User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
mailfilterd stuck at ~100% CPU, FortiMail 8.0.0 build 183 — cause unclearFortiMail 8.0.0 build 183. mailfilterd sits at ~99.8% CPU continuously (not a spike), RSS grown to ~1.5GB (baseline is usually ~100MB). All other processes idle. Session count (24–50) and bandwidth are normal, so it's not a traffic flood.Enabled diagnose debug application mailfilterd level 8 + duration 30 and pulled the Trace Log. The only thing logged for 10 minutes was:FmailAIClient.cpp:931:ping():entryrepeating once a minute, on a single thread, with no other activity captured — looks like a routine heartbeat, not the actual hot path.I can't figure out what's actually causing the 100% CPU. Any help would be appreciated.
Hi Team,We currently restrict our FortiGate SSL VPN access to users connecting from the UAE region using GeoIP restrictions.However, some vendors are based in Egypt and may RDP into their office PC located in the UAE, and then establish the FortiClient VPN connection from that UAE PC.Is there a way to configure FortiClient EMS to restrict VPN access based on the client’s public IP or location, so that if the actual client is connecting from outside the UAE, the VPN connection is denied?Any recommended configuration or best practice would be appreciated.
Hi Community,I’m experiencing performance issues with FortiAP FAP-231G and would appreciate some advice from anyone who has deployed this model in a high-density environment.When the AP has more than approximately 30 clients connected, especially during Microsoft Teams meetings, I experience the following: Some clients are unexpectedly disconnected from the FAP-231G. Clients are sometimes forced to roam/reconnect to a much farther AP, even though the FAP-231G appears to have good signal strength. The issue is more noticeable during Teams meetings and other traffic-intensive activities. With fewer clients, the AP appears to perform normally.I would like to understand whether this could be related to FAP-231G capacity, radio configuration, client load balancing, roaming thresholds, airtime utilization, or FortiAP/FortiGate configuration.My environment is using FortiGate-managed FortiAPs.Has anyone experienced similar behavior with the FAP-231G? If so:1. What is the recommended number of
I am using FortiNAC-CA / FortiNAC-OS v7.6.5.0815 (GA) together with a FortiGate and I would like to implement a daily Internet usage limit for self-registered guest users.My requirement is:Guest connects to the Guest Wi-Fi. Guest self-registers through the FortiNAC captive portal. After successful authentication, the guest receives Internet access. The guest is allowed a maximum of 1 hour of Internet access per day. After the 1 hour is consumed, Internet access should be blocked automatically. The guest should not be able to regain access by disconnecting/reconnecting or registering again. After the daily 24-hour reset, the same user/device should receive another 1 hour of access. Ideally, the limitation should be based on the user or device/MAC address, so creating another self-registration session does not bypass the limit.I understand that FortiNAC has Account Duration and Reauth Period, but from the documentation it appears that Account Duration is not a recurring daily quota. For
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
Currently, the FortiGate 60F is experiencing an inconvenience when there is an electrical power outage and the equipment starts operating using the UPS.When the power change is produced, the FortiGate apparently falls down and stops allowing network traffic, both incoming and outgoing.The way it has been used to restore the service is to physically disconnect the FortiGate and reconnect it to electrical power. After carrying out this procedure, the equipment normally starts correctly and allows network traffic again.However, on one occasion the FortiGate did not start correctly even after disconnecting and connecting it again, which increases concern about the cause of the problem.
Hi, Has anyone had any luck getting FortiClient vpn working on Tahoe? so far iv had 0 success .All windows based clients work fine however
nslookup v4-aws.api.intuit.com 96.45.45.45Server: dns1.fortiguard.netAddress: 96.45.45.45*** dns1.fortiguard.net can't find v4-aws.api.intuit.com: Server failednslookup v4-aws.api.intuit.com 96.45.46.46Server: dns2.fortiguard.netAddress: 96.45.46.46*** dns2.fortiguard.net can't find v4-aws.api.intuit.com: Server failed
Hello everyone! Recently we upgraded our Fortigate (120G HA Active-Passive cluster) from 7.2.11 to 7.4.11, and different problems started to occur.Some users spontaneously lose access to the Internet with ERR_TUNNEL_CONNECTION_FAILED (we use explicit proxy with Kerberos authentication and deep ssl inspection). It happens at random times and with random users, lasts usually up to 2-3 minutes, then works as usual.FortiGates started to randomly reboot with the message "Fortigate had experienced an unexpected power off!", there's no CPU/RAM issue, usually mem is around 40%, and proc is around 10-12%. Due to fast HA failover users don't feel the interruption, but it's definitely not a good sign. Before the update both NGFW had worked for 367 days.Anyone experienced similar issues? Any workarounds? Or should I just be rolling back to 7.2.11?Any advice and help will be appreciated. Thank you in advance!
ScenarioEnvironment with multiple FortiGate firewalls connected to a FortiAnalyzer VM for centralized log collection and analysis.Environment VersionsFortiAnalyzer VM: 7.4.11FortiGate: 7.2.13Fabric ADOM enabledSome FortiGate devices operating in HA cluster modeAfter upgrading the FortiAnalyzer from version 7.4.6 to 7.4.11, the FortiGate devices stopped displaying FortiAnalyzer logs directly from the FortiGate GUI.SymptomsWhen accessing logs from the FortiGate GUI:Log & Report → Forward Traffic / Event Logsthe page remained completely blank.However:FortiAnalyzer continued receiving logs normallyDevices remained online in Fabric View / Device ManagerLogs were visible directly in the FortiAnalyzer GUINo explicit communication or authorization errors were displayedAdditionally, the following behaviors were observed:Analytics (actual/config days) above 100%Archive Usage above 90%diagnose dvm device list showing:conn: unknownconf: unknowndev-db: unknownThis initially suggested a possible
Hi everyone,I’m planning to migrate from SSL VPN to IPsec VPN. Here’s the situation:The FortiClient app is already installed on users’ devices, and I need a way to deploy the IPsec VPN profile to those devices via Intune (all devices are managed by Intune).I’m currently using the VPN-only version of FortiClient, and as far as I know, deploying VPN profiles centrally requires an EMS license.Could you please advise if there’s any alternative solution in this case?Thanks
i have newly created VIP rule to publish local microsoft dynamic test server to the internet to access anywhere, but the vip rule not hit any packets.attached the rule screenshot and policy, any help from the community team would be appreciated
I have a VIP IP address defined on my Fortigate Firewall, and I'm using Cloudflare with a proxy enabled. When I log the source on the firewall, I only see the Cloudflare IP address. Is it possible to see the incoming VIP traffic as if it were the real IP address?
Hi,I would like to know if anyone else is experiencing similar issues with FortiEndpoint EMS Cloud and the integrated FortiEDR feature.Our environment is currently running:FortiClient EMS Cloud: 7.4.7 build 2194 (Mature) FortiClient: 7.4.7 Windows 11 25H2: Build 26200.8875 FortiEDR Engine assigned by EMS: 5.2.8.0044Originally, we noticed that some endpoints using the same EMS policies and profiles had FortiEDR working and connected, while others showed FortiEDR Disabled in FortiClient and Disconnected in FortiEDR Cloud.Both working and affected endpoints are operating in the same environment and network, which makes the different behavior seem questionable. We are also seeing the same issue on endpoints in customer environments, so it does not appear to be limited to a single device or network.We also tested multiple FortiClient versions, including 7.4.4, 7.4.5, and 7.4.6, but the behavior remained the same.On affected endpoints, the Collector reported:FortiEDR Detected incompatible ma
We are currently evaluating our options and already have a quotation prepared for a licensed FortiClient solution, which is awaiting final approval and signature. Our organization has two FortiGate firewalls with active licenses and has been using FortiClient VPN Free Edition 7.4.3.4726 as our VPN client.Approximately 20 days ago, one of our security partners advised us to remove or upgrade FortiClient VPN 7.4.3 due to a reported vulnerability. As a result, we upgraded to FortiClient VPN 7.4.8. However, we later discovered that this version appears to require FortiClient EMS for ongoing management, leaving us uncertain about the most appropriate temporary solution.We have been unable to determine whether FortiClient VPN Free Edition 7.4.3.4726 remains secure for continued use. The software is still available for download, and discussions in community forums appear to reference different CVEs than the ones currently under review.As part of our evaluation process, we would like to unders
I am currently using MACOS Sonoma when I use FortiClient and connect to the client but I have no access to my internet. I even tried using the router to add a new wheel and nothing worked I can't ask the client to change their settings outside. I need a solution I saw a video on the internet saying that Sonoma has a VPN problem. Link youtube: watch?v=F60PBFlhjMQ&t=30s But is it really Sonoma?
So, MS Surfaces and Forticlient VPN have been one of my Nemesis' at a specific site for a specific user. Previously when we upgraded his Surface Pro a few years ago, when he'd connect via SSL VPN, internet connectivity would slow way down, at that time we were using the free Forticlient and got permission from Fortinet to get a trial version of the paid client to see if issue was FC related. After a lot of back and forth, the issue was resolved and I and the user was happy. I am going to review that ticket again and make sure there wasn't some kind of work around put in place that may be affecting this. Fast forward to the beginning of June, we replaced his Surface and used our typical tool (TransWiz) to transfer his existing Windows profile to new machine, he was happy. A few days later I get advised that when FortClient Free VPN is connected ALL internet traffic that's not across the link stops, example if I have a remote session with him I loose connectiv
Hello!I just recently downloaded the Hyper-V image for FortiGate-VM, version 8.The VM boots fine, no issues, the CLI is accessible through SSH.When comes time to apply the evaluation license, it seems to fail (using the “exec vm-license-options” command).On the Web GUI, the evaluation license seems to apply (by logging in with my Fortinet account) but after a reboot, it says “No License” in the system status.Then, in the Web GUI, I login, briefly see the “what’s new” video pop up and then it pops back to the login screen.Any ideas?Thanks!EDIT: I forgot to add that when running “exec vm-license” it requires a token, which I do not have.
I have a brand new out of the box Fortigate 90g. I’m setting it up, and I get to Network → DNS, and I enter Comcast’s DNS servers (Since it’s on a comcast line). The firewall immediately says the IPs are unreachable, however, I also told the device to run a dhcp server, and hand out comcast dns as the dns on the leases. The clients are fine, they can resolve addresses all day, no problem it’s something with the fortigate itself, it can’t “use” these addresses. It’s also saying it’s unable to connect to FortiGuard servers for support info.I tried doing the execute ping command from the cli, it dropped a few packets at first, then was 100%. Is there some filter or something I should turn off (web filter on the WAN interface, maybe? ) that’s causing this? the IP addresses I’m using are 75.75.75.75 and 75.75.76.76 thanks.
dear mam/sir, i need to upgrade the firmware of the fortinet this is my client’s fortinet to repair fortinet i want firmware of FWF40C3912006020 fortiwifi -40c thank you Tejesh Maharjan
Hello,We are moving store suites and AT&T is changing their IP address.So we need help updating the new IP address configurations.The move occurs this Saturday, 29th at 5 PM PST.Can we schedule a time to make changes?
We have a FortiGate-VM running on a trial/evaluation license that expired on July 2 (about 2 months ago). We're planning to deploy a new FortiGate-VM instance (same IPs) and push the existing configuration backup to it, then license the new instance properly.Is it possible to restore a config backup taken from an expired trial VM onto a newly deployed VM instance with a different serial number?
We have become aware of the following security advisories regarding a vulnerability in FortiClient:https://fortiguard.fortinet.com/psirt/FG-IR-26-156https://advisories.ncsc.nl/2026/ncsc-2026-0296.htmlWithin our organization, we exclusively use FortiClient VPN-only for Windows. We do not use the full FortiClient client or FortiClient EMS.Therefore, we would like to know whether the vulnerability described in FG-IR-26-156 also affects the FortiClient VPN-only client.Additionally, we would appreciate clarification on the following:* Is FortiClient VPN-only affected by this vulnerability?* If so, which versions are affected?* Which version does Fortinet recommend installing to address the vulnerability?* Is an updated version of FortiClient VPN-only currently available?* Does the VPN-only client update automatically, or do we need to manually deploy the updated version to all our laptops?We would appreciate your clarification so that we can take the appropriate measures if necessary.Kind r
I try to build VPN remote access using ipsec to preparing upgrade my fortigate production from 7.2 to 7.6 on my lab.My fortigate lab use version 7.6.4 and after i create vpn tunnel, the forti client is connected and get the ip address but the client is not able to reach to anywhere. The firewall policy and static routing was working fine.Open case to the fortigate support and they also feel strange with this issue. Someone here can help how to toubleshoot?Here my VPN config===========================config vpn ipsec phase1-interfaceedit "VPN-RA"set type dynamicset interface "port1"set ike-version 2set peertype anyset net-device disableset mode-cfg enableset proposal aes128-sha1set add-route disableset comments "VPN Remote Access"set dhgrp 5 20set wizard-type dialup-forticlientset transport autoset fortinet-esp enableset ipv4-start-ip 10.64.200.20set ipv4-end-ip 10.64.200.50set dns-mode autoset save-password enableset client-auto-negotiate enableset client-keep-alive enableset psksecret
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.