Mark a Best Answer
Fortinet Community
Recently active
We have received a message from our employees that the VPN client no longer works with IOS 18.3.2. It still works on older versions or Windows clients. We use the VPN with our own IDP as 2FA.As soon as the users confirm the 2FA, we get the message with URLSessionTask failed in the app. (See photo) Anyone having similar Issues?
Like a lot of you, I'm going to have to migrate a lot of users to IPSEC VPN which seems strange to me. IPSEC being so old I just assumed SSL VPN was the way to go. That aside, has anyone had experience with using different clients or the built-in windows client for connecting to a Fortigate IPSEC VPN? I have no experience with IPSEC clients beyond whatever the vendor provided (sonicwall global vpn anyone?) Would love to hear about your experience especially related to stability and ease of pushing out to users.
Hi thereThanks for your support.I'm looking for choose a fortiClient license for my FG-100F.Do you think the below SKU is ok? if NOT, can you please advise the best one? FC1-10-EMS04-428-01-12Endpoint-based Licenses - VPN/ZTNA (On Premise Deployments) 1 Year FortiClient VPN/ZTNA Agent Subscriptions for 25 endpoints, includes on-prem EMS and FortiCare Premium.) Thanks a lot
Hi,Does FortiAuthenticator have the ability to enter a token and then a password? Can we implement such a scenario? Best Regards,İsmail Ürek FortiAuthenticator
Client version is 7.0.2.0069. We use SSO but with or without SSO turned on we are getting: "Login Error. Connection Dropped by Remote."We have previously had this work for MacOS including MacOS 12. using DNS or IP address for the VPN address didn't help. At initial install and 1st time connection we do get prompted to sign-in with our SSO account (with 2FA on) and it looks like it should but then the connection just dies and we get the above error. Subsequent login tries just give the error right away. Thank you for any help!
We have been testing DPDK acceleration for ipsec tunnels on our nutanix hosts. dpdk-iperf-1 and dpdk-iperf-2 are simple 4-core 8gb RAM ubuntu VMs with minor host tuning (sysctl window sizes etc) for iperf performance testing, and can maintain about 17Gbps using iperf3 when directly connected to one another. dpdk-test-vm04-1 and dpdk-test-vm04-2 are fortigate VMs on v7.6.2 (2cpu, 16gb ram). When testing iperf performance on a basic ipsec tunnel we saw approximately 1.2Gbps between the ubuntu VMs. After enabling dpdk (see config below) we are only able to increase this performance to 1.5Gbps.test diagramI've confirmed that the dpdk engine is correctly picking up this traffic - ipsec_dec_packets and ipsec_enc_packets are incrementing, and the vnp and vnpsp engines all kick into life with `diagnose dpdk performance show` while the test is running.However we did expect to see a significantly higher performance uplift for ipsec tunnels, is there something we're missing?Current work
Overview One of Fortinet customers, a large fintech organization, leverages TeamCity to deploy auto-scaling EC2 workload in their AWS environment. The customer builds new resources by automatically starting and stopping cloud-hosted agents on-demand, depending on the current build queue workload. They also use FortiCNAPP (Lacework) to protect their cloud native applications and resources. During periodic scan, FortiCNAPP discovered 10% of the EC2 workload from certain AMI images expose to CVE-2023-42793 which has the score of 9.8 where attackers had already deployed the publicly available exploit without authentication supporting remote code execution on the victim server using a basic web request to any accessible web server hosting the vulnerable application. Incident Summary Attack Vector: CVE exploitation on AWS workloads Impact: Remote code execution for unauthenticated users, enabling access to critical applications running on EC2 Initial Entry Point: Application accessed
Just in case someone runs into this same issue. We ran into a problem where users were complaining prime video would not load on their apple devices. Turns out the "Known Exploit" signature is blocking the videos but not the app itself. Turning off the specific signature fixes the issue. Not sure if this is intended or a false positive. Absolute Date/Time2021/07/14Time16:06:22Session ID334183039Virtual DomainrootAgentPrime%20Video/8.330.7424.12 ActionblockedPolicy ID17 Profile NameTest FilterEvent ID90300017DirectionrequestSeverity MessageKnown ExploitsLog ID1200030248TypeutmSub TypewafEvent Typewaf-signatureSource Interface RolelanDestination Interface Rolewan
Hello guys,I am labing fortigate advpn sdwan with bgp routing. I am trying to summarize the spoke's lan networks in the hub but when doing this I loose spoke-to-spoke shortcut vpn and all traffic is forced through the hub. Cisco has NHRP to solve this issue to override the bgp spoke routing so exact route can be received from the other spoke. How I can summarize of fortigate in the hub firewall so I can have on-demand shortcuts in the spokes? Thank you so much.
Hi everyone.I am just trying to find out what everyone is doing regarding moving from SSL VPN to IPSEC VPN, what are you putting in place that is potentially free as safeguards and best practice methods.Geo - location - restrict where users can SSLVPN from.SAML - with 2FA auth.Others?Thanks in advance.
Hi everyone Just installed my first ever Fortinet 30G (latest 7.2 firmware) and I am having some troubles with logging. I have created a virtual wire pair with a firewall policy attached to it (accept everything from anyone and anywhere, but apply AV, IPS, WebFilter etc. policies). Logging is set to "UTM" and should be local (no FortiAnalyzer).Now, when I try to access the EICAR test file, it successfully blocks the access - however no security logs ever show up. How can I solve this? Best regards Andreas
Hi,I am trying to block specific applications example TeamViewer . I don't want anyone to access our network from outside or even using TeamViewer inside the network.Also the are lots of other users who have admin access to their computers , so I cannot prevent them from downloading anything but i want to be able to prevent them from executing the install file example WireShark.I have tried reading on the forum but the documents does not match exactly what i want.The firmware version for my FortiGate 100F is v6.4.9 build1966(GA) ThanksTazio
Hi Fortinet Community, We're facing an issue where traffic shaping on our FortiGate device doesn't seem to be working as expected. Despite setting up the necessary configurations, no traffic appears to be shaped — the system always shows current-bandwidth=0(kbps) when monitoring shaping statistics. What We’ve Verified So Far:1. Class IDs are configured correctly.2. Traffic Shaping Profile is set up and active.3. Relevant Traffic Shaping Policy is in place.4. Interface outbound bandwidth is configured.5. Traffic Shaping Profile is applied to the correct interface.6. Ran "diagnose netlink interface list" command No matter what we try, shaping stats show zero usage: Any help or insights would be greatly appreciated.Thanks in advance!
hello, i am facing an issue with some of the hosts installed persistent agent, these hosts are not communicating with fortinac server. i have checked everything and also disabled the antivirus running the hosts and uninstalled and installed the persistent agent and nothing is working. Any ideas will be helpful.
Hello, I need some help with this issue. I have a user who is working remotely and connecting to the Forticlient VPN software. She is able to log in just fine however she cannot access our server drives or our exchange server. However, when I log in at my location I am able to access the drives just fine. Could anyone help me pinpoint the issue. I'm not an expert in this area by any means but I am the only one available to help. Thank you.
Hello. We are currently using FortiSwitches with FortiLink.In version 7.2.x, I understand that changing the FortiSwitch name does not affect active sessions. Recently, we upgraded all our devices (gate, switch, AP) to 7.4.x.We have about 20 switches in use.However, when we change a switch name from the gate, it appears that some other switches temporarily disconnect and reconnect. It also seems that active sessions are interrupted.Based on my research, it seems that when a managed switch is renamed, it is deauthorized and then rejoined, which causes all sessions to be dropped. As the switch reconnects, STP path recalculation occurs, so session drops or other switches disconnecting may be observed. Is this understanding correct?I referred to the following URI for this information:community.fortinet.com/t5/FortiGate/Technical-Tip-Unable-to-change-managed-FortiSwitch-name-after/ta-p/280009docs.fortinet.com/document/fortiswitch/7.4.0/fortilink-guide/59264/defining-names-for-managed-switche
Hello, Our FortiAnalyzer has been running continuously for about 180 days, however: - Analytics log is only 1 day,- Archive log is kept for only 11 days. - Disk occupancy is 85% (445 GB total available). Our expectation was that these times would be much longer. No manual changes were made to the log retention settings.I rebuilt FortiAnalyzer but then the day counts were updated as shown in the image below. Best Regards, İsmail Ürek FortiAnalyzer
Tunnel flapping, or frequent disconnects and reconnects, between a FortiGate 7.2.9 (HUB) and 7.4.7 (Spoke) device in an ADVPN setup.Following this are observed.In IPsec VPN logs DPD failure errors is showingIPSec tunnel disconnect and reconnect frequently.BGP neighbor renegotiation.observed packet loss 16 % frequently, unable to figure it out reason of packet loss in the tunnels not on public interfaces.
Dear Team,I’m using an HA setup with FortiGate 121G devices. After a sudden power outage, I received a notification stating "File System Check Recommended" (please see the attached screenshot).Although the firewall has restarted and is functioning normally , all policies, routing rules, and services are working as expected and the message still persists.Additionally, the HA status page is not loading correctly (screenshot also attached). Any suggestions on how to resolve this?
So to give you guys some context, I have 13 sites globally with 26 total firewalls (All FG200E) that we are going to be looking at upgrading at the end of the year. With Fortinet pushing for either IPSec or ZTNA we have decided to move forward with implementing ZTNA. We already have an EMS server in place, so it just makes the most sense for us. Especially considering we use Microsoft SAML for authentication. We are currently running 7.0.17 on all the FortiGate's, 7.0.12 on the EMS server, and FortiManager is running on 7.4.6I am just looking to hear on your experiences with the latest mature versions of 7.2 or 7.4 and what you guys would recommend for us? We have not moved on from 7.0 because of how stable everything is right now and the last thing I want is to introduce any kind of bugs and have to deal with that. Anyone else here running ZTNA with SAML SSO?
I've received IP address information from my new ISP, and it looks like I may need an additional router. They provided two public IP ranges: one labeled as the WAN, which is a /30 subnet, and another labeled as LAN, which is a /29 subnet.From what I understand, the /29 subnet contains my usable public IP addresses, and I need to route traffic from this range through the WAN (/30) subnet.Is it possible to configure this setup using a FortiGate firewall, while still using it as a traditional firewall—publishing services from an internal or DMZ network through the /29 public IPs? What would be the best way to approach this configuration?
HKJC is very common gambling website in Hong Kong.I would like to use fortigate gambling web filter but i want to exclude HKJC website.What can be done about it?Thanks
Not that I'm pushing 7.6 in to production anywhere, but with SSL-VPN being totally retired, there's one show-stopper with IPsec that I'm wondering if anybody has found a solution for.At least with non-EMS managed FortiClients (95% of my install base) on an IPsec VPN setup you can't push a DNS suffix to a client like you can on SSL-VPN. DNS lookups work fine as long as you use a FQDN - but - you can't use just the hostname to connect to things. Has anybody found a solution for this or heard rumors of it being addressed at some point?
Overview One large cooperative bank is tackling modern cloud security challenges head-on through a comprehensive digital transformation, migrating workloads from on-premises data centers to AWS. The bank is reinventing its digital and customer experiences through innovative new services, while enabling its remote workforce to securely and efficiently access private applications. During this transition, the bank experienced a security incident involving a Server-Side Request Forgery (SSRF) attack in its AWS environment. The breach highlighted the risks of cloud-native architectures when combined with misconfigurations and legacy service settings. To contain the incident and strengthen their security posture, the bank engaged the Fortinet Incident Response (IR) Team, which conducted a full investigation using the Fortinet FortiCNAPP platform and delivered a comprehensive cloud security remediation plan. Incident Summary Attack Vector: SSRF vulnerability in a
Is it possible to configure a time-based administrator user access in FortiGate?For example: an administrative user must be able to login the firewall device from 9 am to 11 am. Beyond 11 am, the login access should be disabled
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.