Mark a Best Answer
Fortinet Community
Recently active
Dear Team,I have a question regarding the use of the Per-IP Shaper feature in traffic shaping on the FortiGate firewall.I configured a traffic shaper with a total shared bandwidth of 20 Mbps (Reverse enabled) for 10 users.Additionally, I applied a Per-IP shaper limit of 4 Mbps.My inquiry is:Does this configuration mean that all 10 users combined can consume up to 40 Mbps (i.e., 4 Mbps per user), or will the total bandwidth still be limited to 20 Mbps regardless of the Per-IP shaper setting?Looking forward to your clarification.
We've been running FortiNAC for 2 years now and are starting to deploy Intune joined workstations. I followed the 9.4.6 Intune integration guide and it's successfully polling Intune and bringing in devices. The issue we are now seeing is, we're a global company sharing a single MS tenant and NAC is pulling in thousands of devices from other countries. Since this is an API call, it sounds like we cannot do the filtering to our devices only via Entra, so we need FortiNAC to filter the devices on an extension attribute or a tag. While ChatGPT seems to think FortiNAC can filter the devices, it failed to spit out how, and I cannot see any filtering options in the connector setup. Does anyone know if it's possible to setup a polling filter to narrow the list of devices it will ingest from an external MDM? On another note, the FortiNAC 9.4.6 Intune integration guide, steps 9 and 10, tell you to setup a permission under Windows Azure Active Directory, which was deprecated
How can I set up an SSL VPN connection on an FGT60F v7.6.2.F? Unfortunately, I can't find this option in this FortiOS version.
Hello everyone, creating this topic after months and months of search without any positive result. I am currently in charge of trying to upgrade the 35 last clients we have with VPN 6.4.8.1755 We face a problem that made us stuck for a moment and locked us from upgradingAs soon as we try to touch it, we loose Keyboard Mouse HID and Network (error code 39 object name unknown drive missing or dammaged) We tried with the same end result : - Basic uprade via EMS - Manual upgrade via launching different more up to date version of forticlient (EXE or MSI)- Manual upgrade after uneregistering=>unlocking=> stopping forticlient- Just uninstalling it via control panel after uneregistering=>unlocking=> stopping forticlient- uninstalling via msiexec - Using the FCRemove tool of the right version after uneregistering=>unlocking=> stopping forticlient makes a particular particular case, we notice that Forticlient remains in
is it possible to receive a mail when the license of a Fortigate is about to expire (for example 14 days before).Or is there an alternative API call?
I have a fortigate and use SSL VPN. The setting is that a VPN connection can only be established from certain countries “Limit access to specific hosts”.Now someone is going on a round trip by boat and will want to establish a connection from several countries. In addition, there will certainly also be an Internet connection via satellite.How do I solve the problem without generally allowing all connections?
I recently installed a 100f with two WANs but one of them will not ping and I cannot setup any IPsec tunnels with it or use it for sslvpn as the interface. The interface shows up and I'm able to ping the modem behind it but I'm at a loss and I'm sure it's a simple thing Im not aware of https://mobdro.bio/ .Sdwan was setup for the interfaces and grouped together. I set the default route to this group and the priority and Admin Dist is default, very basic currently.Previously I migrated these connections and conf from a Sophos XG which, when I moved the connections back to confirm, both WANs were pingable.Yes I confirm ping was enabled on the interface, I'm guessing this is a route issue but Im not sure where to look.Thanks for your help sorry for the wall
Hi Everyone, We just bought a FortiSwitch 448E and when I tried to connect a LAN cable from my laptop to the FortiSwitch's MGNT port, it's giving my LAN port an IP of 169.254.200.221. The label on the switch says the switch itself is supposed to be 192.168.1.99. I even tried to set my laptop's LAN port to a static IP of 192.168.1.10 and still can't access this switch's GUI. Any assistance is greatly appreciated. Thank you very much,Sonny
FortiClient EMS 7.4.1.1872FortiClient 7.2.9.1033 I have gone in to EMS -> Endpoint Profiles -> ZTNA Destinations. Edited the ZTNA profile. Disabled it. Then re-enabled it and made sure the EYE was looking. This has been pushed out to my machine only. However, in EMS when I find my endpoint I still see ZTNA enabled (hidden) under Features and my client is not showing the Destinations tab even after waiting minutes. What am I missing here????
I am trying to install FortiClient 7.4.1 on MacOS but the installation fails with the error message „Endpoint Failed to download deployment packages“.The same installer packet is being used for windows clients and everything worked with no issues.The clients are using MacOS 15.3.1 and are shown as online and managed in the EMS.I already checked for permission issues and followed the special notes but it didnt help.https://docs.fortinet.com/document/forticlient/7.4.1/macos-release-notes/223986What else could be the issue here?
Hi,I am trying on my own to figure out how to replace my existing Aps with FortiAps 431F. I am planning to replace all the Switches which are Cisco and some are HP in the short run but for now am just replacing the APs.It is a live network and I am very cautious as each time I am trying something I am doing a backup.I can see the SSID on my phone and laptop but I cannot connect.When I try to connect it shows connecting and then Couldn't get an IP address.Can any one guide me where to start checking and what to check please.ThanksTazio
Hi Team, I’m currently diagnosing an issue I encountered with our FortiMail system. The logging service unexpectedly stopped functioning on its own and only resumed normal operation after a system reboot. Could you please help me understand what might cause FortiMail to stop logging without any manual intervention?Also, are there any best practices or preventive measures I can implement to avoid this type of behavior in the future? Thank you.
Hi all,i have 3 branches with MPLS link to HQ and a DIA access.We have only one ISP that manages two different connections for every branch. The ISP give me the possibility to use the local internet connection as a DIA in every branch. The ISP manages the redundancy of MPLS and internet link between the two different connection they provide. I want to build an IPSEC tunnel over the MPLS for security reasons and use this also to route some particular internet traffic. In case this link goes down I need to route all the internet traffic through the DIA. I always need the possibility to use the DIA for other traffic. Branches does not need to talk each other. This is the network scheme. I only manage fortigates. Routers are managed by the ISP. I've coloured the path that i want to implement. - Should I use SDWAN to manage that?- Do I need BGP?- How do i manage route changes and nat changes?
Hello, My wireless clients do not receive an IP Address when connecting to a SSID.My Infrastructure is as follow;FortiGate 120G <fortilink> FortiSwitch FS-108F-FPOE <port1> FAP231 On the FortiSwitch port1 the native vlan is 5 and the allowed vlan are 30 and 40 On the FortiGate in the fortilink interface the vlan5 is configured with a subnet 192.168.5.32/27 and a DHCP server to provide management subnet for the FAP231 (this is working).On the fortilink I configured the vlan 30 without any IP or DHCP serverOn the fortilink I configured the vlan 40 with a subnet 192.168.40.0/24 with a DHCP server (192.168.40.10-192.168.40.250).In the SSID section I configured the SSID GUEST_30 in Tunnel mode, with a subnet 192.168.30.0/24 and a DHCP server (192.168.30.10-192.168.30.250) open authentication with a local captive portal, and the vlanid 30.In the SSID section I configured the SSID OFFICE_40 in Tunnel mode, without a subnet or DHCP server, WPA2 Personnal (will go to
Have few Fortigate devices (6.4.12) managed by Fortimanager (7.2.2) and have problem with packet capture in Fortimanager.Packet Capture is grayedAny suggestion why this option is not available in Fortimanager? Only solution is to make packet capture directly on device but then device will "out of sync".
I know Fortinet is doing away with SSL VPN. I am close to moving off SSL VPN and going to Dialup IPSec VPN. However, its taking a while due to issues I am working with support on. At the same time I am trying to get my head around ZTNA and from what I have been reading ZTNA uses SSL VPN too but in a more secure way. Please tell me that ZTNA using SSL VPN is NOT going to be going away any time soon???? I am looking to use ZTNA so users can access internal websites on port 443, SSH to hosts, RDP to hosts. I know there are different methods for each of these. I just want to make I am not wasting my time by setting this up with ZTNA.
Dear Team,Need your support to Understand the Industry Benchmark on the Secure Rating Score on the Fortigate Firewall.
Hi all I have a DHCP problem with my FortiAP setup.When clients connects to an SSID with Radius authentication, the client never gets an IP Address.In the FortiAP log I see the DHCP Discover and DHCP Offer, but not a DHCP Request and DHCP Ack.If the same clients connect to one of our SSID with WPA2 authentication on the same FortiAP, then there is no problem and the clients gets an IP Address. If I then move the same FortiAP to a different patch in the wall, but still connected to the same switchport (Aruba), then everything works and the clients gets an IP Address, and I see the DCHCP Request and DHCP Ack in the log.The only thing that is changed is the network cable from the office to the patchpanel in the serverroom.I have tried several patches in the office, some works and some don't. Bonus info. The Radius SSID uses DHCP Relay from a Windows Server, one uses same DHCP Relay as the Radius SSID, and another WPA2 SSID uses the Fortigate as DHCP Server, so I do not thin
Dear Expert,I face many issue during the working hours with LAN users. there are multiple security profile applied on the policy. like - Webfilter, DNS Filter, IPS, Application control, SSL inspection.I want to check which security profile first check in case any user try to access let suppose - https://abc.com (URL)I did google multiple time but could'find any better way.Example - USER (A) -- try to access URL - https://abc.comHow Security profile inspection happens. If I have applied - Webfilter, DNS Filter, IPS, Application control, SSL inspectionTroubleshooting steps should be in both way CLI and GUI if possible. I hope response will get soon from expert.
Hi, I have an issue whereby I am migrating from device based, to centrally managed AP management in FortiManager. We are on firmware v7.4.6 for Fortimanager and the Fortigates are 7.4.7. I have created the necessary AP Profile with the necessary WiFi networks manually added and then assigned this to an FAP231AP but when I try to apply the policy FM says there are no changes. This is the same for Installing device settings and the policy package. I have tried this on different APs managed by different firewalls too. I did find the following article which I followed as well but this did not work either; How to move from device AP Management to ... - Fortinet Community I have a support call also open and the issue can be replicated in the lab using the configuration backup I provided however I was hoping someone else may have encountered this problem before and got to a resolution? Thanks in advance.
how can i make use of Forti Analyzer to generate report to see which user or application is consuming alot of bandwidth until user start complaining of slow Internet access for one particular subnet. eg 172.28.0.0/24
I've been watching this alert to see if a solution is posted for the version we are running. I'm wondering though if the note for versions below 7.6 means that the only solution for them is to migrate to 7.6 or if there is a fixed version of the earlier versions in the works.
I have integrated FortiMail with the Google Workspace API and am now looking to implement the Phish Alert Button (PAB) within Gmail to enhance our phishing reporting capabilities. However, I have not found specific documentation on integrating FortiPhish's PAB with Gmail. Could anyone provide guidance or share their experience on how to achieve this integration? Any insights or resources would be greatly appreciated.
Hello,I would like to know how I could create some type of report, I have FortiGate and Analyzer, to show everyone who is accessing something related to AI on my network. I believe that the web filter can be used for this. Could you help me with a solution?Thanks.
Hello,I'm trying to create a new site to site vpn for a customer.Headquarter device is fortigate 80E, branch is fortigate 60F. There is already a site to site ipsec vpn between Head and Branch that is working internet provider's router at both site are not natted so fortigates route using public IP addresses.Now the customer has a new FWA faster connection at the branch and want to use this new for vpn to the HQ, but this connection has a router with firewall that we cannot disable and we cannot use a public IP address for WAN port of the branch fortigate.What are seeing connection from the HQ arriving at the branch on port 500, but when the branch sends out ike packet to HQ the branch fortigate shows error "network unreachble" Following an exaple of packet capture session 2025-04-11 16:40:01.021309 ike 0: comes 2.40.80.242:500->192.168.1.2:500,ifindex=6,vrf=0....2025-04-11 16:40:01.021384 ike 0: IKEv2 exchange=SA_INIT id=cdb44172569bf4cb/0000000000000000 len=5002025-04-11 16:4
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.