Mark a Best Answer
Fortinet Community
Recently active
Hi everyone, I'm setting up a new cluster for a new location of ours the location will be L2 connected to an existing location but also have it's own Internet connection and Fortigate cluster. At our existing location we have an Active-Passive HA cluster running and now I am considering making the new cluster Acitive-Active to not leave performance on the table.I reached out to support to ask what the recommended mode was since the documentation does not mention a best practice/recommendation as far as Active-Active vs Active-Passive but was told "we don't make recommendations". So instead asking the community about their experience with this :) We are a single company so not sure how relevant using VDOMs is to us. Thanks!
Hello,I have three FortiGate firewalls: A, B, and C.- A ↔ B: IPsec tunnel- A ↔ C: IPsec dialup tunnelI want to allow communication between B and C **without a direct tunnel**, by using FortiGate A as a **VPN hub**.Is this setup supported, and what are the best practices for routing, phase2 selectors, and policies in this case?Thank you!
Hello.I purchased a Fortigate201G; previously, I used Mikrotik. I am unable to configure VLAN. I am creating them according to the instructions. On Mikrotik, I created tugged and untugged ports. However, the end computer does not receive an IP address from the VLAN. DHCP is enabled. Could you advise me on what I am doing incorrectly?
Hi All, We have successfully implemented SAML authentication with Azure from FGT 120G cluster running 7.2.11.It works without any issue from the edge browser for all the tested users. But from the chrome after the Azure login page is prompted and after adding the credentials it is going to a URL looping.It loops between the local IP (https:192.168.50.254/saml/****) and login.microsoftonline.com (https://login.microsoftonline.com/****) URLs. For some couple of users it works with chrome too. Checked adding after the SSL user certificate into chrome but no luck. Any idea for a workaround or solution for this issue? Thanks
What oid can be used for get IP address for specific port, example ip for ifindex3.
Using the search bar to search for an IP address at the top of the firewall policy screen in FOS 7.4+ always includes as a result any rule containing the "all" object. How do I turn this behavior off? While it's logical, for me it's uninteresting (unless I would specifically want it that way). This worked just fine in < 7.4, i.e. a search gave all policy rules containing a subnet or group or anything that contains what I am looking for, but not "all".
Hi!As I understand, after failover, system ha's "route-ttl" timer dictates validity period of FIB routes inherited from former Primary. Default is 10s - low value.However, BGP Graceful Restart timer "graceful-update-delay" default is 120s - a much higher value.How does Fortigate enforce these two values or is it up to me to align them? If so, given that "route-ttl" affects all routes, not just BGP routes, how would I align - recommendations?Thanks!
Hello, We're running a pair of FortiGate 121G (v7.2.11 build1740) in active/standby mode, acting as a gateway/DNS and DHCP server for the wireless guest users.The Security Policy along with the DNS Filter policy is very generous with literally nothing blocked. There are absolutely no issues with any laptop (Windows or Mac) and Android phones/tablets, but I have consistent issues coming from iPhones. It takes some time to load any page and sometimes it works fine and sometimes it just times out. Reloading the page seems to help. I initially blamed Private Relay, but turning it off doesn't seem to help, and there is nothing in my policy that could affect it. Everything is under DHCP and it's the same SSID for all devices. Would greatly appreciate any tips since I can't find any errors in the logs, nor traces that some web resources are blocked. Thanks.
Does FortiSwitch support just RMA and hot swap of the FAN and PSU without RMA the whole appliance? For FS-1024E, FS-T1024E, FS-T1024F-FPOE, FS-1048E, FS-3032E, FS-2048F. FortiSwitch
Good evening, We have a issue regarding a IPsec remote access VPN configuration. We now have to covert entirely to IPsec VPN (no ssl-vpn anymore) and we are having issues with configuring user and group based restrictions. We want to create 3 tunnels which will use 3 user groups which have users that have a external Radius server for authentication (everything works fine in that part). We want to create a policy for each group, which will have access to 3 servers, and then add access to other servers for specific users. We are using Fortimanager, and a sample configuration is Incoming interface : ipsec-VPN-Tunneloutgoing interface : local-area networksource: 172.17.0.0/28 + user1destination: server 1, 2 and 3 Problem is, the Fortigate allows all the users in the 172.17.0.0/28 to access these resources, not only user 1. We also tried enabling the "security mode: captive portal" option on the tunnel interface and allowed only the logistics department
Although I’ve successfully established an IPsec tunnel between our Head Office and Factory using the same DDNS, I’m still unable to access the Factory’s FortiGate 80F through it.I am using internet from Mobily and STC 5G routers, enabled the DMZ in there...Kinldy help ASAP.
Good morning, Since upgrading to 7.4.3 on my 601E firewall cluster, my AP's (only 9 of them) keep dropping offline with no good explanation in the logs that I can tell. I never had a problem with the previous version I was at which was 7.4.1. A reboot of the AP (either by resetting the POE on the switch port or by unplugging and plugging back in) will bring the AP back online and connected with clients but then randomly (could be hours or days later) it will drop back off.My Fortigate cluster is stable (no HA changes) and seems to be normal. The APs are all 221Es running 7.4.2 firmware. The only log entry I see that seems to be related to when they drop is:Action ap-failReason Control message maximal retransmission limit reachedProfile resv-dflt-FP221E5519035229Physical AP ap-2b-publicMesh Mode mesh root apMessage Failure happened on AP ap-2b-public. I did find a document (https://community.fortinet.com/t5/FortiAP/Troubleshooting-Tip-After-a-failover-F
I am trying to automate the creation/renewal of Let's Encrypt certs through the REST API, but I cannot seem to get POST /system_certificate_local/automated to execute properly. Even following the example formatting, I still can't get it to work. I can upload certs using the API with POST /system_certificate_localut only the automated portion gives me issues.I can create an automated cert in the GUI using both ACME and DNS-01 challenge, so I know it is possible.I am on v7.4 if that adds any context.
Hello,I'm about to configure Agentless access to private applications through FortiSASE for contractors, however, I read that it's required to Enable SSO authentication for SWG users, which needs an integration with user database such as Azure AD, without that Agenteless ZTNA cannot be configured (as I understand it right now).I already enabled SWG, created the SWG policies required, and have a local user group created, but this SWG SSO authentication is making things though.Is there any way to bypass this and use only the local database (fortisase database, coupled with MFA, why not). Or it works just like that and there is now way to do it differently ? Thank you in advance
Blocking External Access to the Anydesk ApplicationHello, good morning.I'm trying to block external access to the Anydesk application installed on computers on my internal network. I've tried several times to block access by creating firewall rules to block access from WAN to LAN, but to no avail. However, I can normally block access from LAN to WAN using Web Filter, Application Control, or Anydesk's internet service.Could you help me with the best way to implement this external block?My goal is for users on my internal network to be able to use Anydesk for remote access normally, but for external access to Anydesk on my local network to be blocked.Thank you in advance.
Hello. I am using a handout FortiGate unit, that still have several months left on a support contract.How can I register that unit under my Fortinet account and purchase a new support contract, when the current one expires? Thank you.
We've had sections created on each of our FortiGates (currently running 7.4.6) that we manage via FortiManager. Today upon logging into FMG, two of the FortiGates now have the section before every firewall rule and not the specific sections wherer they've been for the past few years. I suspect the cause is something within the FortiManager, because we deployed changes to these two firewalls yesterday, and when I look at what's about to be deployed to another firewall, every line of the firewall policy has "set global-label "blah(##)". Can someone point me in the right direction as to how to disable this behavior? Thank you.
We have fortigate firewalls & EMS server for Forticlient management. We are using several FortiAPs. We want to use certificate-based authentication for wifi users. I know we can achieve it by using EAP-TLS 802.1x and radius server. Is there any way we can use EMS server for certificate-based authentication for wifi users? If so please share document for the same.Thanks in advance.
I am trying to figure out where device info comes from on Forward Traffic logs on Fortigate devices. The source will show an ip address and the device will have a different ip address. This causes some confusion when trying to investigate log data. Thanks in advance.
I have a FortiGate 1000D, v7.0.13, with some VPN connections. Some VPNs have multiple "Phase 2", and the IPsec tunnel only goes down when all of them are down. I'm monitoring the device with Zabbix, which reads the 1.3.6.1.4.1.12356.101.12.2.2.1.3 SNMP table to monitor FortiGate's VPNs. However, I noticed that this table only shows the status of the "Phase 2" selectors and not the tunnel status. When a "Phase 2" status goes down, Zabbix generates an event, but I don't usually need to monitor these alerts.So, I'm looking for an SNMP OID that shows only the actual tunnel status, not its "phase 2 selector". Here's a picture of the IPSec Monitor Dashboard to better illustrate my question. I've marked the actual status I'm looking for in the MIB. Any thoughts on this matter?
Hello, the installation of FortClient on an ARM 24H2 (Win11 Pro) does not work and there is a RollBack. - Tried FortiClientVPNSetup_7.4.3.1790_ARM64 Any ideas?
We have an FG-200F with only FortiCare. The WAF profile has been activated, and I would like to know if the signatures for this profile are updated with only FortiCare Premium Support?. THANKS
Hello, Fortimanager version : 7.4.7Fortigate version : 7.4.8Adom : 7.4 Our fortimanager try to push object who aren't use in Policy package or SDWAN rules For example :config vdomedit SDWANconfig firewall addressedit "ACE-1"12fc575c-6239-51f0-6d5e-bf3aff5d5940set subnet 10.10.10.10 255.255.255.255next I checked the CLI configurations on FortiManager, and this object does not exist in the database of Fortigate. Other problem, when i modify a groupe like GRP-FORTIGATE, the adress object is not add in the group when i push. But in GUI of fortimanager, group and entry are good Best regards, Killian
Hi, I'm trying to move from SSL-VPN to IPSec, and no matter what I do, my forticlient is getting timeout on connect when I'm trying to use SAML.My SAML port is 1443SAML is working perfectly fine with SSL-VPN.I'm on version v7.6.3.I made to read and follow all the guidelines I could have found on the forums and in forti website.If I try to connect with out SAML, it works fine.I'm pretty lost at the moment because FortiClient doesn't seem to generate any logs for this connection attempt as well.
I have a problem. How can I configure an IPsec remote access VPN on FortiManager 7.4.5 and assign it to our Fortigate? I found many documents and videos about hub-to-hub and hub-and-spoke solutions, but unfortunately, I couldn’t find any solution explaining how to set up IPsec remote access VPN. Can anyone help me with that?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.