Mark a Best Answer
Fortinet Community
Recently active
I need to delete ima Interface, but I can't figure out how to do it? I want to remove it and put it in SEM_USO
I would like to know if it’s possible to limit the maximum number of IPsec VPN tunnels per VDOM on a FortiGate 1500D.We’ve tried different approaches using both the GUI and CLI, but we haven’t found any option that enforces such a limit.Thank you in advance for your support.
Hi All, I did some digging and even opened a case with support and I came up empty handed on this topic. We are wondering if the syslog CEF output can be customized? The primary goal is to trim down the size of the logs to just the data we need before ingestion to our SIEM. On PANs we could do this fairly easily, curious if an on box way exists to do with Fortigates. We are running 7.2 code on 200Fs. Thanks
Hello Fortinet Community,I'm currently working with FortiAnalyzer (version 7.4.x) and have set up an automation playbook that triggers upon specific events, such as multiple failed login attempts. The playbook includes a webhook action intended to send event details, including the ADOM (Administrative Domain) information, to an external system.In my webhook action, I'm attempting to include the ADOM using the ${adom} macro in my automation Playbook.However, the adom field in the payload is coming through as blank. I understand that in notification profiles, the ADOM information is readily available, but it seems that in the context of playbook actions, this macro isn't being populated.I've reviewed the FortiAnalyzer documentation, particularly the section on webhook connectors and supported macros , but it doesn't provide clarity on this specific issue.Has anyone encountered this problem or found a workaround to include the ADOM information in playbook webhook actions? Any g
I need to monitor a logs of 1Device Fortinet 40F But Forti Analyzer cost is so high then what is the secondary option
When I do the Fortigate ssl-vpn test, client failed to get gateway, but traffic flow is normalIs it okay if it's like this?IPv4 Add : 192.168.1.1Subnet : 255.255.255.255Default gateway :
First of all, I'm not a developer, but I have some knowledge of React and Nest.js. I'm developing a React/Nest.js web application to centralize my client's data. Everything works fine except for one issue: when I try to call the Fortigate API to retrieve license data and uptime from my different clients. When my app makes a request to the Fortigate API, it sends an OPTIONS request first, but Fortigate does not seem to allow, recognize, or handle this request properly. One important thing to note: when I click on the request URL directly in my browser, a new tab opens, displaying the JSON data. So, I assume that clicking the link directly triggers a GET request, which works fine. On the Fortigate i allowed "CORS Allow Origin" with * (I know i will change it after)I would like to know if there is a way to bypass the OPTIONS request and send only a GET request. I dont have the Web Protection menu on my Fortigate V7.4.3, so i can't configure CORS ProtectionConfiguring a
I have 2 Fortigate 201F set up with a tunnel and I'm seeing some strange traffic (mostly missing) from site A to site B. Site A has 2 active WAN interfaces with the 2nd interface static DF route at a higher priority. My tunnel is assigned to the interface with the lower routing priority. I'm not able to ping devices on Site B, yet I'm able to access the internal web interface of the Fortigate of Site B.Site B only has one WAN interface and I'm able to ping from devices within Site B to devices on Site A, but I'm not able to connect to NTP, DNS or LDAP from the Fortigate B to Site A.Both tunnels were created as custom pointing to the IP address of the outside interface of the opposite. I have phase 2 selectors set for each of the VLANs from Site A and all show active. Both sites are set with incoming/outgoing policies using the named tunnel and allowing ALL traffic and stated VLANs.Both sites have static routes set to use the tunnel interface for traffic.&nb
Is there any way to change the notifications that are displayed when upgrading the Forticlient via the FortiEMS? I would like to add the hint that the new version of the Forticlient will be installed after the reboot - unfortunately I see it again and again that the laptop is not logged in again after the reboot and the users are then left without Forticlient. best regards,martin
Hello everyone, I am using FortiWeb Site Publish functionnality with a SAML authentification (Google).I need to get some of those SAML attributes to my backend server. Following the documentation https://docs.fortinet.com/document/fortiweb/7.6.3/administration-guide/272565/offloaded-authentication-and-optional-sso-configuration Here is what I did in my site publish rule : So, my problem is that my attribute is nowhere to be found in any of my headers. Maybe the $USERNAME var is empty ? Would fortiweb still create the header and give it a blank value ? Thanks in advance to anyone willing to give me a hand :)
Hello team kindly helpi am configuring site-to-site IPSEC on fortimanager to push on fortigate but the i am confused where to confgure the IPsec?i have tried to my best on all platform1. on VPN Manager2. on IPsec Template3. on the device phase1 and phase 2 but after creating the vpn on all the 3 i can not see the VPN as the interface so that i can use on policy?PLASE HELP
Hello Community I am attempting to use the FortiOS API to apply a license. The device is a FortiWifi 80F with Firmware 7.2.6.I am attempting to apply the Advanced Malware Protection Free Trial, for testing purposes.From help with the Fortinet Developer Network I have seen this command: curl -X 'POST' \ 'https://192.168.20.1/api/v2/monitor/registration/forticare/add-license?access_token=xp40rkkhqcbfyr8Nq96H9G7H43q0f4' \ -H 'accept: application/json' \ -H 'Content-Type: application/json' \ -d '{ "registration_code": "STRING" }' I am not sure what the registration_code value should be. I visited support.fortinet.com to gather the license key I wish to apply. It downloads as a .lic file. There is text in there but nothing matches the registration code. I have tried to insert the contract number as the string but this did not work.Where can I find the registration code?Am I using the wrong endpoint?Appreciate it
I'm confused how updates work for Forticlient, in order to upgrade the client I've read that I need to use the 'Deployment and Installers->Forticlient Installer' and 'Manage Deployment', the strange thing is it forces me to attach an invite when creating the forticlient installer.I've already added devices using 'Endpoints->Invites'. I added my own email in the invite section, and now it seems to be deploying them all, but why did I need to add myself as an invite to accomplish this when I'm deploying to 10+ devices I've already added?Theres also an option 'Reboot When Needed' which is confusing. I want it to install but to not auto-reboot, so am I disabling Reboot when needed; except if I do enable it there's an option to Notify User to let them decide, but that is only supported on older versions of Forticlient. I'm at a loss as to what to do, I'd like a notification, but if its on a newer version of Forticlient does it then auto-reboot?
Hello, could someone help me with a question? Which license should I purchase to export logs from 40F? We need a visual presentation of the generated reports. Which solution should I purchase to do this?I found information about this license, FortiGate Cloud Management, Analysis and 1 Year Log Retention. Would this be the solution?I added some images, we need this subscription, what is the required part number?Thanks.
We have recently migrated a number of sites away from older FortiWLC Controllers and Meru AP's to FortiGates and FortiAP's, and found we are having a number of issues with AP's not publishing SSID's on the 2.4Ghz radio when multiple SSIDs are configured. In our case there are 3 SSIDs. For example, we have a FortiAP 233G with 3 SSID's configured on the 2.4Ghz and 5Ghz radios as follows; SSID1SSID2SSID3 The SSID's are in bridged mode. 5Ghz clients can see and connect to all 3 SSID's with no issues. However 2.4Ghz clients can only see and connect to SSID1. It can happen randomly across any of the FortiAP's we have installed and is happening at multiple sites. If we enable any one of the 3 SSID's on the 2.4Ghz radio on its own, devices can see and connect to the SSID with no issues, so it seems the FortiAP 233G has an issue when the 2.4Ghz radio is configured with multiple SSID's i.e. devices can only see and connect to one of the SSID's. Has anyone else experience
In the process of renewing SSL certs, this is the first time doing ADC, staff that built is no longer here. I created the CSR via the local servers IIS, cert was created with DigiCert and uploaded to the same IIS. I then exported the .pfx from this server getting the following errors when trying to import into ADC.type: PKCS12 Certificate it fails with the following error 'Failed to store the private key' I then used open ssl to get .crt and .key and attempted the following:type: Certificate. and applied the .crt and .key files but get the following error: 'The imported local certificate is invalid.' Not sure what I'm doing wrong here, any help will be greatly appreciated. Thank you
Hello,Is there a way to see in Fortigate how much bandwidth (Mbps)is consuming an internal user?I recall before in fortiview it showed this but now (FortiOS 7.4) I can not see it. Only shows traffic in Bytes (MB).What widget would it be if any...? thank you.Regards.
Overview One of Fortinet customers, a tele-communication (telco) company in the Spain, has a large fleet of EC2 instances across multiple regions in Europe to meet customers’ demands and GDPR regulation. The telco company deploys application in to auto-scaling EC2 spot instances to save on cloud cost which makes it challenging to deploy persistent workload protection tool. They also use FortiGate-VM on AWS to deliver advanced threat protection and secure connectivity for EC2 instances, including antivirus capabilities through FortiGuard. It provides features like application control, malware protection, web filtering, and IPS. FortiGate-VM forwarded events to AWS Security Hub via FortiGate API integration. The telco company’s FortiGate-VM detected a wave of attack by un-authorized users using Rhysida ransomware. FortiGate-VM was able to block all of the traffic with Rhysida ransomware. Incident Summary Attack Vector: Ransomware attack Impact: Non-critical peer-to-peer appl
Fortigate detects teams.microsoft.com based on http, but the delay is always unstable. Is there any way to check which IP address teams.microsoft.com is detected by http? Thanks
I've been looking at how to best do geo-blocking, and my options are to set every rule I have for inbound access to only accept from specific locations, or to manually add all the ones I don't want to a rule that applies at the top of the list. With SonicWALL, WatchGuard, etc. I can select the countries I don't want and set that policy at the top, why doesn't my Fortigate have the same option? As for the meat of the question, does anyone have a curated list of countries that they use and is available without a $25/month or more subscription?
Does anyone have a good CLI script to identify and group countries for geoblocking, or I do need to use the GUI and go one-by-one?
Hello , when it is used the comfort client? ONLY when I use AntiVirus profile? Or If I use another profile like IPS it is used too?I mean if I activate comfort client in a protocol option profile and apply it to a FW policy ... this comfort client is activeonly If I apply AV to the policy? or If I apply IPS is active too? The doubt is when it is active...Thank you!Regards
Hi All, I have experience with a number of Forti roducts but Fortimail is completely new to me. I am deploying a solution replacing the embedded mail protection on some Sophos XGs. I have the Fortimail up but I am unusure how I can replicate and route traffic. The Sophos only has two policies in the mail configuration. The first is allow mail to the domain recipient and scan this mail - this is not used as mail accounts are in O365. The second is allow mail from internal servers to internal users (in O365). Mail sent from named servers to a named relay and then on to the mail account. An exception rule was created allowing either the host source or sender address to skip AV/Spam etc checks and send through the mail and out to O365 whilst checking all other mail. I have set configured the domain for the mail FQDN in Domain User>Domain configuring relay type MX Record. I have also configured a recipient policy for recipients of the mail domain. The Forti
Hi, (Fortigate 201F, 7.4.3)I have a new SD-WAN setting, and I have an internal e-mail server. How can I limit the email server traffic (SMTP) so that traffic only goes out through the designated SD-WAN interface. If that interfece go down, I do not want to allow to go this traffic out in other SD-WAN interface. A would like to prevent the email traffic to go out from an other public IP. My current goal is not to configure the mail server (DNS, MX, SPF etc...)I tried to create an SD-WAN rule (Interface selection strategy = Manual) with the mail server address and SMTP traffic, where I only specify one SD-WAN interface in the interface preferences, but it seems that if I stop this interface, the traffic still starts to go out on the other interface. How can I stop this from happening? Thanks
I have FGT3140B (v 5.0.7) in HA mode, and i am not able to add device in ADOM v. 5.0 The Add device wizard "jam" just after the wizard end to run proccess Retrieving IPS signature information. I recieve in the status information "data not exist". The process Creating initial configuration file are blinking, but not finishing. I have wait over 30 mins, and nothing to do. I can just press cancel button. If i cancel the operation, the device are not completly added. Any one have an idea? All my fortigard services on the FGT are a green check status
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.