Mark a Best Answer
Fortinet Community
Recently active
Currently, each router has two service providers (2) on each device. These infrastructures serve different tasks (Fortinet with operational functions and services on servers, and UDM, especially with Wi-Fi coverage).It will be possible to communicate via OSPF, for example, between these routers to meet specific company needs. They intend to have these in different offices, but not all of them have two networks (physically).
Hi guys !I'm facing an issue with requesting forticare trial license.First of all, i downloaded VM on Fortinet ressources.After that, I installed it and click on "Evaluation license" and then it worked nice.I deleted my VM and now i need to do another tests.So, I installed another time a VM and when I click on "Evaluation license" I have this message : " requesting forticare trial license proxy (null)I think the problem is i already used a trial license, is it possible to delete the first one and then i'll try to enable it on my last VM ?Thank you for your support.Regards.
Hello everyone,I'm currently experiencing an issue with FortiMail displaying the following error message "Deferred 454 4.7.0 TLS handshake failed"Here’s what I’ve checked so far:- The certificate is still valid.- TLS is set to "preferred" for outgoing emails, with TLS versions 1.3, 1.2, and 1.1 enabled.- FortiMail can successfully communicate with the internet (ping tests to Google servers and FortiGuard were successful).- There are no firewall restrictions affecting FortiMail traffic.I'm looking for any additional ideas or suggestions to help troubleshoot and resolve this issue. Has anyone encountered this before or have any recommendations? Thanks in advance
Hello everyone, I recently uploaded some images from Fortinet on my eve-ng, however, it turns on and seconds later it turns off, has anyone had this problem? I have other images that work from Cisco etc.
Is it technically possible to block specific Facebook pages (for example, facebook.com/examplepage) or specific YouTube channels (for example, youtube.com/channel/UC123456789) using FortiGate, while still allowing general access to Facebook and YouTube, in an environment where users access the internet via both computers and mobile devices?
Hi guys, Can i get some help here? This is my first experience with FortiSASE. I have 2 sites: 1 in NL & 1 in the USA + Remote users in NL, USA, and Bangkok)I'm planning to deploy 2 FortiGate in each site in Active Standby setup. Each FortiGate will have 2 internet uplinks.Would you please advise which deployment guide should I use? When checking the KB, i get lost!What i understood is that I've to create SPA tunnel to the FortiSASE and deploy BGP for routing. but in the KB there are so many types of deployments!The sites should be able to communicate with each other in a secure channel.The users should use the FortiSASE to connect to the internet.I would like to use the forticlient to access the fortigates via its management interface. I already registered the fortigates/licenses and chose 2 PoPs in Europe and 2 in USA. Thank you in advance. RegardsSaid I re
FortiADC Our developers have implemented an "auto-save" feature to a web application. using a javaScript function, whenever there is a change in the value of the fields, we write the values to the Cookie. This works as expected when we connect to the website directly to either of the two individual weblogic bypassing the ADC. But when we go thru the ADC, is not working.We don't know the cause, but the condition is that the page keeps refreshing causing all the fields to get cleared. From the logs I see that the Request from the same session is going to a different server. Is there something to check to debug this behavior?
Hi, Have a bunch of Fortinet switches and they all are connected fine via Fortilink with 1 exception. The setup looks like this for this exception, Fortigate --- Fortiswitch1 --- Netgear Switch ---- Fortiswitch2 I can no manage Fortiswitch2 though the fortigate. I have looked online for the last few days and cant seem to find anyone that has cracked this issue so im coming directly to the forums. Could someone explain what the configuration on the Netgear switch should look like please.
I have seen a few posts with the same title but nobody seems to have found a solution yet. Has anyone found a working solution to the issue where FortiClient will connect to VPN then immediately disconnect? We are using FortiClient with EMS, and if the user has auto retry checked it will repeatedly try to reconnect and fail. Sometimes I can force it to start working again by shutting down the Forticlient app and restarting the computer but I can't find any useful information in logs or debug info. FG is on 7.4.2, FC client is 7.2.3, and EMS 7.2.2 (which I plan to update to 7.2.4 sometime this week). If you have any solutions I appreciate it!
Current Setup:We are using Explicit Proxy on FortiGate with FSSO-based user authentication.Challenges Faced:Scenario 1:We are using N-Computing devices, where multiple users log in simultaneously. These users all share the same IP address.As a result, we are facing the following issues:Some users are intermittently unable to access the internet.In certain cases, user traffic is incorrectly attributed, leading to policy enforcement mismatches and access issues.Scenario 2:We have scenarios where a single user account is logged in on multiple devices simultaneously.This allows the user to access the internet from multiple devices at the same time, which is affecting the reliability and accuracy of user-based controls. Is there any solution to over come the above issue.
I am trying to connect to a fortigate 80E running 7.4.7 to roll back a software version but I am having difficulty connecting to the console during the boot process. I can connect to the console port via putty when the Fortigate 80e is booted and up and running. Putty is set to 9600 8 n n 1 But when the system boots, the system outputs odd characters until the boot process is complete, then I get the login prompt I read that the Baud rate changes to 115200 during the bootloader stage and then returns to 9600. However, I have tried changing putty to 115200 and rebooting and I still get garbled output.I have tried 9600, 19200, 38400, 57600, and 115200 but all output bad characters. I have also tried a FortiGate 60E, which has the same issue. I have also tried a FortiGate 90D at 9600 and this works just fine. What are the correct settings for an 80e running 7.4.7?What else can I try? I don't understand why this is so dificult
I need to create a VDOM (named it VDOM-A) which will operate in Transparent mode with two interfaces. I want to set all firewall management using Root domain on MGMT with out of band. Is it mandatory to assign an IP address to VDOM-A at any level? In L2 mode, can it operate without assigning any IP to it?
I am backing up one 60F to another, which successfully worked earlier this week. I made some User security changes so I created another encrypted backup file and when I tried to restore it to my offline 60F it crashes it. I have repeated the process and then when to trying to reload from USB the configuration generates all kinds of errors on reboot. The only difference in the 60Fs is my online one is running 7.2.11 firmware and my offline is 7.6.3. I haven't been able to get the down time to upgrade the online 60F. This process worked earlier.
I had Forticlient 6.0 installed in a Windows 10 VM for test purposes. (This is the VPN-only client without the other functions.) However after attempting to uninstall the program via "Programs & Features" it was still there despite no error messages from the uninstaller. Additionally, the option to exit in the Forticlient system tray icon was greyed out. (Online instructions for uninstalling typically start with "Exit the Forticlient system tray icon".) Attempting to stop Forticlient processes with Task Manager resulted in the stopped processes automatically restarting. The Forticlient scheduler service could not be stopped through the Services panel. The IObit uninstaller was unable to uninstall it. (Removed it from "Programs & Features" but Forticlient was in fact still installed and running.) This thing is like a virus! Finally the only way I was able to delete Forticlient was to reboot Windows into Safe Mode, delete the program files, and delete the Fortinet sched
Hi ! on one machine, if our common used VPN IP-Sec tunnel is established, web based browsing can't find any webpages.("no internet")DNS is ok -so names are resolved !Maybe this is a client specific setting - we checked that but no obvious differences kind regards christoph
Is it possible to make custom triggers or make changes to existing Automations->Trigger templates somehow? I've tried but the only thing that seems to be custom under Automatios is Actions, which is mainly to make a email notification. The reason is because I have a FortiGate that is using 76-78% memory consumption on average, and this one Gate is giving a lot of: System performance statistics = HIGH events, and I would like to minimize this by raising the event handler to maybe 80% memory consumption instead, is this possible in Fortigate Cloud?
Hello, I’m interested in the following information.I have a FortiGate Firewall 90G, and I need to establish tunnels with many Cisco routers — about 100 of them.Is there any example or method that would make this setup easier, so I don’t have to manually configure 100 individual tunnels?For example, is it possible to configure a Dial-Up VPN on the FortiGate, where the Cisco routers act as clients and connect using a pre-shared key (PSK)?I’d like to hear your opinion on this. Thank you in advance!
Hi! I created a hardware switch interface type, with 2 physical ports, and cannot delete it.It's grayed out, even if I try to disable them. How is it possible to delete them, please? TY
Hello, we just changed a FG cluster and we have FG90G with 7.4.7. I know that 7.4.8 does not support SSL VPN anymore so I guess we have no other option than changing from SSL VPN to IPSec. I am trying to build up the IPSec connection same way like the SSL VPN but I cant connect. Of course standard IPSec DialUp connection is easy and always works but since we have a lot of Groups and I want to control them with Policies I dont get it running. Incomming Interface is clear, the same and I know that it doesnt block any trafficClient address range I use the same object SSL VPN rangeAccessible Networks all since I also have to route them to Azure and our VPNs (like SSL VPN)PSK I checked many times, this is 100% correctXAUTH Inherit from Policy So in the IPSec to LAN policy I just copied from SSL VPN the same range and my TEST User, destination and service all. I try to connect but I get in the Client a failure of wrong credentials and than VPN connection failed, chec
Hello everyone, I have read the documentation and multiple community posts, but I'm still confused if a FortiGate can act as an IPAM server alone? The documentation says the FortiGate can act as a standalone IPAM server:https://docs.fortinet.com/document/fortigate/7.4.8/administration-guide/166728/configure-ipam-locally-on-the-fortigate But I also have seen community post that say the opposite:https://community.fortinet.com/t5/Support-Forum/IPAM-feature/td-p/312696 https://community.fortinet.com/t5/Support-Forum/IP-Address-Management-IPAM-feature-on-Fortigate-enable/td-p/260963 So can a FortiGate be a standalone IPAM server or no? The documentation isn't very specific for a standalone FortiGate that manages multiples networks or maybe I have missed that part. Also when I configure an interface on the FortiGate for IPAM, with rules and all, it doesn't configure the DHCP server on the interface. It leaves the DHCP pool blank even though screenshots wi
Hallo everyone. I recently started working for a company that has this network topology.I see that the Aruba switches are set to MСLAG with Fortiswitches, but from the Fortiswich side there are no MCLAG settings. At the same time, Fortiswiches are online and available through Fortigate. I tried to set up MСLAG on FortiSwitch, but I encountered the fact that the Aruba side is specified as native VLAN 4094, and there is no such VLAN on FortiSwitches, at least I don’t see it through Fortigate GUI.Should I create a new VLAN with ID 4094 or is it better to change the native VLAN on Aruba?I am confused that VLAN with ID 4094 is specified everywhere in Aruba settings as native and the network works.
In version 7.4.8 for Fortigate 90G, the support for SSL VPN has been removed. Why is there no mention of this in the documentation? I need the SSL VPN functionality on this device. Where can I address my complaint about the removal of functionality for this model without any warning?
I registered for the (FCA - FortiGate 7.6 Operator) offered on the FortiNet website.How can I complete the tasks in each lesson?
HELLO?we want to enable or use protocol zigbee in fortiap 231f with controleur can you help us
Intune pushed Forticlient profile keep asking for username and password even though we are using SCEP certificate for sslvpn connection.Anyone knows how to disabel username prompt?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.