Mark a Best Answer
Fortinet Community
Recently active
We have a pair of FortiGates in an active/passive cluster, and have created a secondary VLAN Interface for VoIP traffic.We have Netgear switches with Auto-VoIP-VLAN enabled. This works by matching MAC prefixes. It appears that FortiGates do not allow the MAC address of VLAN Interfaces to be modified, so I've manually configured the primary switch to use port-based VLAN to get the FortiGates and Netgear switches working. This works, but is not the most ideal solution. So, my question is: Is there a way to change the MAC address of a VLAN Interface? Or, is there another type of Interface that would do basic LAN stuff, which would allow me to change its MAC address? Thanks!
Hi everyone,I don't manage to display Antivirus or ips log in my fortigate (OS 7.2.11).I've set "antivirus log" and "extended log" to enable.In "IPS signature and filter", packet logging is enable and action is block.When i try a test from the cli with the command 'diagnose log test' , there is no log.What is the problem in my conf.Thank you in advance
i have a ready and stable sdwan (Hub and Spoke) with two underlay link (internet / MPLS) using fortimanager overlay template and i want to delete the MPLS link and add internet link ? what is the procedure ?is it to re-edit the overlay template and install the configuration again or what is the best method ? FortiManager
We have some FortiAP's set up with our FortiGate, and a few SSID's assigned around. The last SSID to be created is for guests. One of the things that I enjoy about Cisco Meraki access points is the ability to require guests to get permission from an employee via email. After joining the guest SSID, they would be thrown to a captive portal that would require them to enter their name & the email address of an employee. The email address would be required to match the company's domain(s) (etc *@mycompany.com). The employee would receive an email with links to approve or deny guest access. This allowed a measure of security and responsibility, without being a burden on IT to authorize each guest. So... is there anything like this available with FortiAP ? (We are not looking to collect guest email addresses, or create accounts for guests in our Fortinet environment.) Thanks!
Hi, I am using Multi vdom setup on my Firewall, on the 2nd VDOM I have noticed when I have created the 2nd virtual interface vlan on the new VDOM on the same physical internal ports as the 1st vdom, I notice the physical ports are greyed out on the 2nd vdom, but green on the 1st vdom. These new virtual interfaces are assigned to the new vdom fine but why are the physical ports greyed out on the 2nd vdom? I manged to establish the BGP neighbors in these new vlan interfaces fine. If I view the Global config on these physical interfaces I see the 1st vdom is configured under the physical interfaces, you cannot assign multi vdoms in the global vdom.
Hi, I am new in both eve-ng and fortigate. sorry for my naive question. I create my first lab with fortigate firewall using trial license, everything work fine. then in my second fortigate lab, serial of fortigate node change and trial license is invalid and I cannot register it gain using my account. Is there a way to sustain the fortigate image with its serial number in different eve-ng lab ?
Hello,We deployed an instance of EMS to a Linux environment and can not access to GUI with the admin username and blank password.Access to EMS is only possible through ESXi environment by using ems username.has anyone encountered this problem? Vasilis
New Fortinet admin here. I'm looking to configure the built-in DHCP server to push an alternate VLAN & Subnet based on MAC address. This would be used for VoIP phones. For example, the DHCP server would hand out 10.0.0.2 on VLAN 0 to the first non-VoIP device on the LAN. But, if the MAC address matches those used by our VoIP handsets, it would hand out 10.0.1.2 on VLAN 100. I'm looking to do this without forcing specific ports on the switches to be dedicated to the phones. Any ideas? Thanks in advance!
We had a case with technical support for an IPSEC VPN issue between two sites. Followed up for 2 days. Didn't fix the problem. Last case closed by engineer. Reopened the case. Mentioned clearly we have more than 100 users effected but still logged the case as P3. Called twice to get the case handled with higher priority but the CS team refused to take it up and also hung up the phone. Very bad response from the technical team. I also shared some details for the case later and still no response.
I have new FortiGate 71g, but it seems there is no new firmware version available for this. The latest i can find is 7.2.8, does anyone know about this?
how x forwarder will work for private to private ip could you please suggest on this
Hi, We currently have a HA pair of 201F Fortigates. Currently they link to a pair of HPE FlexFabric switches using the X1 and X2 interfaces using a aggregate interface. Under this interface are a bunch of VLAN interfaces for various networks we use. This interface is called Briggs_INTTrunk and has an IP address assigned directly to it. This subnet this interface sites on 172.19.0.0/21 also has a bunch of old servers on it which are a hangover from a few years ago, the servers use the firewall IP on this interface as their default gateway. The FlexFabric switches are going to be replaced with a pair of FS1048E switches configured in a MCLAG and I want to migrate to Fortilink to take advantage of the management aspect this will give us. We also plan to replace some of the other legacy switches with FortiSwitch in due course. The migration to fortilink seems to involve downloading the existing configuration and re-ording the interfa
Maybe this is an easy one but I haven't figured it out. I have 4 LANs, one wired and three WiFi, one is a guest, and one is a IoT. They all need to access the internet, and I have 6 or 7 blocking rules that are repeated for each. I want to have these policies in one place that all internet access goes through. I use Central NAT. So, I'm guessing I make a VLAN, and put the rules in there. Then just have each LAN exit to this VLAN, and have the VLAN exit to the WAN port. But in this VLAN, what do I do about IP addresses and what about Central NAT? So LAN to VLAN to WAN. Do I just NAT LAN to WAN, like normal, and the VLAN figures it out inside? Anything I need to look out for? Thanks.
I'm looking for an install path to install forticlient on Linux without gui so that it doesn't require licensing. Installing on Windows or Linux with gui allows you to select the free option checkbox to prevent license requirements. In Windows you can change a registry key but where is that value stored in Linux? How can I get this installed in a similar manner, on a Linux system without gui, so that it doesn't constantly expire and require reinstall?
Hello everybody,I'm working on a Fortigate 70G with a 7.2.11 firmware.I've an IPSec tunnel: Regarding this tunnel, I have two firewall rules:   The first policy regards the IPSEC_FULL_ACCESS user group and it allows connections to the 10.1.0.0/24 network, including a specific machine, wich address is 10.1.0.207/24. It works fine.The second policy regards the XYZ_VM_IPSEC user group and it allows connections only to the specific 10.1.0.207/24 machine. It's been working for a while. The XYZ_VM_IPSEC users could in fact access only the 10.1.0.207/24 machine.Since two days, this is not possible anymore. The XYZ_VM_IPSEC users can lo longer access that machine. The log settings are set to "all sessions" (not in the screenshot, but the screenshot is not updated) but logs are empty. Fortigate detects nothing.But...and this is what I am not able to comprehend...if I edit that specific firewall policy, shifting the destination address from&nb
I just finished creating a large number of site-to-site IPsec tunnels (approx. 170) using the CLI, but most of them don't seem to be functioning. Only six or eight of them have ever come up and connected. I can see all of them in the gui, and in a backup of the configuration, so they definitely created. At first, I thought it was an issue with the way the PSK had imported from my script, so I went through a number of them and re-entered and saved the PSK from the GUI to ensure that it encrypted correctly, but that didn't seem to remedy the issue. If I go into the CLI and run 'diagnose vpn ike gateway' I see entries for the 6 or 8 that work, but not for the rest. If I run the command for a specific tunnel name, I don't get any information back at all. Something I have noticed in the IPsec dashboard that may or may not be significant, the remote gateway IP addresses are not updating. All of these tunnels use dynamic DNS hostnames for their rem
Fortigate Version 7.2.10 We have several internet facing devices that use virtual IPs and a phone system that uses SIP which has a one-to-one IP assigned to it. We have two ISPs with link-monitor setup. To match our new locations, we are attempting to migrate to SD-WAN. We made the necessary changes to add the WAN ports to SD-WAN (removing existing polices on the interfaces and readding them). Upon completion the internet was tested and worked - failover to second WAN worked. Our internet facing devices were able to be access via the virtual-IP mappings on their respective public IPs\ports. We are not using SLA targets - strictly a primary\failover scenario. Our SIP device however was unable to register with the trunk provider. The Fortigate shows the IP was assigned and the SD-WAN was using the interface in the specific range. I don't believe the PBX system was able to access the internet with the one-to-one IP assignment. Restoring the
Not sure if this is because WPA3 SAE's spec is not allowing or making this combination useless/meaningless. But with our 6.4.10 wireless-controller on a FGT, I don't seem to have an option for wpa3-sae+captive-portal in the VAP's security setting, while it's available with wpa2-personal.Can someone explain why it's not there? Thanks, Toshi
Hey all,I recently updated our FortiManager instance to v7.4.5 build5874.After doing so, I was trying to install a device + policy package to a test firewall.For some reason, it is trying to append the following commands whenever I try to install, even though I did not configure these settings:config log tacacs+accounting filterset cli-cmd-audit enableconfig log tacacs+accounting2 filterset cli-cmd-audit enable config log tacacs+accounting3 filterset cli-cmd-audit enableall 3 fail with the same message:CLI audit log needs to be enabled in global setting to enable CLI command audit for TACACS+ accounting!node_check_object fail! for cli-cmd-audit enableI've tried the commandconfig system global set cli-audit-log enable end But the same error persists.Just not sure where these commands are coming from in FortiManager or what I have to do to fix. I appreciate any help!
I have a client that refuses to spend the $20 for a static IP through Comcast and they want me to install a fortigate 60f in their home office. I’ve set the Comcast XB-7T gateway device to bridge mode, but the Fortigate is not pulling an IP address when the Wan interface is set to DHCP. When the gateway device is not in bridge mode, I get a private IP address (10.0.0.x) on the wan port of the fortigate without a problem, but this puts devices behind the firewall in a double nat situation, which is causing massive network slowdowns (800mb drops to 20mb connection). He also wants to be able to use VPN to access his network from outside (planning on using a DDNS for when the IP changes) as needed, so I need to get this working fit them. I am open to suggestions on what I am doing wrong. I never have these problems when the client gets a static IP. Thank you in advance. - Chris
Not able to login firewall with local username password can anyone please share the solution on this after upgrading Not getting GUI access of firewall after upgrading to 7.2.8 to 7.4.8
Hi, We have the following setup:SD-WAN with WAN1 (Fibre) and WAN2 (4G)Two IPsec tunnels: To-Hub1 (via WAN1) and To-Hub2 (via WAN2)Both tunnels exchange different BGP routesThere are two issues:Fibre (WAN1) had an outage and traffic failed over to 4G.After Fibre restored, logs showed To-Hub1 reconnecting successfully, but the tunnel remains down in the firewall.How can we set different route preferences between these two BGP tunnels?We want traffic to prefer To-Hub1 and only failover to To-Hub2. TIA :)
HI, can you guys teach me how to bind public IP with local port in fortigate. we want to setup ubuntu server. please also advice what we should do in ubuntu server.
Hi, next week I have to do a Trade Up with a new FG model. I would like to make sure that I dont get problems with 3 FortiAPs (OK with Firmware). Problem is that all of them are really bad accessible and I dont have the option to reset them. Any suggestions? Thanks for your help!R
Hi!I have setup an Hub and Spoke enviroment via the wizards.The tunnel is up between the Hub and Spoke and I can see the BGP neighbours.The problem is when I try to redistribute static routes from the Hub. They do appear in the routing table on the Spoke but they show as "Recursive" to the local WAN. So the traffic is not routed over the tunnel.I did just add them under the BGP configuration on the Hub and toggled "Redistribute static".What else am I missing? :)
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.