Mark a Best Answer
Fortinet Community
Recently active
Hi, I advice by technical support based on the ticket id 7990064 to find the answer in here, because i am using Forticlient free version so didn't come with Technical support. I was implementing FortiClientVPN (free) with SSO/SAML + MFA using O365 Azure on Windows/IOS/Android clients and connect to a Fortigate-501E running FortiOS version 7.0.9,build0444 (GA) and it works very well. The issue on Android client happen since both Android13 OS and FortiClient VPN apps v7.0.xx released. When Forticlient VPN apps on Android trying to connect it will automatically redirect chrome browser to O365 azure login page, the authentication and MFA approval process works fine, but get stuck on browser with displaying "This site can't be reached...127.0.0.1 refused to connect" and it never loads the forticlient VPN apps. Troubleshooting taken, update chrome apps, changes defaul
Hello everyone! With the lack of support for the vpn client through official channels, I turn to everyone here to see if they can help me out. I have been working for two weeks to get some version of the fortinet vpn working on Bazzite with no luck. No matter how I install it, all that happens when I open it is a white screen with a context menu that says <empty> when I right click in it and a menu bar with only a couple options or just a complete white screen under the title bar. I can only try installing the official RPM because their linux downloads page hold incorrect instructions for Fedora (which Bazzite is based off of). I desperately need some assistance because this is the only thing preventing me from being able to get off Windows, but my work requires it.
Hi @community,I'm encountering an issue while trying to sign in to the Fortinet NSE Training Portal. After logging in with my credentials, I receive the following error message: "You have logged in successfully as '<username>' but do not have an account in Moodle." Could someone from the support team or community help me resolve this?  
Hi NAC admins FortiNAC 7.6.3.FortiOS 7.4.8 managing FortiSwitches 7.4.6. According to "FortiNAC - FortiSwitch FortiLink Integration Guide" doc, both SNMP MAC Notification & Syslog methods are supported.https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/bf034eae-75df-11ef-8355-fa163e15d75b/FortiNAC-F_7.x-FortiSwitch_FortiLink_Integration_Guide.pdf From the pros and cons list on page 7 & 8, am I supposed to I understand that Syslog method is more recommended than SNMP MAC notif method?Anyone tried both and can advise on the best one?
I’m working with a BGP setup involving three FortiGate firewalls:FW-AFW-BFW-CFW-A has two BGP neighbors with FW-B: one over a point-to-point link and another over an IPsec overlay tunnel. Both neighbors advertise the same routes to FW-A. However, I need FW-B to only advertise the routes it receives via the point-to-point neighbor.To achieve this, on FW-A I apply an outbound route-map to the point-to-point neighbor with FW-B, matching the route 192.168.10.0/24 and tagging it with the BGP community 65002:200. FW-A also sends this same route to the IPsec overlay neighbor, but without any community tag.On FW-B, this results in receiving the 192.168.10.0/24 route from both neighbors — one copy with the community 65002:200 (from the point-to-point link), and one copy without the community (from the overlay).FW-B also peers with FW-C. Between these two, I configure a route-map outbound on FW-B that matches routes with the community 65002:200, so that only routes received from the point-to-poi
Hello, I'm interested in the following type of information.We have configured and set up IPsec remote access VPN on a FortiGate device. At this stage, it works without issues only on version 7.2.When I tried to connect using FortiClient version 7.4, it got stuck and showed the message:"timeout while responding IP address".What could be the cause of this?Have you had similar experience?Please share your experience if you have.
Hi. I need to connect 500 Cisco routers with a Fortigate. What is the best way to approach this? Preferably I want it to be an IPSec tunnel interface. As I know, AD VPN is only supported by Fortinet devices, so it won't work for me, but is there an alternative? Thanks in advance.
Hello team!! I have many questions about VPN Licences.I think I understand the following, please let me know if I am wrong:* Up to FortiOS 6.2: I have licences for 10 Standalone Forticlient* From FortiOS 6.2 or higher: Unlimited Standalone Forticlients In first place I don't care about support, I am worried about how many client I could connect to Fortigate VPN.What about L2TP VPNs? There is a limit for the amount of clients?I see an article here for FortiClient, but not for L2TP VPNs. Thanks in advance.Regards.Damián
Hi, we have a ssl-vpn configured on mobile phones and the connection is discounted after every phone call, is there a way to prevent the disconnection?
Dear Team, We have encountered an issue where the departing service provider deregistered the FortiGate devices instead of utilizing the "Transfer a device to another FortiCloud account" option. Could you please advise on the necessary steps to re-register these devices under our FortiCloud account, including the process for transferring any existing contracts associated with the equipment? Thank you in advance for your assistance.
Hi everyone, My fortigate device blocked this kind of traffic destination Apple.Store, how do i allow the traffic? Thank you.
i m trying to customize Fortiweb os with terraform, VMware tools is already installed on vm but i get this output errorError:│ Virtual machine customization failed on "/Datacenter_flexos/vm/fortiweb":││ An error occurred while customizing VM fortiweb. For details reference the log file /var/log/vmware-imc/toolsDeployPkg.log in the guest OS.this is my code:resource "vsphere_virtual_machine" "Fortiweb" { name = "fortiweb" datastore_id = data.vsphere_datastore.datastore.id host_system_id = data.vsphere_host.esxi_host.id resource_pool_id = vsphere_resource_pool.resource_pool_fortigate.id num_cpus = data.vsphere_virtual_machine.fortiweb-template.num_cpus num_cores_per_socket = data.vsphere_virtual_machine.fortiweb-template.num_cores_per_socket guest_id &n
Hello, I need your help. I'm trying to set up an IPsec remote access VPN on FortiGate for the first time. Unfortunately, when I try to connect, after clicking "Connect," it shows "timeout while connecting to IP address." I was following this guide.https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-IPsec-remote-access-with-full/ta-p/275672https://www.youtube.com/watch?v=diRUIQGnWqs If you can, please help me — what could be the reason?
Hi guys.I'm trying to upgrade my Fortigate 600E in our production environment. I don't have a forticare account and our contact will get firmware for us. Now I want to verify them by using MD5 checksum. I did a reserach and fortinet said If you go to their site and paste firmware file name, It will give you checksum. But no matter what name I type in bar, It says it couldn't find information about it.Since this is a production unit, I highly appreciate if anyone can give me hash details of these files. Thank you in advance.File: FGT_600E-v7.2.10.M-build1706-FORTINET.out.zipFile: FGT_600E-v7.2.11.M-build1740-FORTINET.out.zip
Hello, I have to connect 500 cisco routers from different branches on my virtual fortigate firewall. what is the best practice for routing?
I'm working on a new design for our SD-WAN and BGP. We're currently on 7.2.10, but I'm planning on attempting an upgrade to 7.4.7 tomorrow. We have two hubs, a primary (we'll call it PH for Primary Hub) and a backup (we'll call it DR), as well as many branches. Current configurationUnderlay: There's a metro ethernet (ME) connection between all sites. PH has two DIA connections, and all other sites have a single DIA. Overlay: We're using the ME directly, no VPN. Each site (besides PH) has two VPN connections between the site and PH, one for each DIA on PH. There's currently no VPN between the branches and DR, but I intend to correct that.BGP is on the tunnel and ME addresses. All sites besides PH are route reflector clients, and PH is doing the reflecting.SD-WAN: PH has health checks and rules for each other site. It prefers ME first, VPN-DIA1 second, and VPN-DIA2 third.It's all very manual and honestly, it's a bit of a mess right now. It's certainly not optimal, and I'm
Hello everyone,I'm currently setting up a lab environment to authenticate mobile users (smartphones, tablets) to a WiFi network using certificate-based authentication via 802.1X.I'm following this Fortinet guide (but i'm using a Bridge SSID and not a Tunnel SSID):FortiNAC WiFi 802.1X based network using FortiNAC Local RADIUS ServerInfrastructure:FortiGateFortiAPFortiNAC-F version 7.2FortiGate Configuration:SSID:RADIUS Server settings:NAS IP: set to FortiGate IPradius-coa enabled via CLI VLAN Interface ID 69 created and enabled with:RADIUS AccountingSNMPPINGSecurity Fabric ConnectionFortiNAC Configuration:Local RADIUS: Configured and enabled all TLS typesWinbind Domain: Configured (used for another SSID with LDAP + Persistent Agent)Network > SSID:SSID bound to Default RADIUS ServerCustom Settings:RADIUS Mode: LocalRADIUS Attribute Group: RFC_VLANEnforced Wireless Role: default, registration, and logical networksVLAN Port Group (ID 69):Authorized Access PointsForced Authenticatio
Hello guys, I need help, i have a fortinet 100f and i need to have HA, when i lost a internet link, i need that switch the trafiic automatic for the other interface. I have only one firewall and i works with the same internet links at same time.For Wan 1 im using for web traffic and Wan 2 for a vpn site to site. Please you help for have
Hello, we are preparing in one office the change from FG81E cluster to FG90F cluster. We have actual 50 One Time Forti Tokens assigned to 50 SSL VPN /IPsec LDAP Users. As I understand I have to open a Ticket so that the CS team can move them to the new serials, correct? Is there any chance to keep users with the old Tokens, like copying them in the config file or do I have to create them from LDAP again and assign them a new token? It could be difficult because I dont think that moving Fortitokens can be done in hours so maybe we have to let them x days without 2MFA. Any suggestions to do this the best possible way? Thanks!
IPSEC VPN is UP and traffic was normally going through, without any action we started to no more receive any incoming traffic in the tunnel. No change done on both side. Everything is ok on both side in term of routing and policy FortiGate
FortiGate-81F # diagnose debug fsso-polling detailAD Server Status(err: server can not be accessible):ID=1, name(172.18.0.1),ip=172.18.0.1, port=0, source(security), users(IPv4:0, IPv6:0),username=swd\lcloperator2read log eof=0, latest logon timestamp: Thu Jan 1 03:00:00 1970polling frequency: every 10 second(s), success(0), fail(106)LDAP status: initLDAP query: success(0), fail(0)LDAP max group query period(seconds): 0this is branch location firewall the AD is in DC location also i checked the Fortinet documents but still i didn't find any solution can you please help me on this Note: Agentless polling mode
Hellowe are running FortiClient EMS currently on 7.2.7 and upgrading to 7.2.10.We are getting reports of staff having random connectivity drops once or twice a day , logs do not show anything particularly useful. What we have noticed though is that the staff getting issues are not rebooting their laptops daily. Staff who do reboot daily do not seem to hit any issues. Is there any oddity around the fortinet EMS client that requires a reboot to avoid issues occurring ?
Hello, Is it possible to setup a email 2FA for LDAP users to protect the VPN IPSec-overs-TCP connection ? The feature is working fine in the SSL VPN as previously. I found this KB but meaning working with a Certificat authentication : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-email-based-MFA-with-certificate/ta-p/348005 My IPSec-over-TCP is working with a pre-shared key. Thanks
I have loaded FG image on Hyper-V, how can I request virtual license in offline (without Internet on Firewall) mode?
After configuring the VPN address provided by the client (scss.square-enix.co.jp) on other computers in the local area network, all connections were normal. However, one of the computers encountered the aforementioned error. Could you please take a look and identify the cause? The version number of FortiClientVPNSetup is 7.2.3.0929 Failed to establish the VPN connection. This may be caused by a mismatch in the TLS version. Please check the TLS version settings in the Advanced of the Internet options. (-5029)
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.