Mark a Best Answer
Fortinet Community
Recently active
Hi All, My FG is setup to block opera browser. It works for some pages (blocked app info) and not working for other (for example we can open cnn.com and FG isn't recognizing it it as a opera browser. It sees https.browser). RegardsMbrodzin
Hi, I am doing for backup fortigate config with oxidized tool. What I need is a read-only user to let the tool login the fw via ssh, show the config, make a diff and copy it into the git.I created a new profile with only read rights, created a user with this profile.When I try to ssh with this user, the ssh client directly close the connection. ¿Can you help me please? What am I doing wrong?
Hi,Our topology is quite simple - 40F Firewall connected to POE FortiSwitch, 5x831F and 2x221F Access points connected to the FortiSwitch.The FortiSwitch and APs are managed via the 40F Controller.The 40F Firewall on a different interface is connected to Cisco Switch for RJ45/Cable connections, which is connected to more switches etc. From the idea of not wasting overhead for CAPWAP Tunnel mode, the SSID's have been configured as Local switching, the interface terminates on the firewall. I've been asked to extend the STAFF SSID's VLAN to the Physical network - and I see that there are 2 options to do it - the first is to connect the FortiSwitch to the Cisco Switch to span the L2.the second option would be to create a Software Switch, configure the SSID to use tunnel mode and terminate it on the interface connected to the software switch. question is - would it have negative effect on performance ?
Hello, I am seeing a lot of posts about configuring Oauth 2.0 for diverse Forti products but FortiManager and Fortigates. Is there a planned feature to enable this for notifications and reporting ? We use a O365 smtp server and legacy authentication will soon be dropped.
Hello everyone,I would like to know if you can tell me the EOL and EOSL dates for the FortiAP FP221E.I couldn’t find this information in the datasheet.Thank you.
Hi,In my FortiGate firewall GUI (they are all running version 6.x), each policy rule has an ID field. But in some screenshots (mostly of firewalls running older software versions) I have seen the possibility to display a "Seq.#" (sequence number) column too. E.g. there's a screenshot in this forum thread that has this Seq#: https://forum.fortinet.com/tm.aspx?m=115842However I can't seem to find that Seq# anywhere in the GUI.How can one display this?Have they removed this in version 6?
Hello, I have configured two fortigates as ha and configured 1048e switches as mclag. I have turned off the split interface and I am using lacp mode active. I am wondering if I should monitor the fortilink interfaces on the ha monitoring interface? In a failover scenario, there seems to be more downtime on the FortiSwitches if traffic switches to the secondary FortiGate. Is there a best practice for this?FortiGate FortiSwitch
Hello everyone,  have a FortiGate 91G managing a FortiSwitch via FortiLink over IPSec. While the FortiLink connection is successfully established, when I configure the DHCP relay on the VLANs, client devices are not receiving IP addresses.Has anyone encountered this problem or found a solution? Any guidance would be greatly appreciated!Thank you in advance.
Hello, We are based in Turkey, and a user in Kazakistan is unable to connect to VPN. Other users in Turkey and other countries such as Thailand are able to connect with the same username and password. The exact error we get is "Unable to establish the vpn connection. the vpn server may be unreachable. (-5010)" I couldn't find anything on error 5010. We tried connecting via cellphone, connecting from a public internet but the error is still the same. Then we formatted the computer, it's still the same. I will be glad if someone can help. Thanks in advance.
Hi,We are migrating from AnyConnect to FortiClient and encountering many problems. Currently, a RADIUS server (NPS) is being used, which passes Cisco RADIUS attributes such as IP address, subnet mask, and a dynamic ACL (DAC) for each user.For each user created in Active Directory, a static IP is assigned, the RADIUS profile to use is specified, and the corresponding ACL policies are created on the ASA.On the Fortigate side, I have configured the RADIUS servers and set up the entire SSL portal. Since the IP is passed statically, I found a guide that suggested setting "set ip-mode user-group" under the portal.I also created the corresponding ACL that allows from SSL VPN to any, but as soon as the MFA notification arrives with Duo, I get permission denied (error -455) and the process stops at 43%.Does anyone have any suggestions?I've tried everything but can't solve it.Below is the configuration. config vpn ssl web portaledit "RADIUS1_PORTAL" <---- my 1st portalset tun
I’m at a hotel using a wifi network and cannot get FortiClient to connect to my work VPN. The connection works if I use mobile data tethering to my iPhone. When I click connect, after about 10 seconds, a message comes up saying cannot connect, timeout error. A few relevant facts: I am using an iPad Pro. All software is up to date. I’ve never had a problem on my laptop. I am in Mexico but location is not an issue as mobile data works and Mexico access is temporarily allowed. access is through port 4433. The hotel systems person says no ports are blocked and it should work. Any ideas on possible solutions or things to check?
Hi, FortiManager Version - v7.4.6 build9266 (Mature), ADOM - 7.4FortiGate-40F-3G4G - v7.4.7,build2731 (GA) (Mature)FortiSwitch-108E-POE - v7.4.5-build880,241127 (GA) Just trying to build a little lab setup using the kit above. When creating a VLAN (FortiSwitch Manager > FortSwitch VLANs), I am able to create the VLAN without issue and apply the VLAN to the switch using a template. The VLAN shows up on the FortiGate and all looks good. The issue is when I enable DHCP on the VLAN. When attempting to save the config I get the error message: - Copy device global objectsCopy objects for vdom root Commit failed:error -999 - TCL error(missing operand at _@_in expression "(24<<24)+(_@_<<16)+(<<8)+") namespace import global::cli_ip2valset startip_str [cli_get_value $CLI_CUR_NODE "" "" "start-ip"]set endip_str [cli_get_value $CLI_CUR_NODE "" "" "end-ip"]set id [cli_get_value $CLI_CUR_NODE "" "" "id"]set startip [cli_ip
hi friends, a question:to consult about changing the name of the Host where the installation of FortiClient Endpoint Management Server is locatedit will still work or you need to reinstall EMS ?
Hi all, I'm running a FortiGate 60F with v7.2.11 build 1740. I've added a Traffic Shaping monitor in my Dashboard but can't find a way to reset the counters:In Dashboard -> FortiView Traffic Shaping there is no 'Right-click' option to 'Clear Counters'. If i go to Policy & Objects -> Traffic Shaping there is an option to select 'Clear Counters' for each Traffic Shaper but i doesn't reset the counters shown in the FortiView monitor. Tried the cli as well (diagnose firewall iprope clear 100015) but same result as above. Thanks, Michael
All my user with the same installer profile have a status unreachable profil today.
Hi everyone! :) A couple of days ago, I upgraded a client's Fortigate 200F firewall cluster from 7.0.14 due to recent vulnerabilities. The latest recommended version for this model is 7.4.7, but we opted for 7.2.11 instead because of a known bug in 7.4.7 that prevents HTTPS access to the secondary node. The upgrade itself went smoothly—everything seemed fine, HA was in sync, and all functionalities appeared to be working properly. However, we ran into issues with their IPsec tunnels: The tunnels are up and passing traffic, but most services and subnets are unreachable.Restarting the tunnels didn’t help.Downgrading to 7.2.10 didn’t fix the issue either.Downgrading further to 7.0.17—and everything started working normally again.Possible Causes?I suspected this might be related to cipher compatibility between versions, but the tunnel appears to be using the correct ciphers, and I’d expect an issue like that to affect the entire tunnel, not just certain services/subnets
Hi all, i am facing one of the strange issue with FortiGate 401F model it run Firmware Version 7.0.12. suddenly sometimes this FortiGate stop working even i can not access internal corporate subnets and internet but when i am checking 8.8.8.8 from FortiGate firewall Console i can reach to 8.8.8.8 but client can not ping 8.8.8.8 and can't brows to the internet.i was opened TT with FortiGate Tach still they are also looking for this issue this issue happen sometime in a week two times and sometime in a month. i troubleshoot allot and check the internal network after troubleshooting the last thing which i did it was i configure on of the physical port of the FortiGate to check and allow that test subnet to internet for testing purpose when this issue happen i connect my laptop direct to that test port but i had no internet so due to that i figure out that issue is with FortiGate firewall becouse even direct from FortiGate i dont had internet, during this period
Hi all, I have a large LAN ReDesign Project. I will Change all Aruba Switches, which are EOL to new FortiSwitches. With this Change I will Change the IP-Subnets, too. My Concept is, that all FortiSwitches get a own VLAN. For CoreSwitch I choosed a FortiSwitch 1048E, which I connected to the free 10 GBit/s X2 Port on the Fortigate. So I configured the X2 Port with the following IP-Config: 10.100.99.1 / 24Receive LLDP: EnableTransmit LLDP: Enable Administrative Access: HTTPS, SSH, PING, FMG-Access, FTM, Security Fabric Connection I configured the FS1048E with the IP-Adress 10.100.99.2 / 24. I leaved a small Config first time. I connected the FS1048E on the X2 Port of Fortigate, but I can´t reach the FS1048E. Administrative Access on the FS is HTTPS, SSH, PING. I tried to ping the Fortigate from CLI of FS1048E but I can´t reach it. I tried to ping the FS1048E from Fortigate CLI and can´t reach the FS1048E, too. Normally it is an easy job, but in this time I don´t under
I am running into an issue with both the FortiClient and the Windows Native VPN, and not sure what is happening. I created the tunnel via the IPSec Wizard for a Windows 11 device. I chose Windows Native, configured the pre-shared key, set my user via LDAP, all the fun stuff you would do. For some reason, when trying to connect, it is telling me that the preshared key is invalid, even though I have typed it, copied and pasted it, etc. to get past phase 1. The PC in question is a Copilot+ PC, so it's running ARM64. I found that there is a new FortiClient for ARM64, so I removed the Windows Native configuration and setup a new one using the FortiClient option for the tunnel. Still, I am getting the same error with trying to authenticate. Relevant Configuration for the WinVPN setup I have: IPSec Config: show vpn ipsec phase1config vpn ipsec phase1end show vpn ipsec phase1-interfaceconfig vpn ipsec phase1-interfaceedit "WinVPN"set type dynamicset interface "wan1"set
Hi Team,I'm facing an issue with FortiClient VPN at one of my client sites and would appreciate some help or insight.We have been using the free version of FortiClient 7.4.2, and it's working perfectly fine for IPSec remote VPN connections. However, as per the client's request, I recently installed FortiClient version 7.4.3 (free version) on two new PCs. After installation, when trying to connect to the VPN, the FortiClient application closes automatically without completing the connection. Is this a known bug with 7.4.3? Are there any patches or configuration changes required for the free version?Any help would be greatly appreciated.Thanks in advance,Aslam.
We have recently switched the SIP from normal TPlink router to fortigate firewall somce than we are not getting audio over external call internal calls are fine but when we are calling to a mobile number no audio on both end
Hello, We have some hosts that are blocked from the internet. However, we want them to communicate with Microsoft Defender. I have followed https://community.fortinet.com/t5/FortiGate/Technical-Tip-Allow-Windows-Defender-in-firewall-policy/ta-p/284854 and added the FQDNs for cloud-delivered protection. When running the batch command provided by Microsoft https://learn.microsoft.com/en-us/defender-endpoint/configure-network-connections-microsoft-defender-antivirus to check the connection, I'm getting failed error. Below is the policy applied to those hosts. # show firewall policy ** config firewall policy edit ** set name "Allowed Policy" set uuid 8ac35f8c-eadf-51ef-****-694c164***** set srcintf "lan" set dstintf "wan1" set action accept set srcaddr "HOST_ADDRS" set dstaddr "Microsoft Defender" set schedule "always" set service "HTTPS" "DNS" "PING" set logtraffic all
Hey friends. I have a task that is basically collecting logs in a single place. We have FG in the HQ and Mikrotik routers on our remote sites. They are all connected with site-to-site IPsec VPN. My question is, can I use FAZ as a Syslog server to collect all the logs in a single device? Or FAZ is just for log analyzing?Thanks in advance.
HI All,I understand the Fortigate vWAN offering runs in Active/Active with FGSP sharing the sessions over both NVAs. This is not an issue for most traffic however, when trying to access Fortimanager from inside an Azure vNet it kicks the session out after about 20 seconds..I believe this is because the source public IP is changing due to the Active/Active setup, this would be the same for Banking etc... Other than putting a UDR in to bypass the NVAs what are the other options? Is there any changes within vWAN that can support an Active/Passive setup?
Just created a couple Virtual IP's for NAT and an associated Group for them referencing article ID 198195 however when I go to create the Firewall Policy the destination for the newly created Virtual IP's/Group are not found.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.