Mark a Best Answer
Fortinet Community
Recently active
Hello, I run an Installation from an FMG but it failed. However this created a task in the Task Manager which I cannot delete and consequently I cannot do the installation again. It seems that the pending task is blocking any new installation attempts, however I cannot delete the task that failed. Has anybody experienced a similar issue. Is there a way to force delete this task, because it prohibits any further installation to the FG? Thanks
Azure virtual network terminal access point (TAP) provides the capability to encapsulate and mirror traffic to a network interface of an appliance or a load balancer fronting an appliance. For workloads deployed in Azure, where traffic inspection via a stateful device like an NGFW (Next-Generation Firewall) isn’t in place or isn’t feasible, leveraging the virtual network TAP solution provides visibility into network traffic without the need to rearchitect or reroute production traffic. Leveraging virtual network TAP with FortiGate VM enables the following use cases: Network visibility into the traffic that is sent and received by your workloads in Azure. Leveraging the IDS (intrusion detection system) capability on FortiGate VM helps detect network-based attacks such as DoS, DDoS, and port scanning, as well as malware and virus detection, ransomware, and data exfiltration. The capability to send these traffic logs to a centralized place, like FortiAnalyzer, t
We have been using link-monitor to monitor ping to GW, but after setting up link-monitor, HA switchover due to link monitor failure occurred frequently during periods of high traffic spikes.When we checked the ping statistics of link-monitor, we found a temporary maximum latency of 475 ms, which is a very bad value. No switching occurred at that time.The reason for the frequent occurrences is that the line became unstable due to user traffic.Is it safe to assume that the ICMP packets in the link monitor are likely to have been affected by the unstable state of the line due to user traffic?If so, can this be resolved by changing the timer value of the link monitor?The current settings are interval 5000, failtime 3, and other default values.
I know this is officially unsupported, but still I am curious if someone somehow has a clever solution :) The problem description: On our central datacenter firewall (Fortigate) we have multiple tunnels towards customers who have overlapping destination subnets so policy-based tunneling is a must. A new customer has two tunnels which need to be in a failover setup. Therefore I have two identical policies, both pointing to a different IPSEC tunnel. All traffic for this customer now matches always on the first policy, resulting in the backup-tunnel-policy below it to be never hit. I already thought of an automation-stitch with a script to disable a policy on an event (monitoring the primary WAN IP of the customer) but I think that is too much hassle or might have unexpected results. In the past, when using Cisco ASA, policy-based tunnels could be easely configured as a backup (just add a second peer IP address on the crypto-map). Fortigate lacks this mechanism. O
Dear Concern, I need to access a website that is currently being blocked by my FortiGate-201 running FortiOS v7.6.2.F. I have attached a screenshot for your reference. The website is authentic, and I would like to specifically allow or exempt it so that it can be accessed from our office network. According to the attached capture currently, it is being categorized as a "Malicious Website," which is why the FortiGate firewall is blocking it. I have already added the website to the Security Profiles > Web Filter > URL Filter and set it to Allow by using type simple or wildcard, as shown in the attached capture. However, the website is still being blocked. Kindly guide me on how to properly exempt or allow this website so that it can be accessed from our network. Your urgent and appreciable technical support is required to allowing this specific website in my FortiGate firewall.
Hi Fortinet Community,I'm setting up a network with three FortiGates and need help configuring IPsec VPNs and inter-site communication. Here's the setup::small_blue_diamond: Topology Overview:HQ FortiGate: NAT mode, connected to ISP via L3 linkBranch1 FortiGate: Transparent modeFactory FortiGate: Transparent modeAll sites are connected over Layer 2 linksDHCP for both branches comes from HQ:small_blue_diamond: Network Details:Site Device Role Subnet Assigned HQNAT mode FortiGate10.10.10.0/24 (LAN)Branch1Transparent FortiGate192.168.100.0/24 (via DHCP)FactoryTransparent FortiGate192.168.101.0/24 (via DHCP)HQ Server1: 192.168.100.1 (needs to be accessed by Branch1 PCs)HQ Server2: 192.168.101.1 (needs to be accessed by Factory PCs)All branch PCs should also have access to HQ LAN (10.10.10.0/24):question_mark: What I Need Help With:How to configure IPsec VPN tunnels:Between HQ and Branch1Between HQ and FactoryNote: Branch1 and Factory are using transparent mode FortiGatesHow to allow the fo
hi,i'm planning to build a new FGT VDOM with a single WAN then with multiple "inside" VLAN interfaces, i.e. corporate and guest VLAN.the customer will use all the RFC 1918 address space, so i'll prepare static route and SNAT for the 10.xx, 172.xx and 192.xx subnet.my question is, is the VDOM setup "feasible"? i have same RFC 1918 static routes to both "inside" for corp and guest sub-interface/VLAN which have different exit interface and gateway and RFC 1918 for SNAT/PAT to the single WAN public interface/IP? config router static!! Corp VLANedit 1 set status enable set gateway 172.16.45.20 set dst 10.0.0.0 255.0.0.0 set device "po1.10"nextedit 2 set status enable set gateway 172.16.45.20 set dst 172.16.0.0 255.240.0.0 set device "po1.10"nextedit 3 set status enable set gateway 172.16.45.20 set dst 192.168.0.0 255.255.0.0 set device "po1.10"next!! Guest VLANedit 4 set status enable set gateway 172.16.17.25&n
Hi , I'm Currently facing an issue with My Fortinac-VM i already Download the new version 9.4.7 but when i press install it's sending me to the page to start the download when i press it nothing happen any suggestion
Hello,I have to go through the "Automatic Patch Upgrades" wizard each time I connect to my FortiGate. I am using version 7.4.6 of FortiOS.Does anyone know the solution to this problem?
Hello,I would like to inquire about the automatic update management for FortiManager that is integrated with FortiGate and the Security Fabric.Could you please provide information on how automatic updates are handled in this setup?As far as I know, when a FortiGate is connected to a FortiManager, the FortiGate shows that automatic updates are enabled, and because it is managed by the FortiManager, the option to disable automatic updates is not available on the FortiGate.So, does this mean that automatic updates are not actually performed on FortiGates that are managed by FortiManager?I would like to perform updates manually when I want, and I do not want automatic updates to be applied.Is there anything that needs to be configured separately on the FortiManager side? Thaks all.
I have duplicated dashboard like below pic for some my fortigate, anyone know why?
I often have customers who lose their wireless connection.if I look in the Fortianalyzer I have this log .Someone has an idea why?How to stabilize customer connections? --------------------------------------------------------------------------------------------------------------------------------------------Actionclient-disconnected-by-wtp EncryptionN/A Levelnotice ReasonUnspecified reason Securit Actionclient-disconnected-by-wtp EncryptionN/A Levelnotice Reason Reserved 0 Securit ---------------------------------------------------------------------------------------------------------------------------------------------- Thank you for your help !
Hey,I'm trying to limit my students from using all of their devices on the school's wifi network at the same time. I've changed policy-auth-concurrent to 1 (https://kb.fortinet.com/kb/documentLink.do?externalID=FD33675) in hope that this would help I use WPA2 enterprise for the SSID and I use the local FortiGate user database for authentication. I log on just fine, but it still lets me log on with both computer, phone etc. at the same time My question is: Is policy-auth-concurrent the command to use for this or am I all wrong? Anyone know what I could be missing or if there are other commands more suitable for my problem It used to be a simple task with my old Untangle firewall, but seems a bit more complicated here ;-) Sincerely Leswan
FortiClient 7.4.3.1736 has no reaction after set username, password and click on Connect. In forticlient-logs/confighandler.log are messages as:20250428 16:00:13.520 TZ=+0200 [confighandler:EROR] decorators:52 Failed to send message to fortitray: runtime directory not found20250428 16:00:13.644 TZ=+0200 [confighandler:EROR] decorators:52 Failed to send message to fortitray: runtime directory not found20250428 16:00:30.087 TZ=+0200 [confighandler:EROR] about:105 Failed to get icdb metadata: i/o error: No such file or directory (os error 2)20250428 16:00:31.506 TZ=+0200 [confighandler:EROR] about:105 Failed to get icdb metadata: i/o error: No such file or directory (os error 2)20250428 16:00:57.295 TZ=+0200 [confighandler:EROR] antivirus:49 Failed to get total quarantine entry count: i/o error: No such file or directory (os error 2)20250428 16:01:01.375 TZ=+0200 [confighandler:EROR] about:105 Failed to get icdb metadata: i/o error: No such file or directory (os error 2)20250428 16:01:29.
I have been working on a Fortigate that has over 7000 devices using it as a router and sometimes it goes over 7500 devices. I have noticed that some useful Dashboard widgets and FortiViews seem to reach a limit where they will no longer display more data. For instance the Device Inventory widget will only show up to 5000 devices and it seems if you filter the data it only applies to those 5000 devices. This causes an issue because there is a possibility if I am looking for a specific device it won't be in the 5000 devices that I can filter. I have noticed a similar effect with the DHCP widget but its limit seems to be 7500. Is there any way to increase these limits?
Is there a way to set a custom name of the Forttoken that is mailed to the users (barcode) from the FortiGate?Instead of having the "Fortitoken EFS8", have "Fortitoken Office".I know it can be manually renamed in the Fortitoken app.
Hi everyone.I'm asking if is there a way to order listing of devices in Assets widget (i.e. for ip, Software OS, Last seen, User.....) and if is it possible to mantain certain selected colums to visualize, 'cause everytime I open the widget it reports default columns.I also can't see donut charts in this widget, but i read it's because my Fortigate 60F (FortiOs 7.4.4) is diskless.It would bo so useful for me, but I believe fon many others... it seems impossible to me Fortinet didn't do it. Thamk you for every answer
Dears, I have build an SD-WAN project for one of my customers that has 2 wan links (ISP1 with public IP, ISP2 F5 modem). Once I come to VPN configuration to connect all branches, I used to go with a dual-up hub and spoke. I have created the VPN in the normal way from VPN category. I have seen a document was explaining how to create VPN under SD-WAN as link below, but still I'm not sure if that scenario was helpful to my case, as I have 2 WAN one of them only with public IP. Im not sure what is the difference between creating VPN from VPN category or from SD-WAN to be added as a member!?Pls can anyone explain and advise about the difference if we have 2 public ips, or in my case 1 public and 1 5G modem with private IP. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/209840 thanks
I am unable to login forticlient vpn. using MACBookPro M2. error1: when install forticlient:"Initialize VPN system extension was failed." error2 when configure and login to VPN:"To connect to a VPN with FortiClient, open Security & Privacy Settings and allow system software from FortiTray." Verified full disk access and noticed fmon and fmon2 unable to add thereReinstalled 5 times forticlient to fix this issue - no success
Hi, just wanted to point out an spelling Error in the second image of the guide from this link:https://docs.fortinet.com/document/fortiextender/7.6.0/admin-guide-fgt-managed/201700 The image shows a FortiGate with the description ForitGate. This has been the way since 7.0.0 till 7.6.0. Version 7.6.1 uses a new image without the spelling error.Old:New:
Hello,After reviewing the release notes for FortiOS 7.6.3, I noticed that SSL-VPN Tunnel Mode is no longer supported.Does this mean that all users who rely on FortiClient will need to migrate to IPSec?I still do not fully understand the differences between SSL-VPN Web Mode and Tunnel Mode, so I would also appreciate a brief explanation of these.Additionally, I have an environment where I need to continue using SSL-VPN for the next two years.Would it be safe to continue operating with an earlier version of FortiOS (7.6.2 or below) that still supports SSL-VPN functionality?I would appreciate any responses or insights from the community.(Please note that this translation was generated by AI, so I apologize for any mistakes in advance.)
Hi EMS adminsHow many FGT can I integrate with my EMS (7.4.3)?Does is support a high number like 80?
We're pleased to announce FortiSOAR release 7.6.2. The main features of this release include: New dashboard visualizations that provide more options for displaying and interpreting data A new Playbook Developer widget that simplifies working with nested playbooks High availability enhancements A new version of FortiAI with improved playbook generation capabilities, and the ability to build a FortiSOAR connector using AI Release Notes: https://docs.fortinet.com/document/fortisoar/7.6.2/release-notes/800030/fortisoar-7-6-2-release Upgrade Information: Upgrade to this version from FortiSOAR 7.5.0, 7.5.1, 7.6.0, or 7.6.1.
Hi. I've been a user of SSL-VPN until it was removed from the latest firmware.I've clients using ubuntu linux variants and have problems setting IPSEC for them via strong swan. Any advice if switching to ZTNA would solve most issues?I presume I can install this "ZTNA Forti s/w" on linux?Would just getting a ZTNA licence be enough? What about the configuration of EMS. How is it done? Another question I have is I've 2 Fortinet. Fortinet 1 has a public uplink and serves some services in the clear.It has a port that is attached to Fortinet 2 that turns on and off.Fortinet 2 serves services in a locked-down environment. Would I be able to have ZTNA running on Fortinet2 having Fortinet1 as an uplink?End state is my users be able to connect to Fortinet1 and Fortinet2 one at a time to use services in both networks.
I opened a ticket on this but maybe this will be faster... I am running FortiClient 7.2.4.0850 on a MAC runing macOS 14.5. But I also have a need to run CloudFlare WARP once a week. But the logs for WARP show that the ztagent is running and that port 53 has been redirected to the Fnet app. I do not currently have ZTNA setup at all in FortiClient. But regardless, there must be a way to shut down the client fully for a short time so I can run WARP for a few hours a week. When I do try to shutdown the forticlient processes they auto restart on my MAC. Does anyone know if there is a way to kill them off for a few hours then manually start them up? And yes I am connected to an EMS.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.