Mark a Best Answer
Fortinet Community
Recently active
Hello Fortinet Community, My FortiProxy-VM64 has a very typical memory utilization (printscreen below). It seems that the memory keeps increasing for periods of 6 months approximately until around 80% and then it decreases abruptly to 25%.I do not do any periodic maintenance like reboots, cache cleaning or something similar. Is this kind of memory utilization normal under typical load? Also, could you please advise what are the recommended memory usage thresholds to watch for? Thanks in advance for your help!Best regards
I'm due to upgrade Fortigate 81F v7.1.15 to v7.2.10. There are Forti AP's currently connected to the Fortigate and they are running on v7.0.0. If i upgrage the Fortigate will it affect the Forti AP's in terms of connectivity? What is the upgrade process in this regard?
Hello , I have this issue my security rating in fortigate detect critical endpoint ,do any suggestion to block this issue and conection, how to preventive to resolve this event and log security rating so clean detetection Thank you
Hello,For a long time, I have been experiencing a problem with a sticky DNS configuration on the FortiClient SSL VPN network card in Windows. I need to have administrative rights to modify the network card and delete the VPN DNS entries in order to access the network on my LAN.The behavior is not always the same, and the FCT version is 7.2.8I have already found a knowledge base article on this subject:https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiClient-Sticky-DNS/ta-p/279430I would like to know if anything has changed or if there is anything I can do to fix this issue.Thank a lot
This is a strange one. I have a bastion host running Rocky Linux 9 configured to auto logout users after 15 minutes of inactivity. When I VPN in with SSL VPN or IPSec and then login to this bastion host I am logged out after 15 minutes just as expected. However, when I setup the host so I can connect to it via ZTNA SSH Proxy the auto logout feature does not work. I have found the session still active 12+ hours latter. I do not think I created a keep alive feature any where. Has anyone else had this issue?
SSL.Anonymous.Ciphers.Negotiation some time my fotigate detect event SSL Anonymous Chiphers Negotiation Is there any alternative way to block and eliminate this event from the FortiGate logs?"
Hello! FortiMail 400F version 7.0.9 here. This FM is associated with a FortiSandbox solution. Under Archive Handling, we have Check archive content > Detect password protected archive enabled in our content profile. According to this article, this is supposed to be enough for FortiMail to detect pass-protected attached files and block them, but we find way many true positives slipping by. The attachments are mostly zip, 7z, tar files, and the passwords aren't usually included in the body of the message. I mention the FortiSandbox because every attachment gets sent to it and analysed while FortiMail waits for a result in order to deliver the email. FortiSandbox can't unzip it, TAC said it's because its password protected, it gets a clean verdict and thus sent through. We're beginning to suspect that FortiSandbox is interfering with FortiMail's actions somehow. Are there any additional settings we can apply before looking into fortisandbox? Thank yo
Hi, Need your recommendation on how to block this. Just making sure that this is not configuration issue. Environment:App with login, register, and upload function. All are using JSON but with GUI.FortiWeb with JSON Protection Policy and Signature Detection enabled.File Security and WebShell Detection enabled. PHP file extension not block. For both login and register function, if we were injecting malicious payload, they will be blocked. no issue here. refer screenshots.login and registerblockedattack-log For upload function, Anti-Virus works well. Test upload an eicar.zip file was blocked.However, for WebShell upload like oneliner or c99, these files was not block.response-successreturn 200Same file was blocked if not using JSON upload.blocked So far i notice that file uploads rule, it ask for json setting. However for WebShell detection, no such thing.json setting Any thought on this? Thanks and regards,Muhaimi
hello, I am taking over the management of a FG101F Cluster with 7.2.10 and 4 Interfaces WANs. Tha actual situation of the SD WAN is kind of messy:> Virtual WAN Link with 2 x 1GB Internet Access lines> UPG Zone Port 4 with 1 x 1GB Internet Access> UPG Zone Port WAN with 1 GB Internet Access I would like to use 2 x Internet Access volume based Load Balancing and the other 2 lines exclusively for the VPN connections and SSL VPN / IPSec. So I would change all Policy with the WAN Interfaces with Port X to get them out of the actual situation and than start over with Virtual LAN and under that my SASE with Internet A and internet B leaving Internet C and D out of the load balancing. What are you suggestions, what woluld be the best configuration and whats the best way to do so. Thanks!
Hello ,I want to backup the History and mail logs data at remote windows server at another domain but same organization , Open connection port at firewall & write the bellow info , But It gives me "failed to mount" ?? why do that and how I solve it??
I still do not know what this "FQDN Group" on our fortiproxy means (when assigning new address)?I know what FQDN does, but FQDN group?When clicking on the "Online Help" button, I just see FQDN, there is no explanation for "FQDN Group".
Hi Team, While I am trying to make a custom parser for Windows/any other device type while using the convertHostNameToIp function with setEventAttribute, validation shows failed.Full function is below:<setEventAttribute attr="srcIpAddr">convertHostNameToIp($_saddr)</setEventAttribute>Below is my custom parser for testing. While testing with other functions like resolveDNSNameAll other functions are working fine except convertHostNameToIp. Please give me any suggestions for this issue.Below is my custom parser.Validation failed: convertHostNameToIp<eventFormatRecognizer>TMSSQLSERVER</eventFormatRecognizer><parsingInstructions><collectAndSetAttrByKeyValuePair sep=" " src="$_rawmsg"><attrKeyMap attr="hostName" key="Host: "/></collectAndSetAttrByKeyValuePair><setEventAttribute attr="srcIpAddr">convertHostNameToIp($hostName)</setEventAttribute></parsingInstructions>Validation is pa
Hi A customer of mine grants me access to his network using forticlient. I installed the Ubuntu version using the official repos from here https://www.fortinet.com/support/product-downloads/linux Now I'm getting this error message FortiClient SSLVPN is unavailable: FortiClient VPN trial has expired.Please contact your administrator or connect to EMS for license activation. Looking in other threads (https://community.fortinet.com/t5/Support-Forum/Forticlient-free-version-expires/m-p/231) that I need the "FortiClient VPN" only. However I don't know how to get that. I've found this article https://docs.fortinet.com/document/forticlient/7.2.2/administration-guide/666761/linux but I'm not sure how to get any of these files. I'm able to log in support.fortinet.com, but if I go to Firmware downloads, I only see a blank list and the error message Sorry, you don't have any product covered by a Fortinet support contract. Where do I get
Can a Cisco C9300L-48P-4X switch be used to fully power a FortiAP 441K via dual PoE sharing, or can dual PoE sharing be accomplished via FortiSwitches only?
Hello,I currently hold the Fortinet Certified Professional – Administrator 7.2 certification, which is valid until December 2025.According to the current certification system, to become a Fortinet Certified Professional (FCP), I need to pass (complete) the administrator exam and complete one additional elective, such as the Forti Client EMS (elective).I read that the certification system will change in October 2025, reverting to the NSE 4/5/6/7 model. If I earn the EMS certification before October, I will receive the FCP certification under the current system. If I earn the SD-WAN certification instead of the EMS certification, I won't receive the FCP certification. Will the certification be valid after October? Currently, if I earn the SD-WAN certification while also earning the Fortinet Administrator 7.2 certification, I won't receive the FCP certification. If I earn the SD-WAN certification, will the validity period be extended? Thank you. #https://www.forti
I have two fortiweb devices (Fortiweb-4000f andFortiweb-3000F ) and both have different Version 7.4.7 and version 7.4.4 ) when I need take backup for web protection profile form one box and restore it of another box it is applicable or not?
Hello. We have 3 public ip addresses and 2 web servers. I would like both to be behind the FortiGate but I want to make sure I set it up properly. From what I understand, I am not supposed to use both WAN interfaces and instead I am supposed to assign multiple ip addresses to one interface. If it matters, one of our ip addresses is on one subnet and the other two ip addresses are on a separate subnet. Ideally, the two webservers would use the single ip address and one of the other two. The only reason is that the dns records already point to these two and i don't want to change them if i don't have to. But if it's easier or better to use the two ip addresses that are on the same subnet, I can update everything as needed. I will still be using the same Fortigate and internet connection for all the devices on the network as well. What all do I need to do to set this up properly? Let's say the following: Public IP address info:Static Ip 123.45.25.105Gateway 123.45.25.254Subnet Mask 2
I am using FortiManager v7.6.2 build 3415 (Feature)I would like to block a website named scribd.com .I created url filter and profile under Policy & Objects > Advanced > webfilter> Profile > Create Profile (name Office URL) - attached ID 14 under - Web > Urlfilter-table > ID 14then I created url filter under Policy & Objects > Advanced > webfilter > urlfilter > Create ID > 14 > block as ( *.scribd.com < wild card.Then I attached these under Policy & Objects > Policy Packages > FG Traffic > Office Traffic > Webfilter > attach Office URL profile .There are no rules above on the Office Traffic.The SSL method currently using is -named : no inspection - but - Inspection Method is Full SSL InspectionCA Cert : Fortinet_CA_SSLI did Install Wizard under Device manager and choose FG TrafficI do have License for Webfilter I cleared cache but still cannot block the web page.Should I change the SSL no-inspection to custom-deep-i
Hi All, Looking for wisdom, tips or links (in this forum, tech tips, KB articles, or more general as appropriate).Please forgive my lack of knowledge on this topic.I do know other things. We use Fortigate firewalls heavily in our field network with quite a few site to site IPsec tunnels, typically used to encrypt the link and/or tunnel OSPF. We also have many field devices connected via a cellular network with a private APN. In the olden days the mobile endpoint could only port forward onto the local LAN. For convenience every local LAN is the same subnet. There is typically only a single device on the LAN, but some sites have a small number of devices which each get their relevant port forward (industrial protocols and ports).We have upgraded the mobile endpoint hardware and now have dramatically expanded and improved functionality, including IPsec, much improved ACLs, OSPF etc etc. This toy can do nearly anything it seems.We already have a working site-to-site IPsec co
Hello, we have a VPN set up between Europe and Colombia which works OK. The office in COL just moved to another city and we just had to change the IP in the VPN. One thing, when I checked the public IP there with a remote PC I get information about a IPv6. The local ISP did not respond sofar but in my VPN configuration i stll have IP Version IPv4 and it works as before. What does it mean changing to IPv6? Can I just leave it as it is? Thanks!
Please help to advise this setting can work or ? config firewall addressedit "UNC3886-C2"set type iprangeset start-ip 45.32.12.34set end-ip 45.32.12.34nextendconfig firewall addrgrpedit "APT-Blocklist"append member "UNC3886-C2"nextendconfig firewall policyedit 100set name "Block APT C2"set srcintf "any"set dstintf "any"set srcaddr "all"set dstaddr "APT-Blocklist"set action denyset logtraffic allset schedule "always"set service "ALL"set match-vip enable ← if blocking VIP or incoming trafficset position 1 ← ensures this deny rule comes before any broader allow rulesnextend
Hi everyone, i've downloaded a fortigate VMware Appliance (v7.2.4) and want to run it in permanent trial mode as described in the official support article: Permanent trial mode for FortiGate-VM | FortiGate / FortiOS 7.2.4 (fortinet.com) When i try to activate the evalution license over the https interface, i always get the error message: "Error downloading license: Invalid serial number".When i try to activate the evaluation license over console, i get the error code 61 - "Failed to download VM license".I'm using a new and never before used fortigate account (with a new mail address) and the vm has full internet access ("execute ping google.com" from the console works).Do you have any idea, what the problem could be?best regards,Hannes
How do i enable 2FA for my FG401E using firmware 7.2.xx ?what are the type of 2FA i can use
If we go to ipsec monitor we can see the active ipsec tunnel and for every tunnel there are incoming and outgoing data traffic.My question is in the incoming and outgoing data there are bar indicating the traffic. How much data in incoming or outgoing data so the bar will full?The outgoing data 269.24GB the bar maybe only 25% from full, so what calculation to determinte the full bar?
We have one Fortigate (well, 2 in a HA failover setup). We've had just one ISP, but are adding another fiber provider and a cellular one.For years, our FortiClients have connected to our one IPSEC VPN (HQVPN) which is on the port Spectrum comes in on.So what is the better way to add these additional ISP's? We plan on using the cellular one mostly for remote FortiExtenders - no more campers on the interstate catching on fire melting the fiber taking us offline :) But we'd like the end user to be able to connect via either fiber ISP.Do we just need to clone our HQVPN and bind the new copy to the port for Conexon? And then just push out the second option (HQVPN2) out via FortiEMS to the FortiClients? This could help because we do have some users who their path to us has issues and would allow them to switch if that became an issue. Do we need to adjust anything else on the VPN settings?Thanks. Figured it'd be better to ask first before testing!
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.