Mark a Best Answer
Fortinet Community
Recently active
HiI am a bit confused, I would like to add some ssl traffic inspection but for waf/ips, but I am not sure where/what's the best approach.I have a mix of Virtual server and Virutal IP. Should I use the Virtual server SSL Offloading configuration or using the SSL/SSH security profiles configured as "Protecting SSL Server" with certifcate and added to the ingress firewall rules sufficient?Also what about the same VIP/VirtualServer have mutiple domain hosted behind (abc.com, exmaple.com, bbb.com) how can all ssl traffic be inspected ?Thanx all !
We have an issue with FSSO-based web filtering that I so far have been unable to solve: We have the FSSO DC agents installed on all DCs. We have 4 AD groups set up, and we're using a guest profile set to Deny everything. Everything is working great, pulling in user logins, blocking sites, etc... Except for one thing. We have some users in our organization that either (1) Login from a PC with more than one username at a time, or (2) Admins will connect to other machines, either through CIFS/SMB shares or RDP using their 'Admin' accounts (our admins use a standard user account for day-to-day work activities). The issue is that when someone does this, the FSSO agent drops their normal user account from the list and adds the second account. Then when the second account logs off, it doesn't add the original account back, which means the first user account is now using the 'Guest' web filtering profile and they get blocked from all web sites. To
We're currently facing an issue with our #FortiGate 600E firewalls configured in HA (High Availability) mode. The setup was working fine before, but recently we've noticed consistent failures in the HA behavior under certain conditions. For exampleWhen we perform a basic action like ending a user session,When a user with read-only access interacts with the firewall,Or when we reboot the secondary firewall it unexpectedly becomes the primary, and the HA fails every time.These issues didn’t occur previously, and we haven't made any major configuration changes to the HA setup.Could you help us understand what's causing this and suggest a solution to restore stable HA functionality?Thank you!
I do not know a lot about IPSec except there are many layers of encryption in it. But I have to get Dialup IPSec VPN working for our company. I used the Wizard on the FortiGate to do most of the work. Then to build the FortiClient config I looked at the options and tried my best to select the ones that looked correct. But the initial connection is failing. At one point I saw a message that ike failed. The setup options for both the FortiGate and FortiClient EMS do not seem to be the same or even in the same locations. I have tried a manual config in the client and I have tried a config in EMS which is pushed down to me. The settings in EMS do not even match the settings you can do in the Client. Is there a way to take the FortiGate IPsec config and convert it to a FortiClient config that will work with it? Without being an IPsec expert?
Good morning everyone,I'm experiencing an issue managing my FortiAPs through my FortiGate. Specifically, I have 8 FortiAPs that I plan to manage centrally; however, as highlighted in the attached image, only 6 devices are currently online and accessible.Network ConfigurationHeadquarters:FortiGate 91GIPSec VPN connections established to the retail locationsRetail Location:Mikrotik RouterFortiSwitchOne or more FortiAPsThis is the only retail location showing this kind of problem. Has anyone encountered a similar situation or have any suggestions for resolving the issue? Any guidance regarding configurations, firmware updates, or specific settings to ensure that all FortiAPs are properly recognized would be greatly appreciated.Thank you in advance for your support and valuable insights.Best regards,Corniola AlessandroManaged FortiAP
been back and forth with forti support with no answer.LDAP with out token works ok .when we have forti token mobile we get the promt but we get regex error. (both for macOS / WINos) any one know how to solve that?
Hey all,Is anyone else experiencing issues with FortiClient VPN (v7.4.3.1761) on macOS Sequoia 15.4?It’s always worked fine for our team, but suddenly none of our Mac users can establish a VPN connection. We’ve tried both the standard FortiClient app and the iOS version—same result.The exact same credentials and config work perfectly on Windows, so it seems specific to macOS.Any ideas or workarounds?Thanks!
Hello! I have an issue related to FortiClient EMS and how it's deployment model installed on Windows PCs is needing to use the invite code for every AD user that signs into a PC. In other words, I'm doing something wrong for how EMS handles for AD users. I am deploying this for a client to manage web filtering profiles for verified AD users and sometimes these users need to access many different machines across the facility. Ideally, when a device is installed with the FortiClient program from the EMS deployment models, we apply the invite code and the device is tethered to our EMS server. This theoretically is all we need to do for handling the invitation, and once a user logs in with their AD credentials a unique web filter would be applied to them automatically no matter what PC they're on. Now, the problem is that we don't have a way to have FortiClient activate once we've installed it and used our invite code and instead, signing out and signing in between AD users show
Hi Friends, I am having trouble getting a 431F FAP to broadcast on my Cisco switch.It is connected to a trunk port. The switch tags Native vlan 75 back to the FortiGate.VLAN 75 on my FortiGate LACP is able to receive traffic and gives out an IP address to the FAP on this interface.I can authorize the FAP to the Fortigate. I can access the diagnostics and CLI via the FGT.The trunk port to the FAP allows ALL VLANs (probably not needed as it should tunnel via the VLAN75 interface right?)FortiAP diagnostics say the radio/ssid is UP but doesnt broadcast. Admin up / int down.When the FAP is plugged into a fortiswitch, it broadcasts. Even when the fortiswitch has 0 configuration, factory default. I tested this by plugging in ethernet port 2 into the fortiswitch. Whilst both ethernet cables are plugged in, my ssid broadcasts and I am able to authenticate into it.I dont think its a power issue because my cisco switch can supply 30 watts. Auto mode
hello, i have problem when i getting log from FortiAnalyzer This function is designed to retrieve logs from FortiAnalyzer and extract the application names from those logs.However, I'm encountering an issue where not all logs are being retrieved consistently.Some get log requests return the expected results, while others fail without any clear reason.def process_logs_for_policy_two_interfaces(policies_two_interfaces, src_interface_name, des_interface_name, offset, last_offset): # Ensure policies_one_interface is always a list global error_count if isinstance(policies_two_interfaces, dict): # If a single policy is passed policies_two_interfaces = [policies_two_interfaces] # Convert it to a list session_token = None # Check for existing policies before logging in policies_to_process = [] for policy in policies_two_interfaces[:]: # Use a slice to iterate over a copy of the list policy_name = policy["name"] policy_id = policy["po
Hello everyone,we are currently working on implementation of the FortiClient Agents on all of the computers and servers in our company.After installation of the FortiClient and entering the invitation code, the user is required to sign in with its domain credentials in order to be connected with FortiClient Cloud.But what about servers? Which domain credentials should be typed in on a DC Server to connect to Forticlient Cloud?
Hi, I'm sure this is something I'm overlooking but it does have me a little confused. My Fortigates are still in a lab setting set to roll out to production in the coming weeks. Currently I have two Fortigates with private IP on WAN ports 192.168.2.1 Fortigate - > Cisco Switch 192.168.2.2192.168.6.1 Fortigate -> Cisco Switch 192.168.6.2 192.168.2.1 can ping 192.168.6.1192.168.6.1 cannot ping 192.168.2.1 but 192.168.6.2 can ping this IP. Monitoring the interface on the 192.168.2.1 firewall. When everything other than 192.168.6.1 pings - it sends responses. When 192.168.6.1 pings - it receives the pings but does not reply. Anything (obivous) I may be overlooking here? I don't see any SD-wan rules or policy routes that would apply... Any suggestions with debug commands I can use would also be appreciated. Thank you,
Hello,Is there a way to see in Fortigate how much bandwidth (Mbps)is consuming an internal user?I recall before in fortiview it showed this but now (FortiOS 7.4) I can not see it. Only shows traffic in Bytes (MB). thank you.Regards.
Hey folks,I ran into a problem after migrating my WAN interface into SD-WAN because I wanted to add a secondary ISP connection. I know I should have added my ISP link to SD-WAN from the beginning but that's for another day. My Site to Site VPN get disconnected when I enable the 2nd ISP link, it goes back to UP when I disable the link. I've already raised a TAC ticket but it's so slow.I've added an SD-wan rule to the remote peer IP to go though the ISP1 (Which is the VPN interface). But issue is still here.While pcap on the ISP2, I found that ISP1's packets are being set though it. Also find VPN port 4500 being sent through that link too. My VPN setting are all same, with ISP1 as the listening interface.I'd really appreciate any help from this community.
We've got around 60+ devices to enrol with the FortiToken app and would like to distribute via our MDM solution. To avoid each device requiring access to the app store and having a google account we would need the apk file. Has anyone done this before and what is the safest way of extracting the apk file? Thanks Lee
Hi, I used FortiClient to access to VPN for some weeks but then suddenly something changed. I'm not able to access the VPN anymore. I don't even find the server that I saved and used to access to. In the application window I don't see where to insert all the server information anymore. It also says "FortiClient disconnected". Why's that? Thank you very much.
Dear Experts,we need you expert opinion regarding DDoS attack Mitigation.We are running Fortigate 500E HA cluster (6.0.x) in our production environment. we want to protect our web-servers again DDoS attacks. What measures/steps should we take on our Production Fortigates to be able to protect our webservers in DMZ.I know there are some dedicated products available from Fortinet for DDoS, but we are in a money saving mode nowadays that's why we are looking for the best practices available on the Fortigate.Thank you for your response and time.
I have a 100F that lapsed on licenses over a year ago. It had been pulled from use so it wasn't part of our renewal back then. I know if we go to renew licenses now we're responsible for the lapsed period, though I've seen references that it's capped at 6 months and waived for 2+ year renewals. Those posts are over a year old, and several reference it not being official information. A non-profit I do some work for could really use the unit. I have the approval to donate it and transfer ownership, but just wanted clarification on the current handling of lapses.Is the 6 month backdating and waiver for 2+ year renewals still something Fortinet does and/or would this even apply with an ownership transfer?The cost difference of a 3 year license vs buying a new 100F w/3 year licenses isn't huge, but it's enough that I can get them a new Forti switch they also desperately need with that money.
I have been struggling with forticlient on Opensuse Tumbleweed. It worked fine until last week but now, after a zypper dup, (I did others before and there were no issues) I can't establish the connection anymore. Even trying boot across previous system snapshot, it doesn't work. I use a SAML integrated VPN and it authenticates successfully just before the client dropping the connection. Can anyone help me to fix this? 20241203 16:50:09.950 TZ=-0300 [sslvpn:INFO] main:1817 Init 20241203 16:50:09.951 TZ=-0300 [sslvpn:INFO] main:622 Load profile: BLN 20241203 16:50:09.952 TZ=-0300 [sslvpn:DEBG] main:631 Inherit local DNS: No 20241203 16:50:09.952 TZ=-0300 [sslvpn:DEBG] main:644 DNS service resetting interval: 0 20241203 16:50:09.952 TZ=-0300 [sslvpn:INFO] main:329 Get DBUS session bus address 20241203 16:50:09.954 TZ=-0300 [sslvpn:DEBG] main:333 Failed to find DBUS session bus address in dbus-daemon, try to find in dbus-broker 20241203 16:50:09.955 TZ=-0300 [sslvpn:
Hello Everyone, In the firewall GUI, each time a random user disconnects, we see the reason listed as "User requested termination of service." Do you have any insights into this error? forticlient version's7.2.77.2.37.4.3 2025-04-08 16:49:06 [324:root:2a0]deconstruct_session_id:494 decode session id ok, user=[userxxx], group=[VPN_Group1],authserver=[auth_server],portal=[full-access],host[x.x.218.x],realm=[],csrf_token=[xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx],idx=1,auth=2,sid=797357f,login=1744117062,access=1744117062,saml_logout_url=no,pip=x.x.218.x,grp_info=[EOsIBv],rmt_grp_info=[v7ATir]2025-04-08 16:49:06 [324:root:2a0]session removed s: 0x7fb534392000 (root)2025-04-08 16:49:06 [324:root:2a0]deconstruct_session_id:494 decode session id ok, user=[userxxx], group=[VPN_Group1],authserver=[auth_server],portal=[full-access],host[x.x.218.x],realm=[],csrf_token=[xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx],idx=1,auth=2,sid=797357f,login=1744117062,access=1744117062,saml_logout_url=no,pip=x.x.
My site https://zarashigal.eu.org/ Is static html, hosted on GitHub pages and has no Phishing. Would you please show me where the phishing risk is on my personal site? And if not, please delist it. - Many thanks and Respect,Zarashigal
I have VLAN with IP 192.168.100.0/24 and over IPSec network with IP 192.168.100.0./22.Local users on another VLAN 10.60.18.0/23 need to access the network over IPSec and do not need to access the local network. Current situation is that users are able to access the IPSec network except those IPs that are overlapping with local IP. In other words, users are able to access IP range from 192.168.101.x, 192.168.102.x etc, but are not able to access 192.168.100.x, which because I believe because of the presence of local VLAN, despite having proper firewall policy and static routing.Any idea how to resolve this?
Dear all, Please have a look at the following Lab. We have a Windows NLB using Multicast across one Server only. The NLB virtual IP is 192.168.169.25/24, and the real server behind the NLB is 192.168.169.24 The Server just connected to a Cisco switch without special configuration, even no vlan and IP on the switch. The spanning is enabled as RSTP to prevent looped. The Fortigate wan1 connected to the the same switch to allow access from/to the Server as well. At this moment, everything is working fine and the ping result likes this: Now, let's try connecting the HA1 interface to the switch: Why numerous Dup! message come up to my Fortigate even the HA1 is a standalone interface without joining any Firewall software/hardware/Vlan switch?
Hi!!,I’m having trouble registering the free evaluation license for my FortiGate VM within my network. It’s likely that my internet provider is blocking some ports or addresses. Could you help me by providing a list of all IP addresses and ports that the FortiGate VM uses to connect for license registration? Thanks in advance!!
Hi Team I am Tring to migrate FG 200D to FG300 Using Forti converter FG 200 having 50 IPsec Tunnels. in that scenario all the configurations including Tunnels are migrated to FG 300 device or else if any changes required in tunnels side.Migration happens one day it's enough or else if take more than day.please guide me
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.