Your feedback drives change, make your voice count
Fortinet Community
Recently active
Greetings,Looking for advice on best way to migrate from current Palo Alto in Azure to FortiGate.Can it be deployed into the same subnets, or does it need to be in new subnets same vnet?Thanks!-Greg
I enrolled my forticlient with the EMS, it shows “connected”.When I try to connect to the VPN (SAML Login), it’s stuck “connecting”.Two problems come to mind:* It doesn’t show the SAML popup (auth through azure) as it does on windows.* when looking at service log, last line says /opt/forticlient/iked: invalid option -- 'P'I tried a number of things, starting the session with X or Wayland, no change, setting the open in external browser setting flag … with no success.Help
Hi everyone,I have configured DNSBL under Profile > AntiSpam > AntiSpam on my FortiMail.I'd like to verify whether the DNSBL configuration is actually working as expected. Is there a way to confirm this from the FortiMail side?Specifically, I'm looking for answers to the following:Are there any logs or event logs that indicate DNSBL lookups are being performed? Is there a CLI command or diagnostic command that can be used to verify DNSBL functionality? What's the best practice for testing whether DNSBL is functioning correctly?If anyone has experience with this or can share the recommended verification steps, I would really appreciate it.Thank you in advance!
Hi everyone,I'm currently setting up FortiXDR and I'm a bit confused about the required FortiAnalyzer configuration.Our environment consists of:FortiClient EMS Cloud FortiXDR license Local FortiAnalyzer VM (no FortiAnalyzer Cloud license)We do not have a FortiAnalyzer Cloud license, only a local FortiAnalyzer VM.My question is:For FortiXDR, where should the FortiClient logs (configured in the System Settings Profile) be sent?Should the FortiClients send their logs to a FortiAnalyzer Cloud instance, even though we don't have a FortiAnalyzer Cloud license? Or is it supported to send the logs directly to our local FortiAnalyzer VM while still using FortiXDR?Most of the users work from home, so we are currently using a DNAT with TLS configuration.Has anyone successfully deployed FortiXDR with EMS Cloud + local FortiAnalyzer?Kind regards,MG4
Hi all,just started my first FortiSwitchNMS deployment with about 50 FortiSwitch Rugged at a customer site and am now planning further steps to improve the whole setup.Since the product is quite new and community resources are limited, I wanted to reach out and see if anyone here has done something similar or already deployed the product in general.I'm planning to use ZTP via DHCP option 138 to onboard the switches.Has anyone actually used this in production? Curious whether it works reliably out of the box or if there are quirks to watch out for.I'm also trying to figure out what good day-to-day operations would look like or which features you like.There are functions for backup management that sound quite useful for device replacement scenarios, and I'm wondering how others handle firmware rollouts across a larger switch fleet without things going sideways.The VLAN management in the NMS web UI is a bit confusing and not as intuitive as I'm used to in FortiOS...But maybe I'm missing s
Since deploying FortiClient 7.4.7 some users are reporting that external USB scanners and web cams are no longer working. In device manager we are seeing error code 19. We are assuming that this is linked to the known bug around the 3M PRF UMDF USB driver, however there doesn't seem to be a fix or published workaround for it.As we do not use the specific protection element that would allow us to maybe whitelist the affected driver/USB device we have found that a lower filters driver FortiRMA.sys seems to be the culprit located at the following place in the registry for usHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6bdd1fc6-810f-11d0-bec7-08002be2092f}Deleting the local filters from this area does then allow the affected USB attached device to work ( following hardware rescan, device reboot or disconnecting and reconnecting affected USB device) and as we do not believe that this filter is anything we actually need we believe its safe to do so. Have anybody else come w
Hi everyone,Is it possible to register the FortiClient to EMS Cloud without needing the invitation code. We have more than 300 PCs to install the client and we dont want to enter the invitation to each of them. Bests,FortiEng
Dear Community,I am writing you all because in my Company we have massive Issues with FortiClient (EMS) on the macOS Clients. I am working as IT Administrator and I am responsible for the MacBook’s.The problem:On the Mac Devices we have since many months the problem that when connected with the VPN the Download Speed is extremely low. We have an External Internet Connection at Work with 100 Mbit/s. With WiFi i get WITHOUT VPN like 80-100 Mbit/s. With VPN ON i get like 5 to 10 Mbit/s (with LAN connection it’s a little bit better). There were also days where it was more so its really inaccurate. The Upload Speed is the same with VPN ON and OFF. ~ 40 Mbit/s. For Windows VPN OFF and VPN ON is the same Download Speed. Some informations:EMS Policies are the same for the Windows- and the macOS Clients We have this features: Remote Access (SSLVPN with Split Tunneling, Webfilter and Vulnerability Scan) Windows Devices are still on 7.2.14 and macOS Devices are on 7.4.5 (I also tested today 7.4.7
ScenarioEnvironment with multiple FortiGate firewalls connected to a FortiAnalyzer VM for centralized log collection and analysis.Environment VersionsFortiAnalyzer VM: 7.4.11FortiGate: 7.2.13Fabric ADOM enabledSome FortiGate devices operating in HA cluster modeAfter upgrading the FortiAnalyzer from version 7.4.6 to 7.4.11, the FortiGate devices stopped displaying FortiAnalyzer logs directly from the FortiGate GUI.SymptomsWhen accessing logs from the FortiGate GUI:Log & Report → Forward Traffic / Event Logsthe page remained completely blank.However:FortiAnalyzer continued receiving logs normallyDevices remained online in Fabric View / Device ManagerLogs were visible directly in the FortiAnalyzer GUINo explicit communication or authorization errors were displayedAdditionally, the following behaviors were observed:Analytics (actual/config days) above 100%Archive Usage above 90%diagnose dvm device list showing:conn: unknownconf: unknowndev-db: unknownThis initially suggested a possible
Very simple vpn set up for my iPhone. I have a Fortigate 40F firewall. I'm able to access my movie server after successfully connecting to the vpn but not the hikvision cameras that I have configured on the Hik-Connect app. I can reach https://x.x.x.x:443 (camera1) on my iPhone using Safari while connected to the vpn. so that port is working.The live feed fails once it hits 80%. "device connection timed out" Please check its network connection. But I can reach my movie server and access the web sign in of the camera using https. Help? Cameras work flawlessly when on the local network through wifi. VPN is allowed to access my entire lan and "all" services (ports) Modem > Fortinet > Ubiquiti 24 Port PoE > connects all my ethernet, three aps and 5 cameras. All on 10.10.10.0/24. Flat network nothing else. NVR is a Windows 11 Pro Host running iVMS-4200. No VLANs, nothing. Flatter than Earth. Log Allowed Traffic is set to "All Sessions"
Hello everyone,Equipment:Model: FortiSwitch 124F-FPOE Firmware: 7.4.3 (Build 830) GAIssue:A CMK15 intercom/communicator device connected to a PoE port on the switch is not receiving any power. The device does not power on.Already checked:The Ethernet cable has been tested and is working correctly. A Wi-Fi access point connected to another port on the same switch receives PoE power correctly and works normally. The same phone device (CMK15), when connected to a different Fortinet-brand switch running the same firmware version, works correctly. It also works correctly when connected to a switch from a different brand.Could this be a hardware issue, or is there a missing configuration on the FortiSwitch? If not, what should my next step be?Thank you.
● Prerequisites・ FortiOS version: v7.6.7・ Inspection mode: Flow-based・ SSL inspection: certificate-inspection・ Browser: Google Chrome, (Firefox), (Microsoft Edge)・ Client certificate installed on the endpoint ● IssueWhen accessing a site categorized for "Block" or "Warning" actions, the FortiGate is expected to display replacement messages;however, a browser error (ERR_SSL_PROTOCOL_ERROR, or occasionally ERR_CONNECTION_RESET) appears instead of the replacement message.Switching the inspection mode to proxy-based resolves the issue, and replacement messages are displayed correctly.Note that this issue occurs on some endpoints but not others. ● Troubleshooting results・ Endpoints experiencing the issue produced the same results when inspected via a different FortiGate.・ Changing the FortiOS version (to 7.6.6 or 7.4.12) yielded the same results.・ Updating the browser to the latest version yielded the same results. ● QuestionBased on the troubleshooting results, I suspect the issue lies wit
I setup 1VM (FMG V8.0.0) and FW(V8.0.0) and trying to onboard fortigate firewall to manager but getting below error , is there any bug or do i need to make further changes in the configuration considering both VM Mgt subnet are in same subnet. Error “The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number.”
Hi, how do you set up a VXLAN when you have two locations? We're using FortiSwitches at both locations, and VLANs are also in use there.But we now have another location, and I'd like to know if it's possible to set up a VXLAN using the FortiLink VLAN as well?
Hi all,I am looking for FAZ resources which cover real world use cases or lab based scenario, I have checked on YouTube but not much available, checked their Fortinet Video Lib as well, I would appreciate you recommend some resources, thanksNote : I am focusing on FAZ, FSM
vpn ssl stop working but internet is reachable,my topology is a sdwan connection to internet from two wan sub interfaces joined as sdwan members into a sdwan-zone, we are using the fortigate lower models and firmware are 7.4.0 and 7.2.4, internet connection are asymmetric, home-residential massive internet. SLA health check is active but ramdonly after a couple of days internet connection is up but vpn ssl sub interface is down, no echo-ping goes back and sniffer also doesn´t show anything, only remote solution is to reset port and after that sub interface goes up again. Following current sdwan config edit 3 set interface "subinterface-primary-vpn" set zone "sdwan-to-remote-hub" next edit 4 set interface "subinterface-backup-vpn" set zone "sdwan-to-remote-hub" next... edit "vpn-health-check" set server <remote-looback-ip> set interval 1000 set failtime 10 set recoverytime 10 set source <local-lan-ip-all
I try to send CoA to the endpoint but we can see from below picture the CoA is failed, and from tcpdump there is no traffic to port 1700. Also in the cisco switch i already enable CoA debug but not receive any message. This mean the fortinac not send the CoA message?
Hi everyone,I have the topology below using Fortigate HA Active -Active Cluster Everything works normally until SW1 (the current STP root) is rebooted or powered off.After SW1 comes back (or after the topology reconverges), the topology does not recover correctly. One or more FortiSwitches may randomly become Offline, even though the physical links are up.The only workaround is to disable and enable FortiLink Split Interface, after which all FortiSwitches immediately come back online and the topology is rebuilt correctly.FortiOS 7.6.7 / FortiSwitchOS 8.0.0
Running FortiWeb KVM_PAYG on Proxmox (standalone, not a cloud marketplace deployment). Reproduced this identically on two separate fresh installs — 8.0.6 build0116 and 7.6.9 build1133. Running FortiWeb KVM_PAYG on Proxmox (standalone, not a cloud marketplace deployment). Reproduced this identically on two separate fresh installs — 8.0.6 build0116 and 7.6.9 build1133.Setup:Operation Mode: Reverse Proxy, standalone (no HA) port1 (external): static/DHCP IP, allowaccess includes http/https/ssh/ping port2 (internal): static IP, reaches backend fine Server Pool → backend IP:80, enabled Virtual Server → Use Interface IP enabled, bound to port1 Server Policy → links VS + Pool + HTTP Service (port 80) + a Web Protection Profile, status shows Running admin-port moved to 8080 beforehand, confirmed no port-in-use conflict when creating the policy License page: all green (VM License, Support Contract, etc.)Symptom:Client (Kali, same L2 segment) connects to the Virtual Server IP on port 80: curl -v
We have 2 internet connections terminated to our firewall with spare IPs, and SD-WAN is already configured outbound for load-balance/failover.We have a specific outbound service (SMTP) that we want to attach to a dedicated outbound IP address.Setting an outbound NAT policy with an IP Pool was easy enough, and that's working, but we only have it setup for one of the internet connections at the moment.How can we set this up with a dedicated outbound IP for each internet connection and have it failover if the main internet connection goes offline? (active/passive)
Hi everyone,I'm looking for the FortiAnalyzer 7.2.11 JSON-RPC API documentation. Does anyone have a copy or know where I can find the complete documentation?I'm currently integrating FortiAnalyzer with an external system and need information on the available JSON-RPC methods and objects.Any documentation, examples, or links would be greatly appreciated.Thanks in advance!
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
Hi everyone,I'm trying to integrate FortiWLC 8.6-5 build-8 (FortiWLC-500D) with Aruba ClearPass Guest (ClearPass Policy Manager 6.12.7.308288 on C3010 platform) as an external captive portal.Current setupFortiWLC 8.6-5 build-8 External captive portal: Aruba ClearPass Guest Authentication type: RADIUS Captive Portal External Server Type: Fortinet-Presence External URL: https://<clearpass fqdn>/guest/guest_register_3.phpThe captive portal profile is configured as:Authentication Type: radiusCaptive Portal External Server Type: Fortinet-PresenceSuccess Redirect URL: https://<default redirect url>Login flowClient connects to SSID.FortiWLC redirects the client to the ClearPass Guest portal.The login page receives all FortiWLC parameters correctly, including:magicusermacuseripserveripapmacapidapnodeidssidpost=https://<controllerip>:8081/vpn/loginUser? User enters username/password.ClearPass successfully authenticates the user against the authentication source.After successf
Hello team, I have interesting situation. there are 4xFg900G in cluster. there is FTP server in vlan 100.L3 DG address for that vlan 100 is on Fortigate.When secondary 900G FGs from cluster want to reach ftp they can not.We also have cluster of 4xFG 400F for additional services, and they can all reach ftp server , no matter primary or one of 3 secondary FGs How to solve this situation?My final aim is to upgrade one of secondary FGs regarding MVC (Multi-version cluster) option, set upgrade-mode local-only, and upgrade one of secondaries and then reset ha uptime so that upgraded one become primary. Reason for that is because we must not have any downtime, and we want to take test after upgrade if all services are ok
Had multiple issues when adding a FortiGate using discover device. It always said device serial number does not match Only once I updated to 7.4.11 did it finally add First post here and its the end of my day so I’ll add more later, just don’t want someone to lose an entire day to this like I did.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.