Mark a Best Answer
Fortinet Community
Recently active
Hi All, I'm trying to setup:Fortigate 40F v.7.2.11 as VPN IPSec server.Apple iOS as VPN IPsec client, the built-in client.I'm still trying to use IKE1 to do not go with certificates for now.The problem what I see is:Whenever I'll enable Split tunnel and only expose specific networks (IPv4 works, IPv6 not) it's works.On Windows with Forticlient both networks are working IPv4+IPv6, so IPv6 issues could be Apple centric case, not focusing right now.Whenever I'll disable Split tunnel and want that all traffic from iOS go thru Fortigate once VPN is UP the session do not come up.Before I'll provide my technical setup, I just want to ensure, it is even possible to have such scenario that Split Tunnel will be disabled and all traffic will go over Fortigate (IPv4+IPv6, even only IPv4) using built-in Apple iOS VPN client?Have anyone done that?In theory it should be, because SSLVPN using Fortigate client on iOS (IPv4 only of course) is able to do so, but as SSLVPN is going away, I'm looking
Dear All. I have S2S Ipsec tunnel with configured performance SLA from HQ to BR. due to some reason customer has changed ISP to new ISP. So I have changed IPsec gateway old to new IPsec Gateway. When I changed IPsec using GUI. i has changed but we use command to check into CLI - get router info routing table details x.x.x.x. Here still showing Old IPsec Gateway. but in the GUI it is showing changed. S2S Ipsec tunnel are showing up, I have changed only Ipsec Gateway. even after showing IPsec tunnel up Performance SLA is showing down. Can you suggest also why Old Ipsec gateway is showing in CLI tunnel interface. Let suppose old Ipsec gateway was 1.1.1.1 and I changed it 2.2.2.2 thats it.thanks.
Hello,I tried to install FortiClient 7.4.3 on Suse Leap 15.6 with this result:bad dependecies systemd-libs > 0 je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXcomposite >= 0.3-1 je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXcursor > 1.1.2 je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXdamage >= 1.1 je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXext je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXfixes >= 5.0 je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXrandr >= 1.2.99.3 je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64 libXrender je potřeba pro forticlient-7.4.3.1736-1.el7.x86_64
Try to config ZTNA Shortcuts on SASE end point already integrated with Entra ID. Need clarify config user samledit "saml_ztna"set cert "Fortinet_CA_SSL"set entity-id "https://fgt9.myqalab.local:7831/samlap"set single-sign-on-url "https://fgt9.myqalab.local:7831/XX/YY/ZZ/saml/login/"set single-logout-url "https://fgt9.myqalab.local:7831/XX/YY/ZZ/saml/logout/"set idp-entity-id "http://MYQALAB.LOCAL/adfs/services/trust"set idp-single-sign-on-url "https://myqalab.local/adfs/ls"set idp-single-logout-url "https://myqalab.local/adfs/ls"set idp-cert "REMOTE_Cert_4"set digest-method sha256set adfs-claim enableset user-claim-type upnset group-claim-type group-sidnextend The entity-id single-sign-on and single-logout URLs from SASE and idp URLs from SMAL authenticator ( In My case it's Entra ID ) i follow below guidelines https://docs.fortinet.com/document/fortisase/latest/spa-using-ztna-deployment-guide/976373/configuring-authen
Hello and sorry for my english, In fortigate automation, i have FortiOS Event Log on 'admin login successful' and after sticth to send email. that works very good. When admin connect, i receive email. But i want only alert the night from 9.00 PM to 8.00 AM, it is possible ? thanks a lot
Some one can help me how to appear RIP,OSPF, BGP in my firewall
When I tested it through FortiVPN with a Windows 10 laptop, it worked fine, but when I tested it through FortiClient with a Windows 11 laptop, it didn't work.It is the same environment except that Windows 11 laptop has EMS interworking as FortiClient.What is the problem?
Hi we deployed a firewall and there is no webfiltering on.client can ping printer and it gets added in 3d software but something block file transfer and client can't put things in que or print on this particular 3d printer they just bought.it works fine if we connect a network switch with both pc and printer without firewall connecting to switch Plz help
I can't add any FGTs to my FMG within Eve-NG, debugs are showing it to be a SN issue, found several post to do below, but I don't seem to have that option on 7.4.6 The fix is to disable cert check:FMG-VM64-KVM # config system global(global)# set fgfm-peercert-withoutsn enable Any help would be greatly appreciated? Thanks
I created DNS rule for access internal domains from clients but not resolving URLs. How can i troubleshoot the issue?
Good morning!I have problems with connecting 2fa vpn. I have IPSEC tunnel vpn. If I connect vpn with 2fa it dies immediately and does not even allow me to enter a password. But if I turn off 2fa, everything works fine.I used thisconfig user local edit "epass" set type password set two-factor email set email-to "manny@infosecmonkey.org" set passwd SuperSecretPassword next endmail server isconfig system email-server set server "notification.fortinet.net" set port 465 set security smtps endand thats all
Getting ready to take the secure wireless lan 7.4 exam to finish my fcp. Just seeing what anyone else's experience is with this test or previous versions of the FortiAP test https://mobdro.bio/ .
Hello everyone. Thank you very much for trying to help me. I'm sharing my question or problem, as I don't know if this is expected behavior.I changed the FortiCloud account for my Fortigate from the website, using the "Transfer FortiGate to another account" option.But this only seems to have changed the account for my master Fortigate. On the website https://support.fortinet.com/asset/#/views/products, only that account appears, not the slave account.What am I doing wrong, or what should I do to get the two to sync? Regards
Hi, This query is related to DHCP. I configured the DHCP lease time to 7 days, and everything is functioning correctly overall. However, a few users encountered an issue where they received an IP from DHCP but were unable to access the internet. Releasing and renewing the IP resolved the problem. Upon investigation, I discovered a known issue (Bug ID: 1069208) in v7.4.7 related to DHCP. Bug ID: 1069208 indicates that if a DHCP offer contains padding while using a DHCP relay, the relay removes the padding before forwarding the packet. Please confirm whether this bug is related to the issue we are facing. #fortigate
Hello, We have been trying to setup a Dial-up IPSec connection for our remote user base (30-40 users) seeing as SSL-VPN is being/has been removed from FortiOS 7.4 and newer (we are currently on 7.2.11). I can get a single machine to connect and work as intended, but when I connect another user device, it connects but there is no traffic that returns to the user. It seems like only one connection works, all subsequent are denied. I've "set add-route disabled" from the CLI on the interface, but that didn't help. So far none of my searches have turned up anything more than that. If it matters, our working SSL-VPN uses SAML and I have a similarly configured SAML for the Dial-Up Ipsec. Sorry in advance, I am very green when it comes to these FGT. Phase1edit "vpn_Dial-Up"set type dynamicset interface "port35"set ike-version 2set peertype anyset net-device disableset mode-cfg enableset ipv4-dns-server1 #.#.#.#set ipv4-dns-server2 #.#.#.#set proposal
I got in touch with non-upgraded Fortigate 100E which got compromised (it had 7.0.8 and WAN HTTPS access enabled :\ ).The attacker logged in with non-existing accounts to jsconsole (probably known CVE with the version mentioned) and also connected to VPN with existing VPN account (is it possible he got plain text password or the password leaked?).I cleaned all the users attacker created, checked the configuration, disabled WAN HTTPS, applied GeoIP for VPN and upgraded to 7.2.11 https://1921681254.mx/ .Despite actions taken the auto-script will create new super admin user every day at 15:30 . There is no auto script listed using [get system auto-script]. Probably something on the OS or bootloader level.I tried to load firmware from USB flash using [execute restore image usb] but the hidden autoscript still creates new user every day.How to fully wipe Fortigate and load new clean system using flash drive or TFTP?
We were running v7.2.10 on multiple hardware platforms without issue. Security came along and told us we had to update software due to a CR so we are now running v.7.2.11.Since the update our Firewalls are now losing OSPF adjacencies to the core switches every couple days or so. The biggest offender only has one instance of OSPF running but some Firewalls have 4-5 instances of OSPF running (multiple VDOMs) and we lose adjacency on all vdoms simultaneously.I don't think it's a resource issue; we have beefy hardware; 4201F, 2601F, 1801F.Anyone else seeing this? Any workarounds?As always, thanks!
Hello , In my lab sd-wan everything is ok all my vpn up I create 4 vpn in a vpn zone i create a policy between my lan and the zone a static route between lan and zone vpn but i cannot ping my remote branch .
Hi everyone.I would like to display antivirus log in my Fortigate F60 (OS 7.2.11).In the forum I've noticied that I have to set the value "av-virus-log" to enable.In the CLI, I've edited the profile and I've entered the command "set av-virus-log enable".But there is no impact, when I want to show the different value of my profile, the value does'nt exist.Have you an idea ?Thank you in advance
Dear Fortinet Community,I hope this message finds you well. I am reaching out to inquire about the availability of firmware versions for the FortiGate 200G model. Currently, I see that even newer devices such as the FortiGate 90G are running on firmware versions 7.4, but there are no firmware upgrades beyond 7.2.8 and 7.2.11 available for the 200G model.Given the advancements in newer models, I would like to understand why the 200G model has not yet received the 7.4 upgrade. Additionally, I am eager to know when newer firmware versions will be available for the FortiGate 200G device.Could you please provide any insights on this matter? Specifically, I am interested in knowing whether there are any plans to release firmware versions beyond 7.2.11 for the FortiGate 200G, and if so, what the expected timeline for such releases might be.Thank you for your assistance, and I look forward to your response.
Hello everybody,regarding ZTNA, we found a bug after yesterday Forticlient EMS 7.2.5 upgrade.This is happening only on macOS devices.We have a ZTNA destination profile:On Windows device, rule are correctly retrivied. But, on macOS, I can see no destination (I have all the tags I need):Debbuging this problem, I was looking at the Forticlient ztna.logs, and I found (I removed some rules for simplification): 2024-10-11T16:24:28.238 TZ=+0200 info ztna mergeCfg:{"enabled":1,"rules":[{"name":"EMS","mode":"transparent","enabled":0,"destination":"10.1.0.217:3389","gateway":"ztna.ntditalia.com:13389","encryption":1,"local_port":"7788","type":"private"},{"name":"VMAgostini","mode":"transparent","enabled":0,"destination":"10.1.0.215:3389","gateway":"ztna.ntditalia.com:13389","encryption":1,"local_port":"7788","type":"private"}],"portals":null,"gateways":null,"notify_on_error":1,"portals_enabled":1,"gateways_enabled":1}2024-10-11T16:24:57.148 TZ=+0200 info ztna sync portal select portal err:e
looking to centrally manage and lock down FortiClient configuration settings through FortiClient EMS (Enterprise Management Server)
Hi Team,Is there a way to enable Interface Pair View on a FortiGate 121G without removing the existing policies? From what I’ve found, it seems that enabling this option via CLI may result in the deletion of current policies.I’d appreciate any guidance that would allow this without impacting the existing configuration.
Some time i got anomaly traffic like below pic.We can see below my NPM server (10.103.248.55) monitor on of my VM on azure (10.201.1.7).All non PING traffic have right path where the traffic routed to Azure Tunnel Interface.But PING traffic routed to the internet so my NPM server detect this VM as down.If we restart the NPM server then the PING traffic routed to the right interface.Anyone ever facing same issue with me?
Hello, I'm new at this so be patient with me. I'm unable to connect to my network remotely via IPsec VPN - I can connect on first PC - however unable to connect via second PC. I checked the client configuration on working PC and matched on PC that isn't connecting. From my forticlient that isn't connecting via IPsec VPNIKE phase1 authentication fail as peer's certificate is not verified 2/2/2023 10:52:16 AM info sslvpn date=2023-12-02 time=10:52:15 logver=1 id=96602 type=securityevent subtype=sslvpn eventtype=status level=info uid=C936E3C1403F4C3B9369EFE22C3B5171 devid=FCT8000484597987 hostname=DCDDCD-VKISEE7Q pcdomain=N/A deviceip=172.16.80.11 devicemac=34-17-eb-c3-e9-f4 site=N/A fctver=7.2.0.0690 fgtserial=FCT8000484597987 emsserial=N/A os="Microsoft Windows 10 Professional Edition, 64-bit (build 19045)" user=jakec msg="SSLVPN service started successfully" vpnstate=12/2/2023 10:52:25 AM info system date=2023-12-02 time=10:52:24 logver=1 id=96823 type=systemevent subtyp
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.