Mark a Best Answer
Fortinet Community
Recently active
In today's digitally connected world, data protection is no longer just a technical requirement—it’s a business imperative, a legal necessity, and a cornerstone of customer trust. As privacy regulations like the European Union General Data Protection Regulation (GDPR) continue to shape global data practices, organizations are looking for secure, scalable solutions that not only meet compliance needs but enhance operational confidence. Enter FortiToken Cloud: Fortinet’s identity and access management service that now proudly offers enhanced GDPR support, including region-based deployment and dedicated European Union (EU) data centers. Let’s explore what this means—and why it matters. A Clear Path to GDPR Compliance The GDPR is widely considered the gold standard for data privacy regulation. Enforced since May 2018, it sets strict rules on how organizations collect, process, store, and protect personal data of individuals within the EU. For any business—whether based in Europe or simply
Hello,I am posting this message as I am having a blue screen issue when attempting to upgrade our FortiClient VPN agent (version 7.4.3.1790) on some computers only.Here are the steps performed in my script that was working perfectly on test computers before deploying it on all our clients : The following processes are killed before uninstalling any previous version of the FortiClient VPN agent :FortiClient.exe, FortiClientConsole.exe, FortiClientSecurity.exe, FortiElevate.exe, FortiSSLVPNdaemon.exe, FortiSSLVPNsys.exe, FortiScand.exe, FortiSettings.exe, FortiTray.exe, FortiVPN.exeExisting versions of FortiClient VPN are being uninstalledThe installation script resumes its actions at next rebootThe issue seems to occur on some computers during the uninstall process and cause a BSOD with the "BAD POOL CALLER" error.Thanks to some utilities like WinDebug, logs show that the FortiClient agent is in cause, but with no further explanations.Has anyone already experienced the same issue ?
Hello, dears!I hope this post finds you well. We currently have Fortigate firewall, FortiAP (231F, 231G, and a few outdoor ones), and Hikvision cameras in our network. We also have switches from different brands, including Planet, Hikvision, ONV, Dahua, etc. (4-port, 8-port, 16-port, 24-port). We need industrial switches at some areas, but most are non-industrial.We have planned to start using a new brand for better management, visibility, remote control, great visual tools, etc. However, we need a brand that could cover our needs. Our company is medium size, with around 50 access points and 250 cameras installed so far with the high expectation of expansion. That's why, we will also implement HikCentral system for our CCTV room. We have received some recommendations, but each sources seems to praise what they sell.This is the list of recommended brands:- Ubiquiti (Unifi)- Cisco (too EXPENSIVE)- Planet- Ruijie (easy and modern management system with lifetime cloud manage
Hi,Is there a feature/option for Fortinet 40F to integrate with Microsoft/Office 365 AD Directly natively for Admin authentication and also for SSL VPN authentication ?Any guidance would be great :)
I just ran into this: I have a FQDN that used to be rated as "newly observed domain". I create a rating override to a custom cathegory and added that cathegory to the list of reputable sites in the DPI profile. The Site then worked (before that it got blocked by either IPS or APC and those have no whitelist).Now it seems that Fortinet have removed the rating as it is now shown as "unrated". The cathegory unrated in webfilter profile is set to "warning". The Site still has the rating override from above.In the support docs fortinet writes that if you exempt a site from DPI then no further UTM is processed on it after certificate inspection. In opposition to this I do get a webfilter blocking page stating the site is rated "unrated".As far as I understood the webfilter should not even apply when a site is exempted in DPI.What is wrong here? We're on 7.2.11 on the Fortigates btw.
version 7.2.11from same source IP first rule SNAT to inet, second rule DNAT into IPsec VPN; the issue is, FG takes always the DNAT pool address as source; even in the SNAT (outgoing interface) rule the FG takes the assigned pool addres as source, but sends the traffic to the destination in inet; result I get an outgoing hit to my SNAT rule, but the traffic doesn't come back; in sequence the SNAT rule comes before the DNAT rule destinations are not overlapping; the SNAT target in the internet are three host addresses; so very small; is there something I've to consider specifically? After my opinion the FG shall process the rules after sequence and SA/DA match before processing NAT rules; Is there a good hint to get this solved? thx br Hanno
Hi guys, I hope you're well. I want to rename a managed FortiSwitch but when I attempt to do this I get the below error: I have done this many times in the past this way and have never received this error, the FortiSwitch is currently running 7.4.3 and the FortiGate 7.2.9. In the past when I have done this, it has been with switches I have manually authorized and configured from scratch however, with this since it was a larger install I pre-configured the FortiGate switch-controller with all my switch configurations that is the only difference I can think of. Does anyone have any ideas if it is possible still? Regards, Dan.
For any that use the link-monitor feature in FortiOS, dont forget that you can configure it to reach out to multiple servers at once.Yesterdays Cloudflare outage reminded me that putting all your faith in a single DNS server isnt always the best thing to do. Now using individual server settings to monitor several remote IPs with weighted rules for failover.
Hello.I need setup redundancy paths between FS but one link should be over fiber and second via WiFi bridge build on FAP (mesh config ROOT-LEAF). main problem is that fortilink over fiber is automatically formed but via APs I have to tenable p2p-fortilink. When both are configured all switches are going offline. Any change config p2p-fortilink on classic fortilink via fiber . Just to simulate two p2p-fortilinks. We really need find solution. Already did two links over mikrotik bridges but ofc MT are totally not visible for me and for fortiswitches.
Hello Team,We are currently working on configuring per-user firewall policies for SSL VPN access using both LDAP and Azure IdP (with MFA) to restrict access to specific destinations for individual users.Our FortiGate firewall is successfully integrated with Microsoft Azure IdP for SSL VPN authentication using token-based MFA. Additionally, we have integrated our on-premises Active Directory with the FortiGate firewall for SSL VPN access.However, when creating firewall policies, we are encountering a limitation where policies are applied at the group level, rather than allowing us to define policies for individual users.Can someone advise on the best workaround for this scenario? Specifically:Do we need to create individual user groups in Active Directory and Azure IdP for each user to achieve per-user control?Alternatively, is there a method to configure this directly on the FortiGate firewall?We are also utilizing FortiClient EMS for managing remote access VPN policies. If there's a w
Hello, I’m experiencing an issue where the Web Filter profile on FortiClient EMS does not block access to sites categorized under Gaming, despite being explicitly set to Block. Details: Web Filter profile is correctly applied in EMS.FortiClient shows the Gaming category as blocked.Testing was performed on macOS M3 (Apple Silicon).The Web Filter browser extension is installed on both Firefox and Chrome.However, no block page is displayed and the user is able to browse gaming websites freely. It appears the Web Filter is not being enforced properly on macOS endpoints.Is there anyone who has encountered this issue or has suggestions on how to resolve it? Thanks in advance.
Hello colleagues,I have a question related to the FortiGate 7.6.0 and the property security-rating-result-submissionconfig system global set security-rating-result-submission {enable | disable} endThis property was documented and available in the 6.2 version of the product:Security rating | FortiGate / FortiOS 6.2.16 | Fortinet Document LibraryAfter upgrade of the FortiGate to the version 7.6.0 I cannot find this property anymore:config system global | FortiGate / FortiOS 7.6.3 | Fortinet Document LibraryI also found the information that this property was excluded from the CLI in the document:https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/51fcbb4f-33ff-11ef-bfe5-fa163e15d75b/fortios-v7.6.0-release-notes.pdf995885 Removed the set security-rating-result-submission setting under system.globalCan please someone confirm that the propertysecurity-rating-result-submissionis officially excluded and it will not be available in the product anymore(or it was r
I have 2 spoke and every spoke have 3 connection to the hub (2 using internet connection and 1 using WAN connection)On spoke1 when i check routing details to spoke2 why i see duplicated entries only for both internet connections? SPOKE01 (Internet) # get router info routing-table details 10.101.62.1Routing table for VRF=0Routing entry for 10.101.0.0/16 Known via "bgp", distance 200, metric 0, best Last update 00:28:56 ago * vrf 0 10.10.111.3 priority 1 (recursive is directly connected, INT1_2) * vrf 0 10.10.112.3 priority 1 (recursive is directly connected, INT2_0) * vrf 0 10.10.111.3 priority 1 (recursive is directly connected, INT1_2) * vrf 0 10.10.112.3 priority 1 (recursive is directly connected, INT2_0) * vrf 0 10.103.113.1 priority 1 (recursive via MPLS tunnel 192.168.120.1) If i execute get router info routing table i only have 2 result belowB 10.101.0.0/16 [200/0] via 10.10.111.3 [2] (recurs
I recently had a UPS go down and when we recovered the power to the FortiSwitch 448E that was connected to it, the switch came up but appeared to not work at all. I couldn't get to on any management interface except using the console port in the rear with a serial cable. Anyway, what I discovered was that when power was lost and it booted up again, it booted from the secondary image with a stock config file. I was able to reboot off the primary image and it appears "normal" however I need to do some testing before I start moving devices and users back to it. My question is: Why did it load off the secondary and how can I prevent it (and my other FortiSwitches) from doing that again? I noted the 'set image-rotation' command is set to "enable" by default but I know little about what this does and why anyone would want the image to rotate each time at boot. I believe the current firmware on it was 7.2.3.Also, I want to make sure my other FortiSwitc
Hi All, I am new to FortiGate and i am doing a lab for LDAP I set up the LDAP server on the FG and the connection to the LDAP server is successful however, when I test a user credential on the LDAP it says invalid credential even though i am sure the credentials are correct. not sure where I can go from there? your help and guidance is much appreciated
Greetings, might be the wrong place to ask...I am supporting a customer that has a FortiGate 60E. They need a firewall for their current environment, and upgrade to a new internet provider. We will probably get a new firewall within the next year. I want to know what I need to do to get this device upgraded and supported to assist them. I have found that this device will go end of support in Dec 2026. How would I find out how much it would cost to get the device updated and supported for the rest of the life of the device. From what I am seeing, to true-up support is going to cost more than a new device. Does anyone know a way to get this device updated and supported for a year? I have reached out to sales, but they have been slow to respond. #Fortigate60E #support #newbie
Product: FortiGate 40FFirmware Version: v7.2.11 build 1740Severity: CriticalCategory: System Stability / Configuration PersistenceSummaryUnder low-memory conditions, the FortiGate 40F experiences a critical failure where the active firewall policy configuration is completely erased, resulting in total loss of internet-bound traffic and administrative lockout.Steps to ReproduceDeploy a FortiGate 40F running firmware version 7.2.11 (build 1740).Configure approximately 10 or more IP and domain threat feeds (external threat feeds).Add an additional external IP threat feed, referencing it in a policy.Observe system behavior as the new feed is added and activated.Observed BehaviorThe FortiGate becomes unresponsive for approximately 10 minutes.All outbound internet traffic halts.Management interface (e.g., GUI, SSH) becomes temporarily inaccessible.Upon restoration of access, all firewall policies are missing.CLI command show firewall policy returns no output, indicating full policy loss.Expe
Good evening I want to monitor a lan to a zabbix server with ip address 192.168.1.87 connected in bridge adapter but a tracer to a zabbix server and i see the ip 10.50.3.21 FortiGate-HomeLab # show system interface port1config system interfaceedit "port1"set vdom "root"set ip 192.168.55.10 255.255.255.0set allowaccess ping https ssh snmp http fabricset type physicalset lldp-reception enableset role wanset snmp-index 1nextendFortiGate-HomeLab #FortiGate-HomeLab # show system interface vlan20config system interfaceedit "vlan20"set vdom "root"set ip 10.10.20.3 255.255.255.0set allowaccess ping https ssh snmp fabricset device-identification enableset role lanset snmp-index 29set secondary-IP enableset interface "port2"set vlanid 20nextendFortiGate-HomeLab #FortiGate-HomeLab # show firewall policyconfig firewall policyedit 1set name "vlan20-port1"set uuid a58b44a4-3d9d-51f0-e235-a09bba7147a0set srcintf "vlan20"set dstintf "port1"set action acceptset srcaddr "vlan20"set dstad
Does someone know which ports are used for vpn ipsec tunnel under sdwan scenario considering this fortigate is behind a NAT ISP connection? apart from UDP 4500 and 500 ports which one are require to allow it.
Hi All, I have been trying to get DLP to block a custom file type which is *.kdb so by custom, I mean a file type not included in the default file filter list. I have tried two different ways - by creating a filepattern using "config dlp filepattern and attaching that to a DLP profile, and attaching that to my policy. Did not work. So I then created a dictionary with regex value for the file type, set pattern "\\.pmb$", and attached it to a sensor, profile, policy. None of these seem to work and the DLP is never triggered. Any ideas? Thanks.
I am using Fortigate Firewalls between Windows clients and domain controllers. In this case by allowing DCE-RPC, does the firewall allow the required return sessions without allowing dynamic port range? What are the requirements like firmware, IPS etc?
any help " device is already added in a different domain , please contact Fortinet support
I have two network segments: 10.100.x.x and 10.200.x.x networks. I've successfully established a VPN tunnel between these two different subnets using Fortinet FortiGate-60F(SD-WAN). I have configured a virtual server with the following setup:Virtual IP: 10.200.0.250Mapped to real servers: 10.200.0.102 and 10.100.0.102Health check is configured for both serversIssue: When I shut down the server at 10.200.0.102, the traffic is not being forwarded to 10.100.0.102 as expected. The load balancing/failover mechanism doesn't seem to be working across the VPN tunnel. Network Topology:10.200.x.x subnet: FortiGate internal IP 10.200.0.254, Server 10.200.0.10210.100.x.x subnet: FortiGate internal IP 10.100.0.254, Server 10.100.0.102VPN tunnel: IPSEC connection between the two subnetsVirtual IP: 10.200.0.250Questions:What could be preventing the traffic from failing over to the cross-subnet server (10.100.0.102)?Are there specific firewa
In our environment, we use FortiClient VPN version 7.0.14.0585. We started researching into the possible benefits of Intune, so I configured enrollment, compliance polices, and a simple BitLocker requirement. Those are the only changes to our Entra/Intune environment that I made. Soon, I had rolled Intune out onto a few computers in our division. One of our employees notified us of issues connecting to the VPN, and we suspected Intune to be at fault. Sure enough, when Intune was removed the issue went away. Screenshot is attached. When clicking yes, you are brought a blank page with a 300 second time out.
Hello, I found this thread: https://forum.fortinet.com/tm.aspx?m=68922 from four years ago discussing whether or not there is a bug tracker that is accessible. I couldn't find one so I have to guess no is still the answer. That leads to the question, if release notes only tell you the following bugs were fixed, how are you supposed to know if the fixed bugs are actually relevant to your environment, and/or a security concern? I'm running 2.5.3 and 2.5.4 just came out. It fixes seven bugs, identified only by ID number. Are they critical security issues? Display issues that I could care less about? Should I schedule an emergency outage now? Or never since the bugs don't matter to me? How does one make the decision with no information?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.