Mark a Best Answer
Fortinet Community
Recently active
Hi , I have connected to FortiGate Cloud , Show error : fortigate cloud internal error Could you please give me some advice?FG 61E firmware: 6.2.3
I have installed FMG-VM64-HV on hyper-vFMG firmware v 7.2.10. I am able to ping and ssh the FMG but not able to https or http on GUI however I have allowed https http ping ssh on the allowaccess interface setting.
Dear Concern, I want to set a limit on a specific SSL-VPN user so that this user can establish multiple connections at the same time. For example, User A should be able to establish SSL-VPN connections from two different laptops at a time using FortiClient. If I configure it via GUI: VPN > SSL-VPN Portals, edit the SSL-VPN Portal, and enable "Limit Users to One SSL-VPN Connection at a Time", this restriction applies to all users, preventing multiple connections for everyone. However, I want to remove this restriction only for a specific user while keeping it enabled for others.How can I achieve this? Please share the configuration steps. Waiting for your valuable response.
Why when I configure the Network of the FGT device in FMG, the configurations are not synchronized to the device even though I have applied and checked that there are diff changes compared to the previous Revision. For example, if I enable the https service of an FGT device using the FMG interface, I cannot access it, but if I access the device and configure it, I can access it normally.
New FortiGate admin here. We have two internet connections. I'm looking to shape traffic so specific connections prefer WAN2, while everything else prefers WAN1. Criteria would need to include connections to outside servers (both ingress and egress) that could be specified by IP or FQDN, as well as by protocol (eg. SIP). And, when either WAN connection drops, the traffic would need to fail over to the available WAN interface. I'm not finding good documentation on accomplishing this. Any help would be appreciated!
FortiClient version: 7.2.8.0926Linux version: Ubuntu 22.04.5 I have two VPNs defined, 1 added manually and the other added by EMS.The one added manually connected fine before adding EMS. After adding EMS, connecting to either VPN crashes FortiClient right after connecting. I tried to connect through CLI, but I am not sure if this is possible with SAML authorization. I tried to look for something in the logs, and this is what I found right around the crash, in sslvpn.log:20250402 01:33:11.112 TZ=+0200 [sslvpn:DEBG] route:614 Add the route for 91.226.249.10(192.168.0.1)20250402 01:33:11.112 TZ=+0200 [sslvpn:DEBG] route:374 Set up split tunnel routes20250402 01:33:11.112 TZ=+0200 [sslvpn:INFO] nettools:484 Received error: File exists [-17]. Stop reading socket20250402 01:33:11.112 TZ=+0200 [sslvpn:INFO] nettools:375 Failed to receive netlink message20250402 01:33:11.112 TZ=+0200 [sslvpn:EROR] route:417 Failed to add route. Route details: destination 185.166.1
When we use BGP, it's mandatory to set the interface in BGP neighbor and make static route to the BGP neighbor peer ip?
In sdwan enviroment with one hub and multiple spokes, in which side the sdwan sla should be configure? In the hub or in every spoke?
Hello, everyone.We've different sites with Fortigate 100F in HA. The different sites are connected via VPN, so they are visible to each other.We're testing the evaluation version of Fortimanager to evaluate its functionalities.Specifically, we would like to know if it is possible that, with a specific vDOM existing on both remote sites, Fortimanager is capable of replicating any new policy bidirectionally. In this way, the rules of that vDOM would be the same regardless of the site.What we're looking for with this is that in the event of a catastrophe on one of the sites, it is easy to redirect traffic to the other site, with all the rules and policies that were needed on the downed site already existing.We aren't clear if Fortimanager is capable of carrying out this requirement and if not, how could we carry it out? Through API?Thanks in advance for the suggestions. All the best
Exciting updates available on the FortiSOAR Content Hub!! The Fortinet FortiManager ZTP Flow integration brings FortiManager's central management solution to Fortinet's security appliances such as firewalls and VPNs, seamlessly incorporating the Zero-Touch Provisioning (ZTP) flow. This allows for automated device configuration and deployment, reducing the need for manual intervention and enabling quick, plug-and-play setup. Additionally, the Outbreak Response - Apache Tomcat RCE solution pack works in tandem with the Threat Hunt rules in the Outbreak Response Framework to identify and investigate potential Indicators of Compromise (IOCs) associated with the Apache Tomcat remote code execution vulnerability, CVE-2025-24813. This vulnerability is actively targeted by attackers, and the solution aids in detecting and mitigating threats within operational environments such as FortiSIEM and FortiAnalyzer. Our Cisco ISE integration with FortiSOAR™ enhances network policy
Hi, Right now using on login for our standalone FortiSwitches and wanted to setup LDAP for authentication. FortiSwitch_148F-FPOE, V7.2.9. Can't see an article on this but saw on that say it is not supported, however, that was 2023. Thanks
We are aware of the kernel panic mode issue on 7.2.8 and intentionally avoided it. However, in the past month, we've suddenly been hit with many systems experiencing the "unexpected power off" issue. We use Fortimanager and can confirm no recent changes to anything. We even have half the devices using a separate config where half of the systems use SDWAN and the other half doesn't https://100001.onl/ .Seems to have started in early March.Reaching out to see if others are experiencing anything similar. TAC case opened and under investigation.Thanks.
Hi, is it possible to monitor per ip address created. for example under interface port 1 there are hundred Nat translation. 10.0.0.1 to 10.0.0.100. Can FortiGate tag SNMP to each ip address for network monitoring to create bandwidth graph. Also per vlan?
Hi everyone, I am unsuccessfully trying to implement Web Filter Category quota on my 40F. 2 problems: despite time limit set under a monitored category, (1) client device has access to websites falling within that category beyond such time limit. And (2) in the Fortiguard Quota Monitor dashboard, FortiGate displays “No matching entries found” for this client IP. Current setup:License activated;Explicit Proxy features activated;Fortiguard filtering services on port: 8888; no report received after launching connectivity test;Network > Interface: Explicit Proxy (HTTP 8080, no PAC file) on that Vlan (10 clients, 5 laptops, 5 mobiles);Policy & Objects > Firewall Policy in proxy-based for this Vlan to ISP;Policy & Objects > Proxy Policy proxy-based with Web Filtering profile on that Vlan address range;Security Profiles > Web Filter profile on proxy-mode; andClient proxy manually set up with Vlan IP Interface and Explicit Proxy port.What I can see:Clien
Hi there, I am in charge of introducing FortiPAM in our Windows domain environment to manage log and secure the access to our servers.Testing things out I have created some users, groups, targets and secrets (mostly on the same target). Clearing out some of my tests I ran into a problem: Secret Z with ID=1 gave the answer "Failed to delete some of the secrets or folders" (I can click the delete button). I tried to delete everything that could be related to it. The situation now is following: In my personal Folder and in the secrets folder I can see the entry for the secret Z. I have owner permissions on it. In Targets there is only the asociated Target also called Z. The delete button for this is grey and can not be clicked (obviousliy because there is an dependent objekt). I thought I could solve my problem with deleting the secret entry in the "secret database" via cli-command but the answer is this:"SRV-FPA # config secret databaseSRV-FPA (database) # get==
Hi. I'm having this strange issue with a customer.I'm new to FortiGate so would appreciate any ideas on how to troubleshoot this. The customer when connected to the main office remotely (SSL VPN) or from another branch office (S2S VPN) cannot login to their Syspro application.Basically the application just hangs. When at the office there is no issue as Syspro server resides on the same LAN as the users, so this traffic is not been inspected by the FortiGate. For troubleshooting the SSL VPN rule allows everything and there are no security profiles enabled nor SSL Inspection.There is no latency or Interface errors. What I do see all the time is that the Syspro server (10.0.0.4) sends a rst before there is an ack from the client to complete the 3-way TCP Handshake as shown below.Then there is some communication, connection is terminated and we see a new connection. The server is listening on the port (30110) and there is no local firew
Hello, Does anyone have access to a copy of the Meru MC1500 controller firmware?A certain NPO still uses this controller to manage the WIFI network. I assume that the Compact Flash memory has been damaged and the controller does not start. Repairing the controller and getting the system up is very important.I will be very grateful for any help.ThanksKrystian
New FortiGate admin here. I'm looking to enable web-admin on the WAN ports, but only allow access from specific IP addresses. I've created the address objects, but am not seeing how to configure a firewall policy. There would (obviously) be no outgoing interface.I can see a couple of suggestions coming, so to avoid those...I'd rather not have to use a VPN just for remote admin access.Also, configuring "trusted hosts" for specific users still exposes the admin ports to the entire internet, which is an all-around bad idea.So, a firewall policy should be the way to go...Any help would be appreciated!
Hi, I've got a site that's being blocked by the student policy(yearbookavenue.jostens.com 192.189.112.187). It's a big single page webapp type site that makes a lot of xml http requests. Students can visitthe site just fine, but when students go to save their progress on thesite it makes a POST request to yearbookavenue.jostens.com/savestuff orwhatever and this will work fine on my machine when I'm hitting theStaff policy, but produces an error when on a student account on a chromebook. Looking in the firewall logs I can see that the ip address192.189.112.197 is allowed when the "Application Name" is HTTPS.BROWSER but blocked when it's SSL. I'veallowed the site in web filter but it seems like it's still beingblocked at the application level somehow, like the SPA is producing adifferent application signature. To make things trickier sometimes traffic to that site produces HTTPS.BROWSER when student access it, allowing them to save, but other times it produces SSL traffic and i
Hello,I have two FortiGate 60F 7.4.7 devices configured for redundancy in case of failure. The setup includes two physical WAN interfaces: ISP-1 (wan1) and ISP-2 (wan2). There is also a virtual LACP-1 interface that combines internal1 and internal2. Several VLANs are configured on LACP-1.I need to configure an IPSec VPN with Split Tunneling, where all internet traffic should go through the client's local internet, while traffic destined for the VLANs should be routed through the tunnel.The VPN tunnel establishes successfully, and the client can connect. However, the client cannot access any network resources inside the VLANs or ping anything.VPN Tunnel Configuration:VPN Tunnel Configuration: config vpn ipsec phase1-interface edit "Delta_VPN_IPSec" set type dynamic set interface "wan1" set mode aggressive set peertype any set net-device disable set mode-cfg enable set proposal aes128-sha256 aes256-sha256 aes128-sha
We just started using Fortimanager recently. I've noticed the few virtual servers we have set up do not show the correct settings on Fortimanager. For example, on the actual fortigate, the port is 443 but on Fortimangaer it shows port 80. Is there a way to get these to sync up?
Hey everyone Thanks in advance for any help you can provide. I recently upgraded my company's FortiAnalyzer (FAZ) to 7.6.2, and a custom VPN connection/disconnection report used by my manager has broken. While the report is custom, it was originally based on a Fortinet employee’s article. After logging a support case, I was informed that because this is a custom report, I need to resolve the issue myself. What I’ve Found So FarI found a Reddit post where another user experienced similar issues after the FAZ backend switched from PostgreSQL to ClickHouse.I followed the Fortinet ClickHouse migration documentation and updated my SQL query accordingly.The data appears correctly when previewing the dataset, and it also shows up in chart previews.However, when I generate the report, it comes out blank with the message::police_car_light:"No matching log data for this report"My Current SQL Query SELECT`user` AS "User",(CASEWHEN `action` = 'tunnel-up' THEN 'Co
We are currently running 7.2.x with 160GB disk and have had this disk size for some time without any issues. Is 500GB really required for 7.4.6 or is this just a blanket suggestion? We are utilizing AWS so if it is not required or will cause any issues we aren't going to add any space due to increased cost.
Author: @kcheung DNS: Overview & Threats DNS (Domain Name System) is integral to enterprise IT infrastructure, providing services for name resolution. Without DNS, an IT infrastructure is unable to look up a domain’s IP address. Since DNS is available in many IT infrastructures, its role makes it a target for malicious activity. Enterprises must adopt layered defenses and monitor DNS activity to mitigate threats effectively. DNS C2 commands can appear like normal DNS requests and thus make DNS based threats difficult to detect. Enterprise with firewalls that typically allow DNS traffic (port 53), hence use of a multi layered detection and response systems (Ex: EDR, NDR) is crucial in identifying threats. FortiNDR Cloud offers multiple levels of network-based DNS threats detections and response. This blog will go deeper into how you can leverage them to understand, respond and mitigate any such threats and secure your organization’s network. DN
Hello and sorry for my english,I have basic inspection configuration, like this : but i have a lot of SSL anomaly in security events, more than 22,000 and sites are blocked; for example : to website mask.apple-dns.netEvent Type : ssl-anomalyEvent Subtype : certificate-probe-failed what can i do ? thanks a lot
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.