Mark a Best Answer
Fortinet Community
Recently active
Hello, Does the Free FortiClient supports IPSec or only SSL VPN? Is the Free FortiClient going away? Thank you.
I have a computer that was sent an invite from the EMS system that was able to go through the set-up process and appears in my system. Today, when the user tried to connect to a VPN they see "Unlicensed VPN access is available until *insert a date here*" (they can still connect to whatever VPN they were attempting). When I access EMS, the device is showing Not Managed by EMS and Not Registered. Please advise on how to handle this. Extra Info:- I have several open spots in my licensing.- According to the Log Viewer, the device was unregistered this morning.
The VPN connection will be broken if the computer connected by FortiClient with the following settings does not send or receive packets passing through the VPN for 259200 seconds (3 days).---config vpn ssl setting set idle-timeout 0 set auth-timeout 0 <omit>end--- Monitoring in “Dashboard>Users & Devices>Firewall Users>” shows that when there is no communication, the remaining time gradually decreases, and when communication starts, the remaining time resets to 3 days. It seems like a disconnection due to idle-timeout, but the VPN event disconnect reaseon is an auth-timeout. Is it possible to keep the VPN connection for more than 259200 seconds (3 days) even if no packets are sent or received?
Hi,I am trying to connect to sftp via:execute backup config sftp /mnt/Data1/nas/Fortigate_Backup/%%date%%-backup.conf 10.10.10.10 domain\user <password> encryption-<encryption> On a FGT80 with v.7.2.11The error is: Connect to sftp server 10.10.10.10 ...Send config file to sftp server via vdom root failed.Command fail. Return code -1. I can successfully login to sftp from other clients. Any thoughts? thanks in advance John
Hi, I´m a little bit confused about the fact, that with FortiOS 7.6, there is now support for UDP, which is then bypassed by an URL on nginx.org. Is the state of the art of a secure application / appliance? Sophos and Cisco already seems to have full support for UDP ZTNA. What are the plans from Fortinet?Solving this issue with kind of BETA implementation on a third party outside proxy, is not a practiable solution.BestRonny
Greetings everyone, I am opening this case because I have set up a virtual lab with a FortiManager that manages three FortiGates, ALL with TRIAL licenses. The entire lab is virtual, using the following versions:FMG_VM64_KVM-v7.6.1.M-build3344-FORTINET.out.kvmFGT_VM64_KVM-v7.6.2.F-build3462-FORTINET.out.kvmThe FortiGates are registered using the following command in FortiManager: config sys global set fgfm-peercert-withoutsn enableend The IssueAfter registering the devices, the problem arises when pushing configurations or policies to the FortiGate, as it always results in an error. As shown in the images below: Install OK / Verify FAILWhen expanding the error message from the FortiManager UI: Checking the Install Log reveals that the issue occurs because FortiManager attempts to modify (delete) the WebFilter profile "monitor-all", as shown in the following image: CLI Test on FortiGateThe issue is that FortiGa
Hello i feel so confuse about FortiADC Full NAT vs Direct routing vs DNAT when i do Virtual server configurations i worked alot with F5 but i realy like FortiADC but i wish if i have simple explainationcould you please tell meif i want to activate SNAT in F5 = Full NAT with source NAT pool right?but my important question i want to disable SNAT in FortiADC = Do i need to use DNAT or direct routing Regards Adam
Hi all,Users connecting via VPN must be validated via SSO (the IdP is Azure). The problem arises if the user chooses to authenticate via LDAP; the queries reach the server, allowing an attacker to cause a DoS.Force this option in fclient is not an option cause anyone from outside our organization could do it.Has anyone encountered this problem?Thnks in advance!
Hi, We are a school using FortiGate on v7.4.7. We have recently updated our Office package from 2016 to O365, which needs the users to have a licence to be able to access the Office apps. With exam season coming up, we need to set up a web filter to allow users to authenticate against O365, but not access anything else on the web. Has anyone successfully done this? Our web groups are based on a security group from on-prem AD. We do block Edge, Chrome and IE via GPO, but the exam board are quite strict about restrictions schools have. Thanks, Cameron
Hi, I can only access Remote Access from the master account, none of my IAM users can access despite having SysAdmin permission profile.It shows as blank.Tried clearing the browser cache and try accessing Remote Access again.Attempted access from a different browser or an incognito/private window.Issue persists across multiple IAM users. Your help/advise is highly appreciated. TIA :)
Hello everyone! I'm having some problems to redistribute bgp routes learned from another part of the network. The routes learned Hub to hub works fine on the hubs, however in the spokes, the routes learned from the other part are pointing to WAN interfaces, not the overlays. I've created the topology inside GNS3 to test pre-production:I'm using the same AS with iBGP and next-hop-self-rr on the hub to hub overlay neighbor configuration. Hub routing table: Spoke routing table: Any ideas?
I am having an issue with FortiGate Cloud Tunnel Status inactive. I tried upgrading to FortiGate Cloud Premium but it stuck on this page for over 10 minutes and asked me to try again later. I have checked my product and it is not in the decommissioned group
hi Gents, just a quick question- can you configure a priority for routes learned from BGP like you do for static routes?bgp config - i have changed the admin distance to match that on static routesgbp route map - I have set the metric same as the one on static routeswhat i want to achieve is have a static default route and a default route learnt from BGP peers in the routing-table, I have seen the route in the database
Hello team!! We have 2 Fortigates 100F in HA, working fine In these Fortigates, we have 2 IPsec site to site VPNs working fine We need to create VPNs for FortiClient, to some users to have connectivity to office from diferent external sites. I will try to explain what happen from the beginning * I had created a VPN for some external users when Fortigates were in 7.4.4 * This VPN worked fine * Fortigate was updated from 7.4.4 to 7.6.2 * Then we did not need anymore this VPN, and insted we needed to create a VPN for all internal users * Instead of rename VPN, I decided to delete the VPN and create a new VPN * The first time I had created the VPN in 7.6.2, I think I didnt get any error, but VPN did not work * I tried to troubleshoot but did not make it work * I deleted the new VPN again * I tried to create this again, then in the last step, I got "Failed to save changes" But we have received this error:date=2025-03-31 time=11:09:13 devid="FG100FTK22025224" devname="fw-ha01b" ev
Hi, I'm trying to run FortiClient 7.4.3 in a Docker container based on Ubuntu 24.04 All goes well with the installation, all dependencies are resolved, but when I try to runforticlient vpn edit vpn_nameI receive the error:Failed to get response from confighandler Here is my Dockerfile:FROM ubuntu:24.04 RUN apt-get update -y && apt-get upgrade -y && apt-get install -y sudo libayatana-appindicator3-1 libnspr4 libnss3 libx11-xcb1 libxss1 libsecret-1-0 libnss3-tools iptables COPY forticlient_vpn_7.4.3.1736_amd64.deb . RUN dpkg -i forticlient_vpn_7.4.3.1736_amd64.deb && apt install -f CMD /bin/bash When I run confighandler:/opt/forticlient/confighandler It doesn't get any error, but also doesn't respond with anything. Anyone can help, please.
Hello I have an EMS Cloud deployment with assets deployed with Forticlient.Under the Vulnerability profile, there is an option for "Automatic Patching" which is currently enabled for Criticals. Can someone help me understand the following:- Confirming this only applies to applications that support automatic patching (i.e. Chrome, Firefox, etc)- When does auto patching take place? Is it after a vulnerability scan or a specific interval? I'd like to understand this behavior better. Thank you
We've got some development that's going on in Azure which makes a call to our internal servers. I've got the "source" inbound rule pointing to a VIP and restricted to traffic coming from *.azure-api.net*.microsoft.com*.slope.ioThe problem is with something like apimanagement-cors-proxy-prd.azure-api.net depending on what IP that resolves to, the firewall may or may not allow traffic coming from that URL. As I understand it from FortiNet support, this is "expected" behavior. IE if the firewall has resolved apimanagement-cors-proxy-prd.azure-api.net to be 13.91.254.72 and the traffic is coming from 13.91.254.72, then the traffic will be allowed in. However if traffic coming from apimanagement-cors-proxy-prd.azure-api.net is coming from 20.121.82.216 and the firewall hasn't resolved 20.121.82.216 as a valid IP for apimanagement-cors-proxy-prd.azure-api.net then the traffic won't be allowed in. The only other option would be to allow Azure
Hello,We are trying to adjust the threshold for the Fortigate DOS IPv4 L4 anomalies rule because it triggers too many incidents on our FortiSIEM.The issue is that it is hard to know how far the threshold (5000 pps in our case) is overtaken.The raw log, as sent by the FW to the FortiSIEM is the following: <185>logver=702101706 timestamp=1741353017 devname="*redacted*" devid="*redacted*" vd="root" date=2025-03-07 time=13:10:17 eventtime=1741371017400546868 tz="-0500" logid="0720018432" type="utm" subtype="anomaly" eventtype="anomaly" level="alert" severity="critical" srcip=*redacted* srccountry="Reserved" dstip=*redacted* dstcountry="Reserved" srcintf="VLAN35" srcintfrole="lan" sessionid=0 action="detected" proto=17 service="udp-53" count=13 attack="udp_dst_session" srcport=57032 dstport=53 attackid=285212775 policyid=3 policytype="DoS-policy" ref="http://www.fortinet.com/ids/VID285212775" msg="anomaly: udp_dst_session, 5001 > threshold 5000, repeats 13 times" crscore=50 cr
I have problem with Meru MC1550. Device does not respond to ping... I can connect via console cable, but I get errors... What can I do? [ 2.119455] usbhid: v2.6:USB HID core driver[ 2.123843] Netfilter messages via NETLINK v0.30.[ 2.128635] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)[ 2.134982] ctnetlink v0.93: registering with nfnetlink.[ 2.140463] TCP bic registered[ 2.143591] Initializing XFRM netlink socket[ 2.147938] NET: Registered protocol family 17[ 2.152471] Using IPI Shortcut mode[ 2.761588] ata1.00: SATA link down (SStatus 0 SControl 310)[ 2.767338] ata1.01: SATA link down (SStatus 0 SControl 310)[ 3.478989] ata2.01: failed to resume link (SControl 0)[ 3.494968] ata2.00: SATA link down (SStatus 0 SControl 310)[ 3.500716] ata2.01: SATA link down (SStatus 0 SControl 0)[ 3.506317] md: Waiting for all devices to be available before autodetect[ 3.513185] md: If you don't use raid, use raid=noautodetect[ 3.519192] md: Autodetecting RAID arr
hi,i have a remote FW that i need to change to a new WAN public IP.it currently has a ipsec VPN established using the old public/peer IP.my question, can i change/update the remote IP address on the fly?i checked it currently has a reference to the ipsec phase 2 tunnel config.
Hello Community, we have several employees experiencing severe performance issues with the Forti EMS Client 7.2.8, particularly when accessing internal websites via VPN and using applications like SAP GUI. In some cases, connections even drop unexpectedly.Even after reinstalling the client, the problem persists. However, when switching to the free Forti VPN Client, the issues disappear immediately, and everything runs smoothly. Our environment:- In-house EMS Server 7.2.8 with FortiClient 7.2.8--FortiGate connected via IPv4 only (IPv6 is disabled on WLAN and VPN adapters)- Only SSL VPN is used; all other VPN options are disabledDoes anyone have an idea? Many thanks in advance!
How can we do the radius configuration in Fortiswitch if Fortiswitch manged through Fortilink in Fortigate.Please guide.
Requesting Forticare Trial License. proxy:(Null) Failed to download VM License. I am getting this error while requesting a trial license. Unable to resolve it.
I did a simple exercise where I connected the two PCs to the physical FortiGate (to port1 and port2). Then I created a rule where I set the incoming traffic to port1 and outgoing traffic to port2 (with all other parameters set to 'all'). I also created another rule to permit the reverse traffic. However, all traffic is being denied due to the implicit deny rule. Does anyone have a suggestion regarding this configuration? I can ping the FortiGate from the PCs. The FortiGate is not registered yet (I did the same configuration in VMware Workstation with the FortiGate running on a VM, and it worked).
Hello, FortiGate-100E # diag sys ntp statussynchronized: no, ntpsync: enabled, server-mode: enabledipv4 server(192.168.0.61) 192.168.0.61 -- unreachable(0x0) S:7 T:684no data I have the following issue: I have activated NTP on a FortiGate 100E. Unfortunately, I do not have a WAN interface configured on the interfaces, and I cannot assign an external IP address directly to the device. I want to extend the NTP address to the firewall through a tunnel, so the access is open. The access is open, and I can ping it from different interfaces that I have configured under "listen on interfaces."However, it still cannot synchronize and has a 2-minute delay. What could be the cause of this issue? What should I check first, and if possible, could you provide a solution? #FortiGate #NTP #System_Settings
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.