Mark a Best Answer
Fortinet Community
Recently active
Since updating to iOS 18.4 from ver 17 last week, when I click "Connect" there is an error saying "permission denied". I have tried removing and reinstalling the appDeleted and recreated my connections.There is no issue with the connection as even when I put dummy setting in, it doesn't even try to connect.Have tried on another phone running lower iOS version, if dummy server details are put in it will try to connect and saying connecting.... With iOS it doesn't even try to connect. Every time says "permission denied" Forticlient 7.4.5.0174 Iphone 11 (Same on Iphone 13) Status says "Invalid" Thanks
Good evening, could you tell me which Fortinet courses offer a certificate in Spanish? I took one and didn't receive any certification.
What are the IPs and ports need to open from private network for access SASE from FortiClient which protected by Firewall.
Is there a command that can be ran to see the commands at the console to make the associated change? Basically, we want to document a faster way to configure new devices but don’t use the console often currently. I want to do a config and then document the commands so we can quickly load up a new device with a base set of configuration.Thank you!
greetings all,we are using FortiGate firmware 7.2.10, the hardware device is installed in China and is connected to a FortiManager in Europe. I believe all the configuration is pushed from the FortiManager, for example, the changes to configuration like SD-WAN rule, firewall policy, VPN, etc., is pushed from FM to fortigate to be effective.My question is where the configuration (file) is stored? Is it centrally managed or stored in FM? I cannot find it from the fortigate GUI. What if there is a power outage occurs to the Fortigate, will it come back with all settings as it had before the power outage? Thanks for the help.
Is there any way to block upload of the grater than 6 number of files within the 10 minutes above 25MB Thank you.
We configure Microsoft Entra ID SSO with FortiSASE support of Configuring FortiSASE with Entra ID SSO in FortiClient agent-based mode document. But we have faced error as below. Searching for solution...
Hi!I'm struggling with CLI template in FortiManager right now. I must delete all dhcp servers and I made script where I use purge command, but the problem is, it gets stuck there. There is prompt where user must press y to confirm what you are doing, but I cant make it work in the script. When i copy that script manually to FortiGate then it works.I read from other posts that few people got it work when they used \ny after purge command or added y below the command or right before end command "yend". All these ways didn't work for me. I also tried both CLI and JINJA template
Haven't really looked at this for a solution, but I have a question, I want to create a Global Header Policy, and push to 10 FortiGates in an ADOM, seems straight forward, apart from I want to create my own normalised interface in the Global ADOM , called "WAN-GLOBAL" and select devices to map there repsective interfaces (some are wan,wan1, port1 etc) but you cant do this. You can only map interfaces from devices in the ADOM, thats pointless, as I cant then use a normalised interface in the Global Header, as it cant map to anything? is it just a name in the GLOBAL HEADER? as long as its called the same there, and in the ADOM mapped interface?
Hi everyone, on our FortiGate firewall we have a remote site (AWS cloud) reachable via Direct Connect and IPsec VPN.All traffic related to private networks flows through the Direct Connect connection. Only Internet traffic flows through the IPsec VPN. A resource on the remote site needs to be exposed to the Internet for FTPS traffic. I have configured routing, policy routing, and used a VIP. However, if I don’t enable NAT in the firewall policy that allows incoming traffic, the sessions time out. When I enable NAT, FortiGate performs source NAT using a private IP address, and I have no idea where it’s coming from. My doubt is that the remote resource will see the traffic incoming from a private IP address instead of the public IP and the flow will not work.Am I missing something in the configuration? Thanks for the support.
We have a unique problem that has me a bit stumped. Our end user laptops route their untrusted internet traffic over client IPSEC VPN tunnels to our Fortigate VM in Azure for threat scanning and then out Microsoft's internet connection. This has worked fine for a couple years , but increasingly, some internet sites don't like internet traffic originating from Microsoft's IP's, and won't allow the traffic or require the user to be authenticated. (Ticketmaster, Reddit and Youtube are a few) We have a couple physical locations with Fortigate 60Fs that are connected to our Fortigate VM in Azure via Site-to-Site VPN tunnels, and they have lots of spare internet bandwidth at those sites, so we thought we would try routing the internet traffic from our end user VPN tunnels over the site-to-site tunnel and out the internet connection at one of those sites to get around the Microsoft IP issues. We setup the site-to-site VPN tunnel on the Azure Fortigate to the
Dear all,I created a script that first needs to delete table of reserved addressed for DHCP server before it starts creating new entries.However, purge command requires confirmation from the user and this is something that I don’t know how to achieve inside of the script. If I’m entering commands one by one there is no issue.I’ve tried with solution recommended here: https://community.fortinet.com/t5/Support-Forum/Inserting-a-PURGE-command-into-a-script/m-p/29958 but without success.Here are the details:Script:config system dhcp serveredit 4config reserved-addresspurge\ny <--breaks hereedit 0set mac 4c:02:20:5c:65:61set action assignnextedit 0set mac 28:c2:1f:5b:f2:35set action assignnextendOS version is 7.4 Thank you in advance!
I am trying to put a cert on the SSL VPN. All I have access to is wildcard certs. I have already tried and failed, and now I am wondering if I can or if I am doing it wrong.
Hi, Whenever we edit the prefix-list or route-map associated to a specific BGP/OSPF neighbor, we have to clear the BGP/OPSF process to see the effects of the newly made changes. This adds an additional overhead every time we make changes.We would like to understand if this is some kind of fail-safe mechanism or is there anything which we are missing in our configuration. TIA :)
My observation:Secure Boot is a general control intended for the configuration review of firewalls. We are using a customized image during firmware updates, which makes this option not mandatory. You can either provide this justification to close the finding or, if feasible, implement the control using the attached reference https://docs.fortinet.com/document/fortigate/7.4.0/new-features/249947/enhance-bios-level-signature-and-file-integrity-checkingWhat is the relevance of changing the security level to 1 and how we can do this?
Hello.We have configured the FGT as an SSL VPN terminator, implementing posture/compliance controls with the FortiClient EMS without any issues.To force clients to not "skip" the posture and connect to the VPN by downloading FortiClient Free (since doing this the EMS cannot enforce the client's posture), we added the command in the FGT: config system globalset vpn-ems-sn-check enableend We tested this and it works fine.The issue is that now we need a mixed environment: clients with posture and clients without posture (i.e., FortiClient Free and not connected to the EMS).For this, the current solution doesn't work anymore...Is there a way to do this granularly by SSL VPN portal or similar? From what I've seen, SSL VPN is for the entire FGT globally.thank youregards
This afternoon I upgraded from 7.0.15 to 7.2.10 and to my surprise the packet capture GUI changed to complete garbage. Not only that, I have lost the ability to capture multiple interfaces like before.Is there any way to get the ability to capture multiple interfaces into their own pcaps like before?Maybe it is hidden in the cli somehow?
Hello,Wanted to ask for some guidance on configuring the Simultaneous Connections and Idle Timeout parameters, especially for untrusted or Public-Facing SMTP Servers.Didn't find anything on the web, so asked ChatGPT, and this is his response. But I wouldn't take it for granted, so I'm here for some expert opinion1. Internal Mail Server Relaying Mail to FortiMail (e.g., Exchange, Postfix)Scenario: An internal mail server handles high-volume email relay, such as sending newsletters, transactional messages, or processing bulk emails.Recommended Configuration:Max Simultaneous Connections: 20–50Rationale: High-volume mail servers may open multiple simultaneous connections to efficiently deliver a large number of emails. A higher number allows for quicker throughput.Reference: FortiMail’s Session Profile Configuration suggests adjusting connection limits based on your mail system’s throughput requirements.Idle Timeout: 300–600 seconds (5–10 minutes)Rationale: Allows for temporary p
We just installed a Fortigate 40F running v7.0.17 0682Our workstations cannot see the Active Directory Domain Controller. I can only assume this is because of adding the domain to the DNS, or setting primary DNS Suffix.All documentation on setting DNS suffix seems to point to VPN or IPSEC, and that's not the case. I'm thinking DHCP, but I cannot find where to set primary DNS suffix.The Fortigate is set as DHCP.Any ideas or other suggestions?
Several of my teammates using MacOS when they are working from home are experiencing lags in Teams (but not in other programs or on speedtest) since they updated FortiClient a month or so ago. They did not have these issues before the update. A couple of them come to the office hybrid and do not have the issue on the corporate network. At home all users have the issue whether the VPN is connected or not. Any ideas?
This is intermittently happening to me and some teammates. We have Macs and log into our corporate active directory (azure). Connecting to VPN on FortiClient opens up a browser tab in Chrome; usually this connects quickly and then has a message about being able to close the tab and then FortiClient connects. However, sometimes the browser window that pops up just hangs and stays empty forever, and FortiClient does not connect. To fix this we usually have to reboot. I opened the Chrome dev tools to see what was going on, and it appears that the web page that opens is trying to connect to http://127.0.0.1/8020 and that never responds. Is there a permanent fix for this so that we don't have to reboot to connect to VPN?
Hello after active ZTNA in FORTIPAMi have a messge error from gui access ,help me pleaseAccess DeniedThe page you requested has been blocked by PAM policy restriction.Invalid ZTNA client certificate
Hello,I have a SSL indound inspection that is not working for email traffic. The action is "Bypassed" "Message SSL connection is bypassed" says on the SSL logs....does anyone know what cold be the case?On SSL profile we are inspecting ALL ports. Thank you.
Hello everyone,This morning we had a situation at the office.We have a FortiGate 80F at the office.So here’s what happened: we have VPN configured with MFA through an NPS server in Azure.There’s a Site-to-Site (S2S) connection between On-Prem and Azure VNET.This morning, the local Active Directory (AD) server went down, so the VPN couldn’t connect — even though we also have AD in Azure, which is accessible from On-Prem.But we have the LDAP server configured to use the local AD.So the question is:Is the RADIUS server (configured on FortiGate) dependent on the LDAP server that is also configured on FortiGate?Thank you in advance!
Hi all, I would like to know until which date it would be possible to take the FCSS SDWAN in version 7.2 ?Where can I get this information ?In the Fortinet Institute, the courses I took are now archived and I'm following the courses in version 7.4 but in the Pearson Vue Portal, I don't find it in version 7.4, only 7.2 version is available for the SDWAN certification...Other question, I'm looking for any others sources that Fortinet Institute, for this certification, book, vidéo etc...Do you have a best seller to advice me ?Many thanksRegards
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.