Mark a Best Answer
Fortinet Community
Recently active
I have some Reolink camera equipment on my network. Its all on the same VLAN (2 different switches), and it talks to each other, but the devices are showing the wrong IP. If I look in the Fortigate on the port the NVR is connected to for example, it says its IP is totally different than what shows on the NVR when I go into its settings. A different subnet even, as the FG says 10.x.x.x but on the device it says 192.x.x.x. Now I imagine this is just the device’s internal network it creates perhaps. But its the same thing for the cameras which are connected directly to a fortiswitch. And if I look at their mapping from the NVR, they all show the 192 addresses as well which is at odds with the VLAN they are on and what the FG tells me they should be. It all wouldn’t matter except for one problem. I cant connect to the NVR or cameras externally. There is a firewall rule present that allows that VLAN to go out to the internet, so I’m not sure what the problem is. If I manually change the NV
Hi , I am trying to understand what is the purpose of the configuration :EMS CA Certificate (ZTNA) under EMS Settings.Is this supposed to allow EMS administrators to install a CA certificate onto the users device CA bundle?
Hello, I am wondering if it's possible to manage AP's without a fortiswitch? Company just bought a Fortigate to be used but they are sticking to the old Entrasys switch. I have it connected but it keeps using the main internet (10.1.1.x) and I am unable to find where to assign the proper VLAN tag for it. It needs to go to on the (10.1.2.x). Old switch has the proper VLANs tagged, now I just need to figure out how to get the AP to use the right VLAN.
Hello Fortinet Community,I am currently deploying a new FortiGate and would like to clarify the recommended approach for remote access.I have read that SSL VPN tunnel mode is being deprecated/removed in newer FortiOS versions or on certain FortiGate models. Could you please help clarify the following?Is IPsec VPN now the recommended/supported option for remote-access VPN? Is there any official Fortinet documentation explaining the changes to SSL VPN tunnel mode? From which FortiOS version and/or FortiGate models does this change apply? For an existing or new deployment, should we now prioritize IPsec VPN with FortiClient instead of SSL VPN?Additionally, regarding ZTNA, I understand that it can be used to provide more granular access to specific applications/resources instead of providing traditional network-level VPN access.Does implementing Fortinet ZTNA require any additional license or FortiClient EMS subscription, or are there ZTNA capabilities already included with the FortiGate/F
Hello. I have some Ubuntu 26.04 servers configured in FortiPAM. When I set up Web-SSH access, I enable the "SSH auto-password" option so that FortiPAM can pass the password when I connect and need to run a "sudo" command. The problem is that with this version of Ubuntu, FortiPAM does not pass the password.
I upgrade our fortigate to v7.6.7 and after upgraded then the web admin gui if use mgmt ip address can’t be accessed from advpn, only can be accessed from local site and from hub only. If i using lan ip (not mgmt) then i can access. Anyone know why?SSH to the both port (mgmt and lan) is working fine.
# Why You Can't Add DDNS to an Existing IPsec Tunnel — and What to Do Instead**Environment:** FortiGate-60F (FortiOS 7.6.x) and FortiGate-30G (FortiOS 7.4.12), site-to-site IPsec, route-based.If you built a site-to-site IPsec tunnel with a literal peer IP address and later needed to switch it to a DDNS hostname, you have probably found that FortiOS accepts every command you type and then discards all of it at commit. This article covers why that happens, the field-naming distinction that causes most of the confusion, and two ways forward depending on whether you can take an outage.---## The scenarioTwo FortiGates, site to site. One side holds a static public IP. The other is a home or branch office on a DHCP-assigned public address from the ISP.The tunnel was built with the peer's current address entered literally:```config vpn ipsec phase1-interface edit "VPN-TEST" set type static set remote-gw 203.0.113.117 ... nextend```This works. It keeps working right u
I need to move my FMG and FAZ from VMware to Hyper V. I am moving from version 7.4.11. I am assuming I can just install the template machine in Hyper V and just export/import the configuration. I will be keeping all of the same IP addresses. Am I overlooking something or will this be straight forward?
We currently have a provisioning template set for a FortiGate, however some updates were done on the actual firewall’s configuration. Mainly for connecting it to FortiClientEMS and Authenticator. Then adding a few new Policy rules. Is there a way to import the updated configuration into the FortiManager as a new provisioning template? Thanks!
What's the best way to get back in? It's a Gateway, 7 switches, and 65 APs. I've asked the client who sold them the gear it's been through the hands of 2 MSPs and no one seems to know passwords. Transitional passwords between the last 2 MSPs (not ours) are not right.I want to work veryhard to make sure we don't brick this stuff and get into a mess.It's newer gear, so unlikely the maintainer account is still in place on this firmware.How do we go about getting access back/proving ownership to Fortinet?
ENVIRONMENTFortiOS: 7.6.x (FortiGate 120G)FortiClient EMS: 7.4.x (FortiCloud SaaS)FortiClient: 7.4.7 (Windows)Authentication: IKEv2 EAP-SAML via Microsoft Entra ID---ISSUEFortiClient endpoints managed by EMS fail to complete IKEv2 IPsec VPN tunnel establishment after successful SAML authentication. The EMS-managed client sends an EAP NAK (type 08) in response to the FortiGate's EAP Identity Request, causing the FortiGate to tear down the IKE SA with 'unexpected payload type 41'.A non-EMS-managed FortiClient with an identical manually-configured tunnel connects successfully every time. The failure is specific to EMS-managed clients.---FORTIGATE IKE DEBUG (EMS-MANAGED CLIENT)The sequence on every EMS-managed connection attempt: responder received AUTH msg responder preparing EAP identity request responder received EAP msg unexpected payload type 41 schedule delete of IKE SA connection expiring due to phase1 downThe client response decodes as EAP type 08 (EAP NAK) — the client is re
On HA enviroment for FNAC with shared IP Address then we need to configure both FNAC IP to tghe switch as Radius Server and CoA? The shared IP only for FNAC mgmt only?
FortiEMS 8.0 managed FortiClient 7.4.7 using FortiTokken.after first time enter user and password details it don’t ask again user credential only fortiTokken.But as per compliance i have to configure like fortiClient ask everytime user password .i already disable the option save pasword and auto login. still same and in fortiClient (Save login) grayed.
Hello everyone, Is it possible to bypass DNSBL for certain IP ranges at FortiMail ? If we enable DNSBL using spamcop, lots of legit messages are blocked if sent from a shared SMTP clients that are temporarily blacklisted (such as *prod.protection.outlook.com and others). We get so many complains that we had to disable DNSBL.I guess we are not the only facing this problem because it seems to be an obvious problem. If a spammer sends spam using example.prod.protection.outlook which is used by thousands of legit organisations, if we discard all all messages coming from that example.prod.protection.outlook, then we are labelling legit messages as spam, and that's a problem.Can anyone recommend a workaround o a differnt approach maybe? Thanks for your help.
I forgot the password of my FGT 300C thats why I needed to reset the password via cli using the ff commands. However I got an error " User must have a profile object set operator error, -56 discard the setting Command fail. Return code -56" how to add profile for admin? Welcome ! New_FG300C~ # config system admin New_FG300C~ (admin) # edit admin new entry ' admin' added New_FG300C~ (admin) # set password password123 New_FG300C~ (admin) # end User must have a profile object set operator error, -56 discard the setting Command fail. Return code -56
We have on-prem FortiClient EMS server (7.2.x) which is an application that runs on a Windows Server. It does not appear to support SNMP. Other than just ICMP , any suggestions on the best way to monitor the EMS server?
have a FG 70G 7.4.12 and a windows client with free VPN 7.4.3.4726I have followed the doc:https://docs.fortinet.com/document/fortigate/7.4.12/administration-guide/785501 but when I try to connect, the client says “Timeout while connecting” I have diagnose sniffer packet wan1 "udp and port 500" running, and see 4 packets every time I try to connect like:19.844532 1.247.132.25.1012 -> 214.153.140.239.500: udp 668The odd part (to me) is that I do not see anything in the GUI System Events > VPN Logs >Memory.I’ve made sure the proposals match on both sides.I’ve done this before multiple times on 7.2 and older, and never had these kinds of problems.Any suggestions?
After upgrading our FortiGate device from FortiOS version 7.6.6 to 7.6.7, users at the branch lost internet access when the BambiDeep SSL/SSH Inspection profile (Deep Inspection) was used in the firewall rule.Traffic is allowed by the firewall rule, and NAT is working properly. However, HTTPS connections fail when Deep Inspection is enabled.As a temporary solution, we changed the SSL/SSH Inspection profile from BambiDeep (Deep Inspection) to Certificate Inspection, and internet access was immediately restored. The first rule includes certificate inspection, and internet access works fine, but the second rule is the old one and includes “BambiDeep” SSL inspection; after the firmware upgrade, internet access is not working. Also ı tested the problem on new rule by adding BambiDeep SSL inspection ant internet acces is not working. Are they any known issue about 7.6.7 version for tihs topic ?
Previously, with FortiClient version 7.2.13, when users initiated the VPN connection using SSO, FortiClient automatically detected the existing sign-in sessions for the customer's corporate accounts. When the authentication window was displayed, the available accounts were presented for selection, allowing users to authenticate without re-entering their credentials.However, after upgrading FortiClient to version 7.4.3, this behavior has changed. When using FortiClient's embedded browser for SSO authentication, users are always prompted to enter their username and password. The embedded browser no longer detects existing Microsoft Entra ID (Azure) sessions or displays the available signed-in accounts.On the other hand, we have verified that when FortiClient is configured to use an external browser for SSO authentication, the expected behavior is observed. The external browser correctly detects the existing Microsoft Entra ID (Azure) sessions, displays the available corporate accounts,
I have recently installed a HA pair of FG-71G (v7.6.6). The standby firewall shows the interface status changed as shown below, but there is no log at the switch / firewall the ports connected to. The interface counter seems normal for both sides. I have already replaced the physical cables but problem persists. Any idea if it is a firmware issue or the firewall is faulty? Thanks.
how to delete synced ztna application
I need to configure our environment for both single and multi-user, domain and workgroup (personal) computers.. Ideally we want absolutely no user interaction required for the shared domain pc's, at any point. These are EntraID or hybrid-joined, managed by Intune. They don't need different configuration profiles based on the user login, although we would still want to track who is logged in of course. However, auto-registration appears to only occur once during initial installation. When another user logs in, FortiClient reverts to being unregistered for that user, requiring them to enter an invite code. I would have thought it would attempt auto registration again and perform SAML user verification automatically, but it does not.We need to keep the shared devices as free from user interaction as possible, while still securing against rogue installs. Is there a different way to go about this?
We are configuring SAML authentication on our FortiGate firewall to authenticate users before applying internet access policies.Our requirement is:The first firewall policy should only trigger SAML authentication.After successful authentication, no services should be accessible through this rule.Once authenticated, subsequent policies should apply access rules for the authenticated user/group.To achieve this, we created an authentication-only policy with the following configuration:Source: allDestination: Internet ServicesInternet Services used:Microsoft-AzureMicrosoft-Azure.Front.DoorMicrosoft-Office365.PublishedAfter applying this configuration, SAML authentication works correctly when the authentication process is triggered.However, we are facing the following issue:When users open a browser and try to access Microsoft-related services (for example: office.com, outlook.com, etc.), the SAML authentication page does not appear.The browser waits for some time and eventually the webpage
We need your urgent assistance in troubleshooting an issue with our ADVPN deployment.Network Topology1 Data Center1 Head Office6 Branch Offices (Total: 8 locations)We have configured ADVPN for Hub-to-Spoke connectivity. Initially, each spoke had a single leased line, while the hub had dual leased lines. Two Hub-to-Spoke IPsec tunnels were established from the hub side, and the spoke had a single ISP. This setup worked without any issues.Recently, we added a second leased line at every spoke site for redundancy. Now, each spoke has dual ISPs, and both Hub-to-Spoke IPsec tunnels are established successfully. Routing is configured using loopback interfaces over iBGP.Issue DescriptionThe issue occurs only when the old ISP at a spoke goes down and traffic fails over to the new ISP.Although the IPsec tunnels remain UP, Hub-to-Spoke communication becomes unstable. During failover, we observe the following behavior:Sometimes the spoke loses reachability to the Data Center Hub, while the Head O
We wanted enable auto backup of Fortigate firewalls from Fortimanager to FTP server.Please guide.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.