Your feedback drives change, make your voice count
Fortinet Community
Recently active
This update adds three solution packs and refreshes the connector catalog with three new connectors and five updates.The new solution packs are:NetOps - FortiManager ZTP v1.0.0, for zero touch provisioning workflows through FortiManager. Outbreak Response - WP2Shell RCE v1.0.0, for investigation and response to the WP2Shell remote code execution outbreak. VM Lifecycle Management v1.0.0, for provisioning, tracking, and decommissioning of virtual machines.The connector changes are grouped as follows:Network and infrastructure: Forcepoint NGFW SMC v1.0.0, Proxmox VE Hypervisor v1.0.0, and Ping v1.0.0 are new additions. Fortinet FortiSIEM has been updated to v6.2.0. IT service management: BMC Remedy AR System v1.6.0 and ManageEngine ServiceDesk Plus v3.0.1. Endpoint and device management: AirWatch v1.0.1 and Trend Micro Deep Security v2.0.0.The following table summarizes the changes since the last announcement. # Type Name 1 Solution Pack NetOps -
HI all, I’m deploying a couple of 701G fortient onver an inter DCI (one fortinet on each DC) using vxlan (on a nexus 9k) and I found that when HA is enabled the same MAC are generated and for this reason this MAC’s are getting dropped from vxlan table and HA is not forming. If HA is disabled and I leave them as stand alone and put IP’s on the interfaces they can ping each other (the same for mgmt) once HA is enabled and the virtual MAC’s come in the connectivity on HA is not working and both MGMT can’t ping each other anymore and I have a duplicated messaje on my nexus logs. Does anyone know what could be wrong? Working on a 7.4.11 Regards
Hi erveryone,We use the FortiMail only as a filter.The MTA is provided by an external service provider.The FortiMail is therefore between our service provider and our internal mail server.We have deactivated the SPF check in the Antispam and in the Session Profile, because this is not needed in our construct.Nevertheless we get in the log for most mails a SPF Fail/Softfail with the message "that MTA (IP address) is/may not permitted to send email for ....".The mails are processed and sent correctly but this log entry bothers us.We are aware that the external MTA will normally trigger SPF since the mail is not sent from the original mail server to FortiMail.Is it possible to disable the entry, it is not relevant for us or is there another hidden setting somewhere that enables SPF checking?Are any of you aware of a similar problem or could it be something else? Thank you in advance!!
I have a strange case with some fortiAPs right now. 1x FAP 231G and 1x431F both on 7.6.4. I want to set a VLAN ID to have the management tagged but the variable is missing when typing cfg -s. Then i connected to the HTTPS GUI and the field is also missing. I typed in the command cfg -a AP_MGMT_VLAN_ID=200 on the CLI and I got no error. cfg -c for commit to flash. Nothing happened. Reboot and still no change, the AP won't take the VLAN ID. I have 100 more 231G on this site and also 20x431F and they all have the variable and it works fine. How is this possible? Anyone else encountering this problem?
I have a problem with FortiClient VPN 7.0.8.0427 on a few Windows PCs. When trying to connect I get:‘VPN Connection Failure - VPN connection failed. Please check your configuration, network connection and pre-shared key then retry your connection. If the problem persists, contact your network administrator for help.’The VPN does not work with any user account on the affected PC. The same users, the same VPN profile and the same FortiClient version work correctly on other computers. The problem was already present on a fresh Windows installation, so it is not caused by software installed later. Reinstalling FortiClient also did not help.Basic network connectivity looks fine. Internet connection works, the FortiGate is reachable and the client can communicate with the VPN gateway. I tested both Ethernet and Wi-Fi with the same result. Packet capture confirms that UDP/500 traffic reaches the FortiGate and the FortiGate response comes back to the affected PC.I also tested several other lap
Hi all, I have peaks of high CPU usage on the FortiSwitches FS-248E model. Theses FortiSwitch are in modo fortilink.The event is the following: How can I lower CPU usage? Currently very few customer traffic.Thanks,
Download links for FortiClient EMS invitations are not working because the filename in the invitation are Initial Cap, while the filenames are all lower case. Running version 7.4.8. This was working up to yesterday.
I am using FortiGate as aDHCP Server and Windows Serve as DNS (Active Directory). Clients are getting IP addresses correctly, but DNS records are not being created or updated automatically in WINDOWS DNS.So:DHCP works fineBut no A or PTR records are created in DNSIs this expected behavior with FortiGate DHCP, or is there a way to enable dynamic DNS updates?Any help would be appreciated.
I am having 4 VMs 2 each for FortiNAC and FortiAuth, reachability is completed, all kinds of https or http accesses are allowed from CLI, but still unable to access GUI of any machine
Hello, I would like to know if anyone in the community has any AutoCAD document with drawings of the devices, any of them really, but if I had to ask for just one, it would be the FGR-60F. If anyone has something like that, I would really appreciate it.
Hi,I have a strange case with some fortiAPs right now. 1x FAP 231G and 1x431F both on 7.6.4. I want to set a VLAN ID to have the management tagged but the variable is missing when typing cfg -s. Then i connected to the HTTPS GUI and the field is also missing. I typed in the command cfg -a AP_MGMT_VLAN_ID=200 on the CLI and I got no error. cfg -c for commit to flash. Nothing happened. Reboot and still no change, the AP won't take the VLAN ID. I have 100 more 231G on this site and also 20x431F and they all have the variable and it works fine. How is this possible? Anyone else encountering this problem?
Hey everybody I'm new . currently I'm working as a desktop engineer and I'm planning to start studying. In a fortigate firewall now can anyone tell me where to start this course any free resources youtube channel n all.
how can implement
We have 8 sites running fortigate with version 7.4 and 2 sites running fortigates with version 7.6. When creating ADOM, is it better to create 7.4 ADOM or 7.6 ADOM to import configurations from all sites? I assume configuration needs to be re-installed from FortiManager back to the Fortigate devices to validate configuration?
Hello Fortinet Community,I would like to better understand the behavior of FSSO group membership updates and firewall policy matching.Our environment has an FSSO Collector Agent monitoring two Domain Controllers. FortiGate receives the user logons correctly and applies policies based on AD groups. We also configured Group Lookup every minute, and we can confirm that the updated group membership is correctly reflected in FSSO/FortiGate.However, the change is not immediately reflected in the actual traffic.For example, we have an AD group that allows AnyDesk through a specific firewall policy:When a user is added to the group, the membership is updated correctly, but the traffic policy may take some time to apply. When the user is removed from the group, FSSO shows the updated membership, but AnyDesk may continue working for some time. We completely close and reopen AnyDesk during testing to generate new connections, but the previous policy may still be matched.My questions are:Is this e
Hello,We are planning to upgrade our FortiWeb HA cluster from version 7.0.9 to a newer stable release.However, we noticed that several versions are available (7.2.x, 7.4.x, 7.6.x, 8.0.x), and it is not clear which versions are considered as mature or feature.I tried to check whether Fortinet provides a Recommended Release for FortiWeb, similar to what is available for FortiOS, but I couldn’t find any official guidance.Additionally, the upgrade path does not seem to be available on the Firmware Images console. Could you please advise:Which FortiWeb version is currently recommended for production?The correct upgrade path from 7.0.9?Any known limitations or considerations for HA environments?Anything more that i should take in considerations for the new version ?
I try to install the FortiNAC on Azure for my HA but i try search FortiNAC on the marketplace and i didn’t find fortinac as documented in thisarticle FortiNAC Azure Deployment GuideHere available images from Azure Marketplace.
I have been experiencing this error message when trying to install the FortiClient VPN, and I keep getting the error message "Unable to access image servers." I have read on some other forums that if I try installing the VPN while connected to a mobile hotspot, I should not get this error message. But the error still persists. Any assistance provided will be accepted.
An insightful community-member posed a challenge that made us go back to the lab and change our hypothesis: Why You Can't Add DDNS to an Existing IPsec Tunnel — and why there is no zero-downtime workaround**Environment:** FortiGate-60F (FortiOS 7.6.7) and FortiGate-30G (FortiOS 7.4.12), site-to-site IPsec, route-based.If you built a site-to-site IPsec tunnel with a literal peer IP address and later needed to switch it to a DDNS hostname, you have probably found that FortiOS accepts every command you type and then discards all of it at commit. This article covers why that happens, the field-naming distinction behind most of the confusion, and — importantly — why the workaround that seems obvious does not actually work.---## The scenarioTwo FortiGates, site to site. One side holds a static public IP. The other is a home or branch office on a DHCP-assigned public address from the ISP.The tunnel was built with the peer's current address entered literally:```config vpn ipsec phase1-interfac
Hello FortiSIEM Community,I’m currently working on creating a custom parser for Aruba EdgeConnect logs in FortiSIEM, but I’m facing an issue during parser validation.Each time I create or modify the parser, the validation fails with the following error:Failed to execute node: when. Please check the usage of API and attribute name.I have double-checked the parser XML and verified that the attributes I’m using, such as hostName, procName, user, command, eventType, destName, destIpAddr, and srcIpAddr, are defined and supported in FortiSIEM.However, the error does not indicate which specific node, API, or attribute is causing the failure, which makes troubleshooting difficult.I have attached a screenshot of the parser validation error along with the current parser configuration.Would anyone with experience in FortiSIEM custom parser development be able to assist me in identifying the root cause and correcting the parser?Any guidance or example of the correct parser structure would be grea
I have some Reolink camera equipment on my network. Its all on the same VLAN (2 different switches), and it talks to each other, but the devices are showing the wrong IP. If I look in the Fortigate on the port the NVR is connected to for example, it says its IP is totally different than what shows on the NVR when I go into its settings. A different subnet even, as the FG says 10.x.x.x but on the device it says 192.x.x.x. Now I imagine this is just the device’s internal network it creates perhaps. But its the same thing for the cameras which are connected directly to a fortiswitch. And if I look at their mapping from the NVR, they all show the 192 addresses as well which is at odds with the VLAN they are on and what the FG tells me they should be. It all wouldn’t matter except for one problem. I cant connect to the NVR or cameras externally. There is a firewall rule present that allows that VLAN to go out to the internet, so I’m not sure what the problem is. If I manually change the NV
Hi , I am trying to understand what is the purpose of the configuration :EMS CA Certificate (ZTNA) under EMS Settings.Is this supposed to allow EMS administrators to install a CA certificate onto the users device CA bundle?
https://fortiguard.fortinet.com/psirt/FG-IR-26-156FG-IR-26-156 (CVE-2026-70465) advisory states the fix is available in FortiClient Windows 7.4.4 / 7.2.12 and later. However, the free VPN-only agent has not received a new release since 7.4.3 (per the community note that v7.4.4–7.4.8 include no new free VPN-only build).Could you confirm: 1. Is FortiClient Free VPN-only 7.4.3 (build 4726) vulnerable to CVE-2026-70465? 2. If yes, will a patched free VPN-only build be released, or is upgrading to a licensed version the only path to remediation? Thanks in advance.
Hello, I am wondering if it's possible to manage AP's without a fortiswitch? Company just bought a Fortigate to be used but they are sticking to the old Entrasys switch. I have it connected but it keeps using the main internet (10.1.1.x) and I am unable to find where to assign the proper VLAN tag for it. It needs to go to on the (10.1.2.x). Old switch has the proper VLANs tagged, now I just need to figure out how to get the AP to use the right VLAN.
I am automatically updating FortiClient for Windows from version 7.4.5 to 7.4.6. On about 50% of the test computers, the installation process stops at: “Stop services.” I also tried doing it manually by running the installer file, but in that case it also gets stuck at “Stop services.” How can I work around this issue?I have updated versions 7.0.x and 7.2.x many times before and never had this problem. Now I’m updating to version 7.4.x for the first time. Has anyone had a similar issue?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.