Mark a Best Answer
Fortinet Community
Recently active
I recently replaced our FortiGate 60E devices with brand new 60F units (clean config build). Since going live, the HQ 60F has been highly unstable. We've experienced multiple unexpected reboots, almost on a daily basis. The 60E's were rock solid for years, but this new device has been nothing short of a disaster. kernel entering extreme low memory and conserve modesslvpn process timeoutswatchdog triggered lockupsspontaneous reboots I'm a bit shocked at how slow official support has been to respond/assist, so I'm hoping the community can provide better guidance or insight. We are running the latest mature release, v7.2.11 build1740 (GA.M). Has anyone experienced anything similar with 7.2.11 or this hardware? Should I consider downgrading to 7.2.9 or earlier? Outside of looking at different vendors, which is not a quick fix, I'm at a loss. Thank you in advance, and I will gladly provide more config/
hello, Is anyone able to integrate FML Cloud to Zoho email? The way I check Zoho is like GWS. Thanks
hi, we have 4 VDoms on a single physical fortigate running 7.2. All 4 have internet access, 3 over NAT, 1 via explicit Proxy. If i want to whitelist a Domainname (In case SSL-Inspection or some other security feature is blocking access) i have to configure the whitelist entry separately on all 4 VDoms. I am looking for a way to centralize the whitelist on a single place (i.e. a textfile on a webserver). Then use that object in a policy on top of every ruleset. I therefore created a threat feed What i tried so far:DNSFiltern/a for explicit proxyn/a on global VDOMWebfilternot possible to solely allow the whitelist and ignore all fortiguard categories. They must either be set to allow or block Maybe i am missing something here? Is it possible to achieve a common ruleset over 4 Vdoms with Fortimanager?
Hello everyone.I have a question regarding the status of some hosts in FortiNAC that are showing as "Disabled Online". I have already checked the settings to find out the reason, but so far I have not been able to find the cause and resolve the issue. Has anyone else experienced this? If so, can you share what was done to resolve the issue?Thank you for your attention.
I have a firewall configured on Transparent mode (two interfaces, inside and outside). Also I have a MGMT interface connected to the same vlan. In this case can it form L2 Loops? What is best practice?
Hi together, we are actually implementing Forti SRA for remote access for our admins. We installed the SRA VM in our DMZ, only one interface with a RFC1918 IP address. On the Fortigate in the datacenter we have a VIP forwarding an external IP to the SRA.Connecting to the SRA is possible but it seems that there are two different GUIs in the SRA (look at the screenshots attached). Sometimes one appears, sometimes the other. We didn't find out yet on what it depends. If the "well-known" Fortinet GUI appears, there is a messageConnection to the interface IP address via the GUI is only used for uploading the license. All FortiSRA configuration should be performed by connecting to the proxy addressAlso after logging in via this way if one accesses the secrets there is a messageThe feature is not available on interface IP.It does not depend on the browser used (Chrome, Edge, Firefox), the browser plugin is installed in every browser.When the Forti SRA Login page appears everything is fin
Hello,FortiClient 7.2.x (also 7.4.x) shows invalide certificate warning after every reboot of the client, also the setting to do this on ems are not enabled. Any idea?Fortinet says this normal.....
An in-depth look at how Fortinet’s FortiSOAR automation framework performs comprehensive security validation for newly deployed virtual machines—integrating with FortiEDR, FortiSIEM, FortiEMS, FortiPAM, NetBox/IPAM for asset assurance, and Nessus for vulnerability and compliance verification—to enforce enterprise-grade security hygiene and visibility. A. Introduction In modern cybersecurity operations, VM deployment is merely an initiation point. The critical focus is on enforcing defense-in-depth and zero trust principles ensuring every new asset is seamlessly onboarded into the enterprise's security control plane across EDR, SIEM, PAM, asset inventory, and vulnerability scanning. Manual validation creates security drift, expands the attack surface, and weakens compliance posture. To mitigate this, I developed an automated post-onboarding security control validation pipeline using FortiSOAR, orchestrating cross-platform integration with FortiEDR, FortiSIEM, FortiEM
While AWS provides a strong foundation of native security tools, organizations often seek additional layers of protection to meet specific compliance, visibility, or threat prevention needs. This is where FortiGate and FortiWeb solutions come into play. FortiGate is Fortinet’s flagship Next-Generation Firewall (NGFW) solution, designed to provide comprehensive, intelligent, and high-performance security for network whether on-premises, in the cloud, or across hybrid environments like AWS, offers advanced threat protection, secure VPN access, and deep traffic inspection, making it ideal for securing VPCs and hybrid cloud environments, for this scenario securing network traffic to and from fargate tasks by inspecting traffic at the VPC level, enforcing segmentation, and blocking malicious activity through deep packet inspection and threat intelligence. Meanwhile, FortiWeb is a specialized web application firewall (WAF) designed to protect web applications such as Fargate-hos
Hello. Does it matter if the mode of the policy and the mode of the web filter are different except when Fortigate's policy is flow mode and web filter is proxy mode? Thank you.
IPSec VPN with SAML was configured according to https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-Microsoft-Entra-ID-SAML/ta-p/307457. The configuration seems to be in place according to the documentation, but I get ERR_CERTIFICATE_INVALID (which is to be expected), but if I click 'Continue (unsafe),' the Script Error shows up. Error says 'Permission denied,' and the URL says 'about:blank.' If I click 'Yes' for 'Do you want to continue running scripts on this page,' it simply goes back to the untrusted certificate popup. It cycles back and forth indefinitely. Does anyone have an idea as to what I can try? Thank you.
Hi!every KB I've seen, including 212757 & 199661, omits explanation of "scope" attribute in Kernel Table/FIB printout.I understand it originate from Linux Kernel Table, but, in Fortigate context, can anyone may volunteer qualified meanings of 0, 253, 254 and 255, and significance of each?Thanks!
We have 242 devices we need to enable local traffic logging option of syslog through Forti manager.
Hello,I've a problem with only some clients (some users can connect to the tunnel without any problem). The VPN client is Fortigatevpn 7. 4.3 and the firmware of the Fortigate is the v7.6.3 build3510.This is the trace of one of the connection that ends with the timeout:ike V=root:0: comes xxx.xxx.xxx.xxx:4500->yyy.yyy.yyy.yyy:55008,ifindex=3,vrf=0,len=389....ike V=root:0: IKEv2 exchange=SA_INIT id=a26c3f92f0df5a36/0000000000000000 len=385ike 0: in A26C3F92F0DF5A3600000000000000002120220800000000000001812200006C02000034010100050300000C0100000C800E01000300000802000005030000080300000C0300000804000015000000080400001400000034020100050300000C0100000C800E01000300000802000005030000080300000C0300000804000015000000080400001428000068001400000D6B9152EBB35B01EA7298CF01F3127CF921F13B1855AA2DD180EC15DA2315F3601081A8BFA658707448BC16F20E1B3337FDB618FF0137B6AB68C13718A34889ADE62BF3728F840FEAC090A542E69C8FA8F2214EE2026060E3B5824EADA389562B000014F3EC39D2CC6635F93DC56A90466163AF2B0000144C53427
Hi, we are changing to a new FG90F cluster and we would like to use SD WAN. We have a fiber internet access we used before for the www traffic and MPLS internet access for all branch and headquarter access. The actual HA used only routing so that all internal MPLS traffic went by A and default route for internet was used by B. We want to use SD WAN also just to have an option in the future when we need more outgoing traffic for this office. Now we wanted to use SD WAN also as failover if something happens with B and we tried the implicit rule in SD WAN rules with 99-1 for B. We had a small window today and we wanted check before we change the cluster but we got problems accessing our MPLS network. We had a static route for all MPLS traffic but when we wanted to connect to our LDAP server we could not establish the connection. Removing internet access B and leaving olny MPLS A connected we just connected fine with the internal LDAP in our data center. So someth
Hi, "For the public Cloud VMs, the status of 'allow-traffic-redirect' is always set to disable due to one-arm traffic." is advised in this KB: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Traffic-handled-by-FortiGate-for-packet-which/ta-p/196651 However, looking at my existing configuration for 7.0.12, "allow-traffic-redirect" is currently enabled.Tried to look at a newly provision VM which is at 7.2.9, "allow-traffic-redirect" is currently disabled. Would you know at which FortiOS version was the default value changed?My existing configuration was from 6.0 Thanks!
Hi, we just implementing FortiAuthenticator Version 6.6.3 as radius server together with our HP Aruba / Procurve Switches. I configured MAC-Based Authentication on the switches: aaa authentication mac-based chap-radius server-group "FAC"aaa port-access mac-based 2-19 On FortiAuthenticator Site I- created the devices under User Management --> MAC Devices- registered the switch as radius client und created a Mac Authentication ByPass Policy The authentication works by I always have an error before the successfull authentication. If the Client is connected: 2025-05-13T09:00:14.065119+02:00 facauth: Updated auth log '606d3ca7ee62' for attempt from 10.10.1.116: user authentication error: invalid user2025-05-13T09:00:14.068143+02:00 facauth: Updated auth log 'B20195042' for attempt from 10.10.1.116: MAC-based authentication successful Am I doing anything wrong in the config. 2025-05-13T09:00:14.062802+02:00 FortiAuthenticator-BA radiusd[1488]: (47
Hi Team, I am planning to configure HA on FortiGate 60F firewalls in Active-Passive mode, and I want to connect two ISP links directly to the firewalls. Is it possible?
Hello Running FAZ 7.4.7 What does has this impact on (exceeding the daily logs license)?Does this mean new logs will not be saved?Or it has (something) related to TAC support?
Hello, I'm trying to configure an IPsec tunnel to replace ssl-vpn, but i can't make split tunnel to work. I have split-tunnel enabled with just an internal network allowed, and a policy that explicity allows traffic to that network. The problem is, once connected, the tunnel pushes a default route to the client, so all the traffic goes thru the Fortigate.I already tried things i saw on this forum but nothing worked To add info; doesn't matter what config i do on the forti or client side, doing "route print" always show a default route to the Forti (when i'm connected).
Hi, I am setting two sites with vlan layer 2 bridging, VXLAN over IPsec, version 7.4.8Data networks are working fine, but the Avaya phone has no dial tone and is not dialling. I didn't see any place on CLI to adjust MTU on VXLAN interface for this version
I have created an IPsec tunnel between two fortigate firewalls. On the first fortigate firewall, there is both incoming data and outgoing data(see attached photo 1.png). On the second fortigate firewall, there is outgoing data, but not incoming data(see attached photo 2.png). The IPSec VPN Tunnel is up on both fortigate firewalls. I have checked the match logs on both fortigate firewalls, but have not found errors. How do I solve the problem?1.png1.png 2.png2.png
Dear all, I am moving from SSL VPN to Ipsec, which I have not had any problems with with the Notebooks, the problem I have had is with the Android client which does not have SHA256 security, has anyone had the same problem?
Hi all,I need some help configuring a fortigate 90G Meraki switch with APs on interface x1 and a FortiSwitch interface x2 with an AP. I got the Meraki side working by using manual mode on the x1 interface directly to the Meraki and using a trunk (I'm not sure if this is correct), but I'm stuck getting the FortiSwitch and AP working. I configured the dedicated FortiSwitch interface on port x2, and although the interface is showing as online, the status is still down. The switch is also offline, even though I can access it directly.I'm not sure if I'm on the right path with my current configuration, but any help would be greatly appreciated.
Hi, I advice by technical support based on the ticket id 7990064 to find the answer in here, because i am using Forticlient free version so didn't come with Technical support. I was implementing FortiClientVPN (free) with SSO/SAML + MFA using O365 Azure on Windows/IOS/Android clients and connect to a Fortigate-501E running FortiOS version 7.0.9,build0444 (GA) and it works very well. The issue on Android client happen since both Android13 OS and FortiClient VPN apps v7.0.xx released. When Forticlient VPN apps on Android trying to connect it will automatically redirect chrome browser to O365 azure login page, the authentication and MFA approval process works fine, but get stuck on browser with displaying "This site can't be reached...127.0.0.1 refused to connect" and it never loads the forticlient VPN apps. Troubleshooting taken, update chrome apps, changes defaul
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.