs on a standard port.That's fine for the test, but we won't be using standard port, so Is there a way to make image restore work using an alternative webserver port?(The idea behind it is that we can not get the image from an internal server which is accessible only via an IPSEC tunnel. Therefore we need to use a server on a public IP which does not run on the default ports)Kind regards,Tonny
Can we restore the disk structure extended with LVM?
Dear Community, i need to block the access of some specific URL e.g. www.example.com/ecp. i need to block this URL for external users when they hit this URL. My fortiADC is working as reverse proxy. The network flow is External user --> Internet--> Edge Firewall ---> FortiADC --> Virtual servers--> Real servers. Can anyone help me to block this URL for external users. Thanks
Fortinet made a change to their FortiOS API get /api/v2/monitor/virtual-wan/members call from version 7.4.* onwards which changed the response. We're making this call to a device running 7.4.8 (via the FortiManager proxy but hopefully that shouldn't make a difference) and the response we're getting is missing the Interface string.{"result": [{"data": [{"response": {"build": 2795,"http_method": "GET","name": "members","path": "virtual-wan","results": [{"link": "up","rx_bandwidth": 17698,"rx_bytes": 10694535825,"state_changed": 1753381417,"tx_bandwidth": 19306,"tx_bytes": 2152017150},The documentation has a little red asterisk next to Interface, but no mention why or what it means: https://fndn.fortinet.net/index.php?/fortiapi/1-fortios/5140/1/virtual-wan/ Does anyone have any ideas how we can make the interface string appear please?
I am experiencing an issue with FortiClient VPN on a MacBook Pro M3. After successfully connecting to the corporate VPN server, I lose access to external internet services (e.g., Google, Spotify, and general web browsing), even though the VPN status shows as “Connected.” Below are the details for your reference: Environment Details:FortiClient Version: 7.4.2macOS Version: Sequoia 15.3Device: MacBook Pro M3VPN Configuration: IPsec VPNSymptoms:VPN connection establishes successfully.No internet access for external services (e.g., browsers, apps like Spotify).Internal corporate resources (e.g., intranet, servers) are accessible without issues.DNS resolution fails for public domains (e.g., google.com), but IP-based pinging (e.g., 8.8.8.8) works.Troubleshooting Steps Already Performed:Tested with IPsec protocol (issue persists).Temporarily disabled macOS firewall (no impact).Confirmed the issue occurs only when VPN is activeAdditional Information:No errors appear in FortiClient logs, b
I have fortigate firewall acting as wifi controller as well, my issue here is that when I perform manual HA failover or upgrade the firewall, switchover is not seamless and it take at least 5 minutes to switch services for secondary unit. configuration is active passive
Hello,We are attempting to establish a site-to-site VPN between two FortiGate devices located in Egypt and Kuwait. However, VPN traffic appears to be blocked on the Egypt side, preventing a successful tunnel from being established.Could you please advise if there is a recommended workaround for this scenario?We are also exploring the possibility of connecting each FortiGate device to a cloud-based service from their respective countries, and then enabling secure communication between them via that route.We would appreciate your guidance on feasible solutions or alternative configurations.Thank you in advance for your support.
Dear allI need some insights from you who have more experience with forticlients than I do. Our customer has a fortigate (7.2.10) with ssl vpn configured. Our customer offers ssl vpn connection to partners and suppliers of theirs. A few days ago one of the suppliers mentioned, that their new user can't connect to the ssl vpn.We figured out that they got the wrong password. Strangely, I wasn't able to see all the connection tries from said supplier. Only a few. Yesterday, we had a call - supplier, our customer and us. They exchanged passwords again, supplier tried conneciton. It worked.All logs on FAC and traffic logs on FGT were fine. Look marvellous. A few hours later I got a call "it still doesn't work".This time again - no logs in FAC and no traffic logs. We were able to do some live sessions and then I saw it.We received SYN packets from the supplier from their expected public IP, but FGT didn't reply (no ACK).The forticlient (7.4.3 - free, vpn only) in use from
Hello Fortinet Community,I’m working with a FortiGate 100F running FortiOS 7.4.7 (build 2731), and I need to apply specific firewall policies to a subset of internal devices—let’s say a group of VIPs or devices from a specific department like Marketing.In previous FortiOS versions, we used the “Devices and Groups” feature to group hosts based on IP, MAC, or other identifiers, and then target those groups within policy rules.I’ve now learned that this feature was removed as of FortiOS 7.0.1, as referenced in this article: :link: Technical Tip - Devices and Groups feature removedSince that functionality is no longer available, my question is: What is the recommended approach now in FortiOS 7.4.x to dynamically group devices and apply policies?I would prefer something that does not depend on user-based groups, as my use case is based on endpoint behavior or device identity, not user authentication (e.g., AD or RADIUS).Any guidance or updated best practices would be really helpful.Thanks i
I have the following scenario, Fortigate towards FortiSwitch 2048F in MCLAG, and access switches connected to both 2048F. I was able to configure MCLAG, and add 2 access switches without issue. Meaning GUI topology on managed fortiswitch is showing what is expected. But as soon as I add the 3rd access switch, the topology changes and one of my MCLAG interface went missing on the GUI as well as the MCLAG grouping. I am using 7.4.8 on FortiGate, 7.6.2 on FortiSwitch. I am only using the GUI on FortiGate to create all of this.
I'm currently facing network issues involving a FortiGate 200F (firmware version 7.4.8) and two FortiSwitches (models S548 and S458), both running version 7.6.2.Over the past three weeks, since upgrading the switches to 7.6.2, the network has become slow, intermittently unresponsive, and frequently disconnects devices.Additionally, when accessing the topology view, not all switch-to-switch connections are visible or properly displayed.
I have a FortiIsolator in version 2.4.7 build 1120 I'm trying to hook it up to my FAZ in version 7.2.10 build 1682 but I'm having problems after hooking the device up to the FortiAnalyzer.Below are the test already done: - Release compatibility between products (matrix rules). OK - Firewall policies enabled via Fortigate under my management, traffic ok enabled protocols list: ICMP, UDP/514 and TCP/514. OK - Routing between FAZ and FortiIsolator ping ok, routing is managed by my Fortigate where the above policies are also present. OK - FortiIsolator setting under LOG -> REMOTE SERVER Fault description See below the hook from FAZ to FortiIsolator the error found &nbs
I have integrated my fortinet with a syslog server... in case the syslog server goes down for say a day or two then will fortinet forward the historical logs to syslog server when it comes back online ? i can see that fortinet is retaining logs for the past 7 days in its disk i suppose but will be able to forward the retained logs to syslog server in case of a gap ?
I'm trying to test a user authentication by Domain user not success.Could help me to with it?https://community.fortinet.com/t5/FortiNAC/Technical-Tip-FortiNAC-Computer-Machine-authentication-by/ta-p/232010I need more information.
during installation EMS server on Microsoft windows sever 2022 installation fail and here is the message 0x80070643 fatal error during installation any one have a solution
Hi everyone,we tried to install FortiClient EMS 7.2.4 on our Windows Server 2019 Standard. Actually we have installed FortiClient EMS Version 7.0.13. We have previously performed a Inplace Upgrade from Windows Server 2016 to Windows Server 2019.When we try to update as an Administrator, it goes back at some point and says "fatal error".We use Microsoft SQL Server 2017, the ODBC Driver 17 for SQL Server. and Microsoft Visual C++ 2015-2019. Microsoft Docs says that the ODBC Driver 17 for SQL is compatible with Windows Server 2019.Our FortiEMS-Server is not a member of a domain and does not have restricted access to the internet, which should block the installation.For more information i saw the log files but there are a lot of logs and I can't find what's wrong. FortiClient docs said that it is not a problem to upgrade from 7.0.2 < to 7.2.4.Does anyone know this error?
Can we create a Site-to-Site IPsec tunnel using OSPF? So far I have only used static routes, So just curious if we can use dynamic routing protocols to configure IPsec Tunnel?
Hello Community,Please for your support.Just a brief explanation of the topology and the case at first. We have a NAC VM Cluster, in which we have enrolled our inventory switches. we want dynamic vlan assignment for the users, based on an the Role attribute that each user has ( attribute 60 = vlan 60). Switches has the respective AAA config and i can see on the NAC that the radius accept is sent when the user is connected to the port. Users have the supplicant configuration for the Radius authentication as well. Thing is that when the user connects on the switch, NAC does not assign any vlan dynamic as it should and it marks the port as down (not connected), on the nac gui even though on the switch side the port is still up and working on the vlan that it was. normal policies work as it should ( for instance vlan assignment on Cisco IP phones). Below some screenshots that may help The above case is when we try to connect only one device per port. When we have an ip phon
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.