Mark a Best Answer
Fortinet Community
Recently active
Hello everyone, I'm planning to set up two Fortigate 60F (with HA active/passive) and two Fortiwitchs 148F-POE. Before the setup, I created a diagram and wanted to know if my topology was correct and i have questions. - My configuration is correct ?- Do I need to create a trunk between the two switches, or is it not necessary? - Does FortiLink Split Interface need to be enabled? If so, on both FortiLink interfaces A and B of the main Fortigate ? Thank you for your help.Chris
Guys I'm trying to block access via FTP but I'm not succeeding I'm following this https://docs.fortinet.com/document/fortiweb/7.6.2/administration-guide/398215/creating-an-ftp-command-restriction-rule someone could give me a light
I have configured a dialplan to dial some operator numbers in Brazil, 10331, 10315, 10385, etc.I use the configuration: 103XX. in the Match Patternhowever the call is not forwarded to the operator's VoIP trunk. Doing the Test Call-Dry Run, I have the resultDry run start <1743023907>Info: Matched dial plan: Out_Trunk_UPIX_103Dialed number: 10331Outgoing number: 10331Outgoing trunk: trunk_TRUNK_IP_UPIXCaller ID: <0000000>Dialing 10331 on trunk PJSIP/trunk_TRUNK_IP_UPIXDial status: SUCCESSDry run end <1743023907> In Logs, it showsReject INVITE message from: 'H C' <sip:7554@10.xx.xx.11> to: <sip:10331@10.xx.xx.11>, Cause: Service Unavailable
We have a FortiAuthenticator implemented in out environment and we want to use a local user to Drift/Counter Sync the fortitokens when it's needed. Problems:The minimum permissions to that user is through an "admin profile", read & write "Users and Devices". He can then access directly the link https://IP/admin/fortitoken/fortitokendrift/ but he can also access the Authentication\User Management. We don't want that.Through "$env:SystemRoot\System32\curl.exe" and powershell script we just have GET and DELETE. The idea was to GET the list of fortitokens and POST with the 2 codes but POST doesn't exist.Also through SSL using "exec fortitoken sync FTKXXXXXXXXXX 111111 222222": No such command...Any other idea to Sync these fortitokens using a script? Or block the user to that specific URL? Or remove the left menu for that user? Thanks
I have created a Read-Only user and i want to grant the user with specific command>> config system console >> set output standard >> execute date FortiGate FortiGate Cloud
As per the following link, can we have vdom on cloud firewalls. Wil they function properly? https://docs.fortinet.com/document/fortigate-public-cloud/7.2.0/aws-administration-guide/229470/deploying-fortigate-vm-active-passive-ha-aws-between-multiple-zones
Hello,Thanks beforehand for any help regarding my question. We have a simple multi-WAN setup where a particular element I cannot fully understand.Two subnets, e.g. 192.168.0.0/24 and 192.168.1.0/24 managed by our Fortigate firewall, connected to one WAN interface (WAN1.) In the firewall there also is a IPsec connection. We have created policy routes to say that the first network should go out from WAN1 and the second one, through the IPsec connection. In the IPsec connection, I noticed that the gateway is set to 0.0.0.0/0. Notice that I'm not talking about the destination address in a route. I'm talking, specifically, about the gateway itself. So, how does this make sense? And how is it possible that the setup actually works, taking into account these conditions? Thanks and have a good day all!
I have topology with this details - Hub subnet 10.103.0.0/16 - Spoke1 subnet 10.100.0.0/16 - Spoke2 subnet 10.4.0.0/16 and 10.107.0.0/16 - Hub and Spoke have 2 internet connection. - ADVPN and BGP was established also with the shortcut tunnel - ADVPN1 subnet 10.10.111.1/28 (hub 10.10.111.1, spoke1 10.10.111.2 and spoke2 10.10.111.6) - ADVPN2 subnet 10.10.112.1/28 (hub 10.10.112.1, spoke1 10.10.112.2 and spoke2 10.10.112.6) - SDWAN SLA from spoke2 to spoke1 in good conditions (all is green)- SDWAN SLA from spoke1 to spoke2 in good conditions (all is green) - Traffic from spoke1 to spoke2 via tunnel 10.10.111.6 - Traffic from spoke2 to spoke1 via tunnel 10.10.111.2With this scenario i try to disable tunnel 10.10.111.6 in spoke2 and this make spoke1 can't reach spoke2 and vice versa. From spoke1 point of view, routing table to 10.4.0.0/16 already change to 10.10.112.6 but why routing table on spoke2 to reach spoke1 still use 10.10.111.2. Actually tunnel interface 10.10.112.0/28
Is FortiNAC able to change VLANs on a hypervisor's vswitches - WMWare, Proxmox, Citrix Xen, etc ?FortiNAC
In the past when we pushed out the latest Forticlient VPN client (free) users would get the prompt to restart to complete the update. This latest release doesn't prompt at all, instead the only indication that it has been updated is the UAC prompt when you attempt to run it. Is there some reason this version doesn't display the update prompt? Is there a way to enable it?
Hi!Trying to figure out if I can make my scenario work.So I have a FG + Fortiswitch with NAC Mode on the switchports.Have configured NAC policys that work and deploy devices on different VLANS.What I've tried to do is to connect a dummy switch to one of the "NAC" Ports and connect devices to that.Devices seem to get the right NAC policies but IP connectivity doesn't work. I wonder if I'm missing something to make it work? Or if it's just not supported.
Hello everyone,I'm an IT engineer at a company currently using FortiGate 60E devices in a high availability (HA) setup (2 units).We are planning to upgrade both units to FortiGate 60F, and would like to maintain the HA configuration after the upgrade.We are currently running the following firmware version on the 60E:#config-version=FGT60F-6.0.4-FW-build0231-190107 I’ve read about the FortiConverter tool, but it appears to require a separate license. Unfortunately, we only purchased the hardware and do not have a FortiConverter license.I'd really appreciate some advice on the following points:Can we export the configuration from the 60E and import it directly into the 60F?Will there be any compatibility issues or required modifications when migrating the config between these models?Are there any important considerations or steps we need to follow to re-establish the HA setup on the 60F units?Any recommendations or best practices from those who have done similar migrations wou
Hello,I'm currently trying my hand at SAML authentication with FortiAuthenticator in conjunction with FIDO keys.- I can successfully import a Fido key for a local user- FQDN of the authenticator is identical to the SAML FQDN- Certificates are valid- SAML Login with Username/Passwort is working- SAML ServiceProviders to FortiAnlayzer and FortiMail But as soon as I say in the SAML SP settings that it should authenticate via FIDO, “Error occurred during Fido Authentication” is displayed after entering the user name.No error in the FortiAuth-Event Log - just "Local user authentication partially done, expecting fido token FortiAuth Version 6.6.2 The strange thing is that I had the SAML login with FIDO running until a few days ago, then I changed the FQDN name of FortiAuth again - since then it no longer works. However, I have adjusted and assigned all the certificates.
Hello All,I was wondering if anyone knows of any forums or sites where users share report configs so the wheel doesn't have to be re-invented each time. I am not a DBA and usually have a terrible time trying to get what I am looking for out of the FAZ reports. I am looking to create a report that I am sure someone has created before and for the same reasons I am looking for it. Just curious if anyone knows of any resources. Any help will be greatly appreciated. Thanks in advance, JP
I have an unusual problem. When I went to add a rest api user I noticed that I am missing options for "REST API Admin" and "SSO Admin". I can only create create system administrators. I have a mix of hundreds of 7.2 and 7.4 systems in my network. This is the only device running 7.2.11 so I dont know if it is specifically for that version. And I cannot downgrade without getting an approved maintenance window.I tried using the CLI as well...I cannot type in config system api-user sso-admin... those are missing from the CLI.
Hello support team. I'm really happy I use Your product. It gives me a lot of fun. Anyway, I have some issue. I want to do a report in FortiAnalyzer based on my endpoints. But there's problem - I want to use srcaddrgroup variable. But it looks like it's missing! I have to use it, because my Address Group is changing, so my report needs to be changing. Can You help me with it? My Fortigate firmware is v7.0.17 build0682 (Mature) and FortiAnalyzer: v7.0.10 GA build0561.Thank You in advance;-)
Hi, I have a problem with the bialebrenno.pl website. The website was checked manually + antivirus scan + server support scan and nothing was detected. The website seems clean. Despite this, on the https://www.virustotal.com/gui/url/06980036687b00a37e594ca81a0ae97686ba214eb39a681572ccafa7b811f84e/detection it is listed as unsafe. Please help.
Is anybody else experiencing issues creating or updating installer packages at the moment? It appears to possibly be an issue on Fortinet's side. 2024-12-10T07:25:53.759+0200 ERROR service/installer.go:391 requesting FCT installer repackage: repackage of Windows setup installers failed: POST to https://forticlient-rs.forticloud.com/rs/api/public/v1/repackagedFCTInstaller/. Status code: 503 Edit: This is for v7.4.2 which has appeared in the FEMS console. I see in the support portal that v7.4.2 is actually not available for download. I tried setting up a separate v7.4.1 installer package, with auto-patch disabled, and I get the same error.
Dears, We have configured a real-time scanning policy on our FortiMail system to scan emails delivered to user mailboxes.My question is: What are the recommended or best practice profile settings for this policy to effectively scan and protect the contents of the mailboxes?
In a offline environment, I'd like to upgrade AVEN for my 7.0 FGT VM(licensed) manaully, but when I upload the AVEN file, I get the error message: "Failed to upgrade database". The detail message show in the CLI debug is as follow: ```doInstallUpdatePackage[856]-Pkg has wrong firmware version-04000000upd_install_pkg_file[1210]-Installation of pkg /tmp/monitor_upload_hunXz2 has failedupd_manual_virdb[59]-Failed installing pkg file``` The AVEN file is export from fortimanager and it should be legal, after I check the export AVEN file I found: ```pkg header firmware version: 04000000FMGI obj header firmware version: 01000000OBLT obj header firmware version: 04000000AVEN obj header firmware version: 07000000``` It seems the error is caused by the pkg header firmware version. Any idea? Thanks.
I have problem with my tunnel (remote access). I have tunnel IPsec and autentication from Local user by FortiClient. But I want only one user in same time, I have ip adress range X.X.10.15 - X.X.10-25 and I have 10 users. Now, users can autentication by one user name and password. I must create new remote access for new user or group with one IP adress? I found in the Fortinet, SSL VPN have this option limit-use, IPsec also?
Hey Guys I have recently got a Fortigate 60F, and i would like to use my Unifi AP6 Plus to manage wifi and SSID's, but im a little clueless on how to make that work and how to allow the unifi to manage the connection through the fortinet firewallI dont have a spare device to run a controller 24/7 sitting around, but i did read unifi ap's can be managed by an app, i am just not sure what settings to setup on the fortigate. I am not after a complex setup, i just want the AP to bridge with the firewall and then the AP to do the SSID's and wireless work
Is it possible to Buy a license for a used fortigate bought from Ebay? Thanks
Hi colleages, Is there any way to know if one (or more) of my FortiGate comes down from FortiGate Cloud ?? Event handler? I tried with this and doesn't works: Any idea?? Thanks in advance.
Hello,I have these 2 doubts: 1- If I want to protect a web server NATed to internet , I can do this only with a normal VIP and SSL inspection , right?I mean I do NOT need to enable Load Balance feature like this example:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-Inbound-SSL-Deep-Inspection/ta-p/191543 2- And if I want to protect for example an email server (encrypted traffic) in the SSL inspection profile ,under "Protocol Port Mapping" I have these 2 choices right: - select "Inspect all ports" or - on "HTTPS" add the ports that I want (i.e 25,587,465)With any of these 2 I would be protecting my email server from malware and other attacks (with AV/IPS profiles) right? Thank you in advaceRegards
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.