Mark a Best Answer
Fortinet Community
Recently active
Hi, I'm using Fortigate-30E running FortiOS v6.2.16 build1392 (GA). Not sure when it happened, but I can't create geography address anymore. It worked in the past.As can be seen in the picture, the country/region field is empty with no entries. Please advise,Thanks, Ofir
Hey guys. I am an FGT90G owner.I have tested firmware 7.0.12, 7.0.13, 7.0.14, 7.0.15.1. On all firmware there is a problem with Traffic Shaping Policies.I have configured a few rules in Traffic Shaping Policies. The network works fine, but after a few hours, all traffic that matches these rules stops working. After that, I disable the rules in Traffic Shaping Policies and my network works again.If I re-enable the rule in Traffic Shaping Policies, the network does not work.In the logs I see errors - Session time out.The problem is solved only after rebooting the FortiGate.But on firmware 7.0.12, if you turn off the rules in Traffic Shaping Policies and turn on the shaper in Firewall Policies, the Network works without problems. (26.07.2024 - The problem returns if I make changes in Trafic Shaper. Solution: Reboot the FortiGate) 2. Second problem.It is only present in versions 7.0.13, 7.0.14, 7.0.15.I have 29 routers of Zyxel usg-20-vpn connected to FGT90G as Dial-Up IpS
I have below ADPVN with BGP Topology.Spoke1 and spoke2 have 3 connection using different provider, two using internet connection and one using dedicated wan.Since we use different wan connection on spoke1 and spoke2 there is no shortcut tunnel across spoke.When both internet on spoke1 is down, i believe the traffic from spoke1 to spoke2 can use wan connection. Am i right?But if i do show bgp routing details to spoke2 on spoke1 i can see valid route only via shortcut tunnel and no route to spoke2 via wan connection. Anyone know why?
how to enable x-forwodrer in fortigate firewall
I want to create a dataset on my Fortianalyzer 7.4.6 that shows the following data:1. Username2. Group associated with the user3. User type (Whether local or LDAP)4. User status (Whether the user is enabled or disabled)5. Authentication (If it's by email, bring the email associated with that account, or if it's by Fortitoken, bring the token associated with the account)Last VPN connection I've tried Multiple Script, but it doesn't show any information. Does anyone have a script that can help me generate the requested data? Or how can I get this information from my Fortigate? Sorry for my English.
Hello Fortinet Community,I have a setup with two WAN connections that are part of an SD-WAN virtual interface. On each of these WAN links, I’ve configured a site-to-site IPsec VPN tunnel to a remote location. The phase 1 and phase 2 settings for both tunnels are identical, except for the WAN interface used. My goal is to achieve redundancy between these two IPsec tunnels—so that if the primary tunnel goes down, traffic automatically fails over to the secondary tunnel. Could anyone guide me on how to properly configure this redundancy within the SD-WAN framework? Should I use performance SLAs, specific SD-WAN rules, or routing strategies? Any detailed guidance or configuration examples would be greatly appreciated. Thanks in advance!
Hi,I play around with Fortimonitor on the Cloud trial. And to be honest, it seems to have potential.It has the possibility for a quick and dirty integration. BUT we also found a lot of bugs, but can not report them, because, of missing contract. And no, we do not buy, before the bugs are fixed. However; it seems, nobody really seems to use this kind of monitoring-tool. This is the only explanation why so many bugs seems to be there, or even many things do not work or documentation is outdated. - Mongodb. Seems to work on Replicasets only up to V6, with V7, it does not recognize the replica-status, because of new json output format, also, it still searches for mongo - binary, which is now mongosh ... - Rabbitmq completely fails because of hard python code error Who from Fortinet could debug this with me, that we could solve this issues? I am volent to debug it with you and help. But somebody has to take care on it from your site.BestRonny
I was asking to change some website tags when I saw that in character.ai there was the tag Deny_ALL. This tag doesn't seem to change and I can't find it anywhere in the tags list. Can someone explain to me what this tag is?
FYI, im not a coder of sql expert by any means...here is my ChatGPT generated Fortianalyzer SQL query:-- Main query: Count occurrences of srcip, dstport, and policyid SELECT srcip, dstport, policyid, COUNT(*) AS event_count FROM $log -- Replace with the appropriate log source WHERE srcip IS NOT NULL AND dstport IS NOT NULL AND policyid IS NOT NULL GROUP BY srcip, dstport, policyid ORDER BY policyid, srcip; -- Order by policyid and srcip -- Summary query: Unique dstports per policyid SELECT CONCAT('PolicyID ', CAST(policyid AS STRING), ' unique dstports') AS srcip, STRING_AGG(DISTINCT dstport, ', ') AS unique_dstports, policyid, NULL AS event_count FROM $log WHERE srcip IS NOT NULL AND dstport IS NOT NULL AND policyid IS NOT NULL GROUP BY policyid ORDER BY policyid;Wen i paste this code in the SQL query dataset window, I get this error and don't know how to fix this.Validate ResultERROR: 'group by' or 'order by' clause is expected in hcache.Ultimately
hello guyshelp me how to create SSL VPN for remote access on fortimanger to push on the fortigate
Is there an option to add per device mapping for VLANs in FortiSwitch Manager ? I do not want to add it one by one using GUI.
I have created a rule to detect whenever there is a successful VPN login. I have the incident title set as:"Successful VPN login from $user at IP $srcIpAddr to $userGrp" However, the "$userGrp" attribute is not displaying as expected. Instead, it comes through as the "$user" attribute followed by "Grp". Example: I (amacready) logon as part of the "Standard" user groupDesired result: "Successful VPN login from amacready at IP 1.2.3.4 to Standard" Actual result: "Successful VPN login from amacready at IP 1.2.3.4 to amacreadyGrp" Is anyone able to suggest where I'm going wrong?
Hello, I'm running FortiClient EMS 7.4.3 with a FG-120G on version 7.4.7. I've configured some ZTNA access on the FortiGate, and it works like a charm. Now, I'm trying to push the ZTNA connection through EMS. The great thing is, my ZTNA applications are automatically detected since my FortiGate and EMS are connected via a connector. My problem is: when I try to create an application, I can't see those gateways. And of course, if I try to create a new gateway with the same IP, I can't. In the ZTNA destination profile, I see both of my auto-detected applications, but they're not being pushed to the EMS client. So, I'm a little lost here — the "Web Proxy Rules" are not being pushed to the client, and I can't create a rule because I can't create an application, since I don't see the gateway. I was able to create an application with a fake gateway, download the XML, modify the gateway, and re-upload it. But I'm pretty sure it shouldn't be that c
friends a question: I have problems accessing a page, specifically a video that is within the page. Since it is displayed as not available.Reviewing the logs, I do not observe any blockages from the firewall.I performed the following validations: *I generated a new policy, in which no security profile was enabled. Additionally, the no inspection profile was enabled.*For the new policy, all ports were enabled. Furthermore, it is located above everyone. However, when you directly access the internet router, you do have access to the page. Do you know what could be happening?
i have fortigate 40F and i'm trying to access the firewall on web browser but it's not opened ! i connect the firewall through fortigate port 1 to computer by ethernet, the ping was okay but its not opened the log in page ! please help me to log in the firewall. Thank you GG FortiGate #support #all
HiI have a pair of Fortigate 200F running 7.2.3, when i try to configure log disk setting, the option doesnt seem to be availablePlease refer to the screenshots below
Hello Fortinet Community,I’ve configured two identical IPsec remote access VPNs on my FortiGate—each mapped to a different WAN interface for redundancy purposes. On FortiClient, I’ve added both VPN gateways. The issue I'm facing is that when I disable WAN1, FortiClient does not automatically failover to the second gateway. Instead, I have to manually reconnect by clicking "Connect" to establish a session with the secondary gateway. I'd like to know is it possible to automate this failover process, so users experience minimal disruption? Is it possible to achieve automatic remote access VPN failover in FortiClient without using EMS?Thank you!
hi, I am using EMS 7.2.11, with client 7.0.14.software inventory is working fine, but PUA page, under dashboard, is empty.there is only one row with this warning: Software Inventory must be collected for PUAs to be detected, but this is not true.under "software inventory"-> applications I can see all software installed.
hiI have a server configured as a vip in my fortigate to be accesses from internet. I want to block it's admin page. (my.domain.com/admin) . I tried the policy with deep packet and ssl inspection along with creating a webfilter and blocked *\admin* but still admin page reachable from internet. how can i block admin page?
Hi eveyone,I need help or technical help. I have this topology:I have central router Cisco ASR 920, on this router ending L3 routing and interfaces. Router send trafic via BGP to isfw fortigate or segmentation firewall and segmentation send via bgp to perimeter. Comunication to public is okay but internal trafic no, ending on router. Default routes is directed to isfw. I try it PBR from routers but the router has limitations.i dont know how to directed all traffic to isfw. Thank you for supportMathues
Hello, everyone. I have a question. The client ZTNA has 1,500 terminals, and each terminal may have two USB mobile devices. The client's requirement is to release them in a whitelist manner. However, with so many mobile terminals, the workload is a bit large. For the mice of the same brand purchased in the same batch, information such as USB Type, Vendor ID, Product ID, and Firmware Revision is still different.I have several questions:Question 1: Is there any way to avoid manual entry one by one? The workload is too large. Question 2: Can the whitelist be released based on a certain brand? For example, HP and Dell mice, Panasonic USB drives.Question 3: For the control of such a large - number of mobile external USB devices, are there any other good suggestions?References:https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-properly-identify-USB-devices-to-configure/ta-p/339955
Hello, We recently started migrating our SSL-VPN to IPSec. Something we just noticed is that the IPSec setup is not fully compatible for iOS version of FortiClientVPN application. FC VPN at its latest version for iOS devices supports IKEv1 only on Main Mode (we went with aggressive mode on our initial config).For remote users authentication we’re using a FortiAuth server that communicates with the firewall using RADIUS and to the AD Servers using LDAP. FortiAuth checks if the user exists on AD and then sends an authentication token to the user for 2FA. We started noticing that the last part with the authentication is problematic for FC v7.4.6 on iOS devices and after investigation with Fortinet they informed us that FC VPN on iOS rejects the authentication packets and drops the tunnel afterwards. For testing purposes, we disabled the 2FA option within the ForitAuth for the spesific user we login and the tunnel was able to connect succesfully without authentication j
Hi, We have two firewalls located in different locations: Firewall A and Firewall B. Both setups include an L3 device positioned between the LAN and the firewall. In Firewall A, the relevant subnet appears as directly connected, whereas in Firewall B, the subnet is marked as statically connected. This indicates that in the Firewall B setup, the switch acts as the gateway, causing the firewall to receive the MAC address of the L3 device instead of the end-user device. However, in the Firewall A network, even with the L3 setup, the firewall acts as the gateway for the subnet, enabling it to detect actual client MAC addresses and enforce MAC-based policies. Consequently, MAC-based policies do not function in the Firewall B setup because the L3 device serves as the gateway. In contrast, these policies work in the Firewall A setup, where the firewall directly receives the MAC addresses of the client devices. FortiGate
I generated a CSR on one of my Fortigate firewalls that contained over 10 SAN's entries, the certificate was signed by my internal company CA, I then imported the PEM into the Fortigate firewall successfully to use for HTTPS access, then by mistake I deleted the Certificate off the firewall instead of downloading the cert! My signed PEM file doesn't have a private key, I have a PCKS#7 cert, der and cer from my PKI team. But I do not have the private key anymore is my guess after deleting my imported signed Cert on the Fortigate. On another SAN Firewall where I need to install I import any of these signed cert formats, error is "duplicate mismatch" I gather because the signed cert doesn't have the private key and I should be downloading the imported cert from the Fortigate that imported the signed cert where the CSR was generated to the other Firewalls! Any there any way I can install these signed certs on my SANs Firewalls or do I need to generate another CSR again? 
Hey everyone! Last month the built-in wifi certificate expired on my 100E. I'm running the latest possible FortiOS release but without a license. (FortiSwitches and FortiAPs are in place as well)I'm using the certificate for the builtin WPA3-Enterprise authentication against user groups. Some devices didn't care that it ran out, others had a warning and few right out refused to connect to wifi https://mobdro.bio/ .Is there a way to get a renewed certificate without a license?Currently I switched it to a public Let's Encrypt cert, hoping to not get the "untrusted" warning on devices but they still appear and I thing some android devices have issues with the (automatic) renewal of certs, which I'm super duper NOT a fan of, since those devices are business critical.Any ideas? I'm all ears!
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.