Mark a Best Answer
Fortinet Community
Recently active
Hi everyone,Because SSL VPN will be removed soon, I started testing IPSec VPN as an alternative on a customer’s FortiGate firewall. I used the VPN wizard to set it up. The users who should connect are part of a remote LDAP group.When I try to connect with FortiClient, it just stays on "Connecting" and nothing happens. If I click "Disconnect", it says "Disconnecting", but also gets stuck.If I connect using SSL VPN, everything works fine, so the problem only happens with IPSec VPN. Tried on FortiOS V 7.2.11 and 7.4.7 and Forticlient is 7.0.9.0493 I have encountered this problem now on several FortiGates with different IPSec setups.In another forum, some users said that installing Microsoft Visual C++ Redistributable fixed it for them. I tried that, but it didn’t help in my case.Has anyone else had this issue and found a solution?Thanks a lot!
Hi Everyone, We have a FortiSwitch 448E connected to a Fortigate 90G via FortiSwitch. Since the operation manual says ACL (Access Control List) can't be accessed when FortiLink is in use, is the only way to access this via the Management port? Any assistance is greatly appreciated. Thank you very much,Sonny
Hello,I have a request regarding license renewal.I’ve received two new Contract Registration Codes for renewing licenses — one for a FortiGate and one for a FortiSwitch device.These devices were already licensed previously, and now I need to renew them.As I understand it, for FortiGate, the process is:System → FortiGuard → Enter Registration CodeIs that correct?As for the FortiSwitch, it is managed through the FortiGate.How should I apply the license in this case?Do I need to register it separately, or is it handled via the FortiGate interface?I would appreciate your guidance on the correct steps.Thank you in advance!
Hi everyone, I have a question regarding how FortiGate handles override of blocked categories in Web Filtering. Let me explain my setup:I have Web Filtering enabled with a custom profile where the "Streaming Media and Download" category is set to block. The goal is to allow certain users to override the block and access specific sites within that category after authentication.To do this, I enabled "Override blocked categories" and assigned the built-in monitor-all profile. Inside this monitor-all profile, I kept "Streaming Media and Download" set to block, but I also configured a URL Filter exception, where I added a wildcard like *youtube.com and set the action to "exempt".The expected behavior is:When a user tries to access YouTube, the override page should appear.The user logs in with credentials.Due to the URL Filter exemption, access to YouTube is allowed.All other sites under the "Streaming Media and Download" category remain blocked.However, this doesn’t seem to work as intended
hello,i have problem with my vpn ipsec i tried to connect to vpn but i have error during phase 2 and on wireshark i'm stuck at here same on forticlient log, i have no idea why config :same auth-encryption for vpn settings and client good selectors for phase 2 ( src and dest addresses ) why quick mode failed ? i can share log from CLI thanks
I had a user download the "VPN-only" edition of the FortiClient VPN the other day and when they go to use it, it is telling them that they have a license for 30 days and then it expires. They are remote so I can't verify, but they are insisting that they downloaded the "VPN-only" version off the website. I have never seen the VPN-only version mention a license. Is this something new? And once they 30 days pass, they will still be able to use just the VPN right?
Hello, I need help to configure IPsec VPN on my FortiGate. I have created the users and configured the tunnel, but I can't access it via FortiClient. I really need your help.
Hello, I have 2 FortiGate VMs that I want to configure HA in Active-passive mode. I immediately lost GUI access when I applied the HA configuration to the first VM. The same thing happened to the second FortiGate VM.For context, both VMs are deployed on vSphere and are connected to the same port group.Does anyone know why this happens and how I can resolve this problem?
On May 3rd, 2025, when you log in to http://support.fortinet.com, you will be greeted by a redesigned landing page, crafted to streamline your access to essential support resources. Welcome to Our New Support Page! We are excited to introduce a brand-new landing page designed with you in mind. After listening to your feedback, we have simplified and streamlined the experience so you can easily find everything you need - whether it’s troubleshooting tips, guides, or answers to common questions. This page is focused purely on the resources that help you get the answers you need, faster. No more hunting around, we have organized everything for a smoother, more intuitive experience. Smarter Support for You When you need help, we have got your back. For some of you in the UK and France, you will see that we have revamped the ticket submission page so that when you open a ticket, you will be presented with relevant solutions right away. These suggestions can help
Hi,We have FortiMail and trying restrict outgoing email to a few addresses only in an external domain, let's say to user1@abc.com and user2@abc.com and block off everything else to that domain. I have created 2 Recipient Policy with Recipient Pattern, first policy with all the email addresses, and then second policy with wildcard *@abc.com, then enabled Content profile and set max size to 10 and also 102400, Action to Reject.I can see the second policy is able to catch non whitelisted address as expected, but still accept and send those emails and not reject them. Any idea why or better method to implement this?
Hi all,We want to set up a captive portal for guest users, on our FortiNAC. We're currenty using a selfsigned certificate, issued by our internal CA. When we connect to this portal using domain computers, this seems to work fine because the CA is trusted. But when external consultants want to connect to the portal, they're getting an SSL error in their browser because the certificate isn't trusted.We do have a wildcard certificate for our external (public) hostname, issued by an external CA, but I suppose we can't use this certificate for our portal?Thanks for feedback!
Hello all, I would like to start a VPN connection through the FortiClient from command line interface.It all works fine manually but I cannot get the syntax right, it seems. Please see the attached picture. Using online resources, I think it should be someting along these lines: "C:\Program Files\Fortinet\FortiClient\FortiClient.exe" connect -s "Aexis VPN" -u wgielis:MY_PASSWORD Version: 6.0.0.0067 https://kb.fortinet.com/kb/documentLink.do?externalID=FD41256https://forum.fortinet.com/tm.aspx?m=123014 Thanks a lot for any pointers ! Wim
The Benefits of FortiClient for Educational Institutions Web Filtering For primary educational institutions child safety is paramount, including on-line safety, with the necessity for managing and controlling the types of content accessible to students. FortiClient offers web filtering profiles that allow administrators to block or allow access to websites based on categories and keywords. The web filter profiles can be applied to student grades or age groups through integration with directory services from Microsoft and Google. This helps create a safer online environment and prevents students from accessing inappropriate or distracting content. Extensive reporting, analytics, and alerting are available through fabric-connected FortiAnalyzer. This allows administrators or educators to obtain reports on web content visited and blocked, as well as insight into possible student cyberbullying and the risk of self-harm. Zero Trust Network Access In a school environment
FortiAIOps 500G: Boosting Network Performance with Cutting-Edge AI-Powered Insights In the ever-evolving landscape of network management, the integration of Artificial Intelligence for IT Operations (AIOps) has become a pivotal strategy for organizations aiming to enhance operational efficiency and proactive issue resolution. Fortinet, a leader in cybersecurity solutions, has taken a significant leap forward with the introduction of the FortiAIOps 500G (FAO-500G) appliance. This on-premises hardware solution is engineered to deliver unparalleled performance, seamlessly integrating AI-driven analytics into your network infrastructure. Unveiling the FortiAIOps 500G Hardware The FAO-500G is a dedicated hardware appliance designed to enhance network operations by leveraging artificial intelligence and machine learning. This appliance offers comprehensive monitoring, robust troubleshooting tools, and AI-powered insights to ensure optimal network performanc
Hi, Syslog functionality was operating correctly when a single VDOM was in use. However, after enabling multi-VDOM, the syslog configuration now appears exclusively in the Global VDOM mode, making it applicable only to the Global VDOM. In the root VDOM, where all policies, VPN tunnels, and other configurations are present, it is not possible to configure syslog. Attempts to use the "config log syslogd settings" command in the root VDOM were unsuccessful, as the term "syslogd" is not recognized. We are currently running version 7.4.7v. To forward logs, each VDOM needs to have its own separate syslog configuration.
We’re running FortiNAC 7.6.x (NAC-OS) with a trusted 3RD PARTY SSL certificate assigned to our captive portal. BYOD devices are redirected to the registration portal via VLAN isolation and FortiNAC policies.However, we are encountering the following issues:HSTS-enabled HTTPS sites (e.g., chatgpt.com, google.com) throw unskippable certificate errors (ERR_CERT_COMMON_NAME_INVALID) when intercepted before registration.Windows 11 endpoints are not reliably triggering the Captive Network Assistant (CNA). What we’ve confirmed:A valid certificate is in place and bound to the portal (port2).msftconnecttest.com is not in the Allowed Domains list.DNS and HTTP access to FortiNAC from the Registration VLAN are working.What we need:Clear guidance or official best practices to ensure:Windows CNA detection reliably triggers upon network joinHTTPS/HSTS certificate errors are avoided entirelyAny specific FortiNAC settings required to optimize detection behaviorLooking for any insight into possible
we have a problem with certificates and fortiweb, we get a certificate chain error shown as Incomplete on SSL scan with https://www.ssllabs.com/ssltest/, but browsers show certificates as valid, and the complete chain is ok, we uploaded the certificate to fortiweb, and to the IIS server, we get this error with sslshopper too.
How can I use [FortiClient VPN-Only] in an offline environment? I would like to perform IPsec remote access testing in a closed testing environment, but FortiClient VPN-Only is not functioning correctly offline. When I click "Connect," nothing happens, and it returns to the screen before entering the password.No packets are reaching the FortiGate side, and when I perform a packet capture on the client, no packets are being generated.In the testing environment, I am using an L3 switch as a pseudo-internet environment, and there is a Ping response between the client and the FortiGate. The client’s default gateway is the IP address of the FortiGate’s listening port. Even when I connect the client directly to the FortiGate’s listening port without using the pseudo-internet environment, the issue persists. Is it not possible to use FortiClient VPN-Only in a completely offline environment? Environment in use:FortiGate 60F Version 7.4.5 build 2702Windows 11 FortiClient VPN-Only
Hi Fortinet Family, I am currently facing an issue with configuring ISP failover for FortiManager connectivity. The current scenario is as follows: I am onboarding a FortiGate firewall through FortiManager, and FMG access is currently enabled on one of the ISPs. However, I would like to ensure high availability and redundancy for management access. My goal is to configure ISP failover so that if the primary ISP goes down, FortiManager can automatically switch to the secondary (active) ISP to continue managing the FortiGate device without interruption. I would appreciate any guidance or best practices on how to achieve this setup, including any specific configurations required on both the FortiGate and FortiManager sides to ensure seamless failover and reconnection.Looking forward to your support. FortiManager FortiGate
The IPsec VPN wizard clearly states that FortiClient is supported on Windows, macOS, and Android, but not on Linux. So, how can we connect to a FortiClient VPN from a Linux machine?
Good Morning, There were post about the symbolic link vulnerability on Fortigate recently, the document mentioned the updated AV / IPS can remove the bad symbolic link. I want to know if there is AV/ IPS event tell us, the bad symbolic link detected and has been removed ? How to check if bad symbolic link exists in the file system ? Regards,Jacky
Good afternoon,We have a problem with Forticlient VPN. The client is configured with ZTNA and EMS. Every time we suspend the notebook and turn it on again, the Forticlient window opens. We have tried reinstalling and installing older versions, but without success. Has anyone experienced something similar and would know what could be the reason?Thank you in advance.
Hello, Email-based two-factor authentication has been successfully enabled for users, including SSL VPN users, who are now receiving OTPs via email without any issues. The OTP emails are currently being sent from the email address "DoNotReply@fortinet-notifications.com." Is it possible to modify the sender's email address to align with our domain (e.g., example@test.com)?
Good day Team, Fortimail v7.4.1 I have a few entries (full email addresses) under IP Policy -> Inbound Session -> Lists -> Sender Blocklist checkingand indeed, it works, no more mails from those senders. However, I am getting quite a few from same domain, how can someone in Fortimail block only the @domain.com portion of email addresses. Please show me the definite steps to complete this procedure. So far my Fortimail is working well, just a few domains I want to keep under control. Regards,
I am following this doc.https://docs.fortinet.com/document/fortinac-f/7.2.0/kvm-deployment-guide/31945 ./deploy_kvm <domain_name> 1- what is meant by "domain name" in this case?2 - Didn't know what that was so I just used "nac". After running the script, I got the following errors and cannot proceed../deploy_kvm: line 164: virsh: command not found./deploy_kvm: line 165: sudo: command not found Any ideas ?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.