Mark a Best Answer
Fortinet Community
Recently active
Hello, I need to send all quarantine mails every day to single recipient , I configured it at security-quarantine-quarantine report -quarantine report recipient setting , but no mails the recipient received, Could you help me for these steps?
Hi!So i have an HUB&Spoke topology (OS 7.4.6), the 2 HUBs have only 1 link each meanwhile Spoke has 2. Everything seems working fine, i receive the BPG adv from spoke and viceversa until i try to shutdown one of the WAN link on the spoke side.So i have 4 tunnel configured on spoke side:WAN 1HUB1-VPN1HUB2-VPN1WAN 2:- HUB1-VPN1-2-HUB2-VPN1-2So when i shut the WAN 2 i still see that BGP is still sending its hello packets via VPN1-2 even if the Fortigate marked bot as "down". In order to make BGP use the other active tunnels, i had to disable VPN1-2 tunnels manually.Not sure where is the issue, but i attach the configuration of the sdwan section, maybe someone can help me figure out the issue. config system sdwan set status enable set fail-detect enable config zone edit "virtual-wan-link" next edit "WAN1" next edit "WAN2" next edit "HUB1" set advpn-select enable set advpn-health-check "HUB1
Hello, Is there a way to track the username from a session authenticated through SAML Azure IDP when accessing a specific VIP using Site Publish? Should the username be automatically received via Site Publish, or do I need to create a tracking rule for this purpose?
How do i enable 2FA for my FAZ 300G using firmware 7.2.xx ?what are the type of 2FA i can use ?
FortiClient - DisconnectedZero Trust Fabric Agent Register with Zero Trust FabricEnter Server address or Invitation code:Connect
HiI use Fortigate 101F with v7.0.12 in TP mode, but broadcast drops occur.The configuration diagram is as follows.Normally, there is no problem and when I reboot the server, the communication between the PC and the server side L2 does not work.As a result of checking, the MAC address of L3 was not learned in vdomA.So I put the mac-address of L3 port2 into the mac-address-table of vdomA statically and it works normally. This doesn't happen very often, it happens very occasionally.I enabled broadcast-forward, why does this happen?
We have an AT&T ADI Circuit from AT&T. Example of what we have been given from AT&T (this is not our actual IP info, just an example). CR Serial IP Address: 12.246.190.66/30AR Serial IP Address: 12.246.190.65/30Wan IP Address: 12.246.190.64/30IPV4 Block: 13.220.245.96/29Usable IP Range: 13.220.245.98 - 13.220.245.102 We have given our WAN1 interface the 12.246.190.66 IP. We have a static route that points traffic to 12.246.190.65. I can ping the 12.246.190.65 from WAN1. What I need to do now is NAT traffic out 13.220.245.98. How can I accomplish this? Many thanks.
Just upgraded the fiber at the carrier ONT from 150 Mbps to 500. But the Fortinet 60F is only delivering 70 Mbps down and 50 Mbps up on the user side. Additional info: the connection from ONT to the firewall is an existing Cat5e shielded cable.
I use FortiGate to create Authentication for my local user. I create a policy for it, add user group in that policy. It works well for the past 3 months. Suddenly, last week everyone cannot access authentication page and unable to use internet under this policy. Why? And after I try to put user group out of that policy, everyone can access internet but didn't have to pass the authentication. I want to add user group into policy to force everyone to login through authentication. How?
Anyone here have experience with Fortigate products? How do they compare to Checkpoint in terms of performance and reliability?We have Checkpoints currently and have been running into performance and reliability issues (particularly when the Infosec team goes crazy with their vulnerability scans, but also from DoS attacks from the web). The Fortigate salespeople claim they are the only ones in the space offloading traffic to ASICs. Is this true and does it make a difference in real life?
I'm unable to understand why my timezone is different on both FMG and Fotigate. I've checked all ADOMs and it is showing same timezone: IST under each ADOM despite timezone correctly mentioned in each fortigate firewall. I wonder it mean something else when used in FMG? or still it stands as Indian standard time? why its not showing BST? I've checked FMG system time and zone under settings and its correct so not sure what is the issue? Please can someone shed some light on this? Under FortiManager -> Device Manager -> Manage device and under System information: FMG timezone for the same FortigateSystem time showing e.g Fri Jul 18 12:58:50 2025 IST were on the same firewall when I am checking timezone its showing
I have my on going proof of concept with my FML and Google workspace. Everything went smooth as of writing.I am bit confuse with regards to licensing part. Here's the existing setup. EU has a root and subdomains. root domain: 500 mailboxes, only 150 mailboxes should be inspected by FML both inbound and outboundsubdomain1: 300 mailboxes, only 200 mailboxes should be inspected by FML both inbound and outboundsubdomain2: 100 mailboxes, 50 mailboxes should be inspected by FML both inbound and outboundsubdomain3: 100 mailboxes, 50 mailboxes should be inspected by FML both inbound and outbound Overall the FML cloud should be licensed for 450 mailboxes only. Now, how does the FML inspect emails accordingly based on the defined amount of mailboxes from root and subdomains? any help is much appreciated.
Hi I have FortiNAC version 7.4.1.0451 and Fortigate version 7.2.11. FortiAP 432F, SSID(traffic mode = tunnel) is using WPA2 ENTERPRISE and radius is selected pointing to the fortinac. Fortinac Winbind status is running and joined to the domain.I get access-reject error in log. radius not enabled on device.
I need to block the website www.pagalworld.com.se. I have already tried blocking the streaming media and download categories, as well as the bandwidth consumption group and override URL filter, but the site is still accessible. Please help me resolve this.
How to force SDWAN IPSec VPN Down when quota reachs its end - Starlink maritme 5TB quotaThe scenario: small office with Starlink+CG-NAT+DHCP, FG100, FortiOS 7.4 and remote office/DTC, regular ISP with static IPI have two Starlink antenas, with a 5TB/Month quota, something around 168GB/day.Besides that, the Starlink connectins are CG-NAT ones, with DHCP, so, not only the IP sometimes changes, but also, the NAT is under another NAT, so we need to use NAT-T on "forced" and also, use passive mode on remote datacenter, as I am using DDNS because the Starlink side needs it. (note: dial-up is not supported under SDWAN)Because of the number of users and devices, besides controlling very strictly the traffic, we still need to "cap" the in/out max bandwidht to around 20Mbps to make sure that the Quota is not reached before the months endsWe did several tests, when something happens with the link, antenna turned off, cabling problem, DHCP error, remote SIP lack of communication error, it triggers
I have done the configurations to SSO authenticate users with Microsoft Entra ID with Fortigate on SAML.I tried the Fortinet documentation and all the configurations were done as same.https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/33053/outbound-firewall-authentication-with-microsoft-entra-id-as-a-saml-idpOnce we attempt to authenticate, the user is taken to the authentication site (login.microsoft.com). After entering the user credentials, it will load for a long time without any response.
I have created an InterVDOM link on my firewall (7.4.7), and it can renew existing leases, but I canot seem to be able to get any config which will enable new leases to be obtained / givenThe topology is a remote site has a VPN back to HQ. The remote site has DHCP Relays configured, pointing to DHCP servers on the LAN. The setup works perfectly when routing the traffic from our VPN vdom to our LAN vdom over the internal switching. But once I try and route the traffic over an InterVDOM link, all traffic other than new DHCP leases work. As soon as I disable the policy routes, the DHCP and everything else works.
Trying to extend a VLAN via VXLAN between two FortiGate 200G units over an IPsec tunnel. ARP and broadcast traffic get through fine, but unicast (ICMP) doesn’t. ARP tables look good, VXLAN UDP (port 4789).Anyone dealt with a similar setup or have tips to debug?Want me to tailor it more for Fortinet pros or add some tags to get extra traction?
Hello TeamAm inquiring if any user has been able to set custom email notifications for the fortinac like Authentication failures or a connected device instead of using the default email .#Fortinac Email notifications
Hello All, Interesting thing this Policy-Based NGFW mode compared to the profile-based default mode. NGFW policy | FortiGate / FortiOS 7.6.3 | Fortinet Document Library I played a little and when for example you have rule that blocks ssl before a rule that allows Web Browser app then it will never reach the second rule as the app shifts after some time like I have seen on other firewall vendors that policy-based modes for app control. There should be an article how to see the application shift for a session for people using this mode, also a "diagnose debug" command as well for app control showing all the identifications for a session traffic like SSL > WEB Browser > SAAS app etc. As of now I think the default profile mode is better.
Hi Fortinet Community,I run a small business called Urban Timber Tree, which offers tree care services (like planting and pruning). I’m building a simple website to promote our services and products, but I’m worried about cyber threats like hacking or data theft. I’m new to cybersecurity and heard Fortinet has solutions that could help. I need advice on how to use Fortinet to protect my website.Here’s what I’m trying to do:- Keep my website (built on WordPress) safe from hackers.- Protect customer info (like names and emails) collected through the website.- Make sure my site stays online and runs smoothly, even if there’s an attack.- Use affordable Fortinet solutions since we’re a small business with a limited budget.My questions:1. Which Fortinet tools (like FortiGate or others) are best for securing a small business website?2. Can Fortinet help protect customer data on my website? How does it work?3. Is there a free or low-cost Fortinet solution for a small business like mine?4. How
Hi Team,We have integrated the FortiGate firewall with FortiClient EMS and are currently in the process of applying posture checks, specifically focusing on enforcing Antivirus (AV) software compliance on vendor laptops.The tags created within FortiClient EMS are being correctly pushed to both the FortiGate firewall and the FortiClient. These tags have been referenced in a firewall policy associated with remote VPN access. However, we are encountering an issue: when the VPN connection is established and the EMS tag is active, the destination resources become unreachable, despite the antivirus being installed and running properly on the vendor's workgroup laptop.We are testing on Azure IdP user and create a separate user for the vendor.Conversely, when the EMS tag is not applied, the destinations are reachable without any issues.Could you please advise what might be causing this behavior and suggest possible steps to resolve it?Thank you for your support.
Good day,after upgrading our 60E to 7.4.7 firmware we noticed that just at boot the memory usage goes 60% used.This has caused issues when it goes over 80% as all RDP session are dropped.If we reboot the unit, it starts at 60% How can I check which memory process is eating that?
Hello, We have installed an All-in-One FortiSIEM setup with one collector, and successfully migrated our old environment to the new one, including manual IP changes. The system is now operating normally.However, we are encountering an issue with agent installations. While we are able to install the Windows and Linux agents on some machines, the installation fails on others — even though they are running the same OS versions, are on the same subnet, and we are using the same installation scripts and configuring the collector as revers proxy.Could you please advise on how to proceed with troubleshooting this issue? The errors are as follow:Continuing with installation... Agent parameters validation failed. Please check if the parameters you passed to ./fortisiem-linux-agent-installer-7.4.0.0435.sh are correct and re-run the script with correct values. Please check if the registration organization, username, or password has errors. INSTALLATION FAILED
On my FG firewall I have defined MGMT as OOB / dedicated management, and the firewall is in L2 / Transparent mode. One interface PORT1 from firewall is connected to the switch VLAN-1 and MGMT on the same switch VLAN-1. In this case is there a possibility of L2 loops formation on Switch?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.