Mark a Best Answer
Fortinet Community
Recently active
If the endpoint was idle for some time then when i change the group on the NAC, I can see the fortinac not send the CoA to the switch.We can see here the last fnac send the CoA is 14:02:18 then i change the group for that host at 14:30 and there is no CoA bsend to the switch
Hi everyone,On my FortiGate running v7.4.9, I have a specific VDOM configured for one of my clients.Currently, this VDOM is integrated with a FortiAuthenticator (FAC), which in turn queries two remote LDAP servers to handle MFA for client VPNs. I now need to configure these same two remote LDAP servers directly on the FortiGate (under User & Authentication -> LDAP Servers) so I can use Active Directory groups in our firewall policies. I would like to know if there are any specific best practices to follow, and I have a couple of questions: LDAP Query Load: Are these two remote LDAP servers at risk of being overloaded with too many queries due to this dual integration (FAC for VPN + FortiGate direct for security policies) ? Cache Management: Would you recommend enabling and tuning the cache on the FortiGate (increasing `set cache-ttl` to 300 or higher) ?If so, what is your recommended value for a production environment ? Thanks in advance to everyone for any advice or insights !
Hello dear community, I got a new customer that has an unlicensed FortiGate 50E and FortiAPs 221E on firmware 6.0.x. They want to replace the FortiGate with the 50G model but want to keep the APs for now. The target FortiOS for 50G would be 7.4.12. As the config would be converted/migrated, what would be the best upgrade path to avoid losing the APs management?Put the 50G on 7.4.12 and convert the 50E configuration as is Upgrade the 50E and 221E APs to latest possible 6.2 branch and then convert the 50E configuration for 7.4.12 Upgrade the 50E and 221E APs to latest possible 6.2 branch, convert the 50E configuration for 7.0.19, then upgrade the 50G to 7.4.12 Please let me know if more details are needed. Best Regards
I cannot install Foticlient VPN on my new windows PC.Installation fails premature pc configuration Microsoft Windows [Versión 10.0.26200.8737](c) Microsoft Corporation. Todos los derechos reservados. C:\Windows\System32>systeminfo | findstr /B /C:"Tipo de sistema"Tipo de sistema: ARM64-based PC C:\Windows\System32>echo %PROCESSOR_ARCHITECTURE%ARM64 C:\Windows\System32>wmic csproduct get name"wmic" no se reconoce como un comando interno o externo,programa o archivo por lotes ejecutable. C:\Windows\System32>powershell "(Get-CimInstance Win32_ComputerSystem).Model"HP ProBook 4 G1q 14 inch Notebook Next Gen AI PC Can you help us?thanks
Replacing a FortiGate 3700D with a FortiGate 900G?Management has proposed replacing the current 3700D model edge firewall with a 900G unit. The 3700D is capable of handling a throughput of approximately 17 Gbps.
Modern Cloud Threats Need More ContextModern cloud environments generate a constant stream of activity: users sign in, services call other services, automation creates and updates resources, and workloads shift across accounts and regions. Hidden inside that routine activity are the early signs of credential compromise, privilege escalation, reconnaissance, and resource manipulation. Traditional detectors often evaluate events one at a time. That can work well for known bad indicators, but it struggles when the risk comes from a sequence of ordinary-looking actions. For example, a console login, a few ListRoles or DescribeInstances calls, a CreateAccessKey event, and a later policy or security group change may each look explainable in isolation. A single API call is usually not enough to tell the story and can get lost in the noise. When combined together, however, these events form a suspicious activity pattern. The relationship between the identity, the resource, the action, the sour
Hi, We have FortiPAM. We have our users who use SqlServer Mgmt Studio for connecting to database and they using windows integrated authentication. External users have also account and they connect the same while they are logged on some domain PCs. But sometimes external users need to connect from their own laptops which doesnt belong to domains. We created secret with sql template and ssms launcher and when they launch we see that SSMS is not run with user who can log choosing option windows integrated authentication and also login is failed because natively it using sql server authentication.Is there anyway to say fortipam agent when launch secret to run as different user ssms (using defined credential in secreet)? I see that is option With FortiPam 1.9 and FortiClient 8.0. I have PAM with 1.9 version but i dont see 8.0 version of PAM agent? Can someone help or give some idea how to enable users to connect to db?
How i renew or get a new FortiGate trial license in VmWorkstation that i launched before with my Forticare account and now expired ??
Hello community, I have an IPsec VPN with IKEv2 connected to FortiClient 7.4.5, which connects perfectly when I log in with a local user created in Forti. The problem is when I log in with a domain user; it doesn't connect and I get the following error: "IKE message other than DPD retransmit to maximum". Could you lend me a hand? Thanks
It would be very nice, if Fortinet will add some bulk funktions to change configuration in menues like static routes. Sometimes we have to change things in many routes like interface or distance or priority. It would be nice if this button becomes available, when i mark 2 or more static routes.Maybe this also would be nice in some other menues.
Hi, I'm using FortiClient VPN for conneticting to a customer's VPN but I can't receive any bytes: Same username and password on other PC work and every username and password on my PC don't work.I tried disabling/closing: firewall, antivirus, teams, onedrive, ...I have the default settings of Windows 11 and I'm using FortiClient 7.0.7.0345.VPN configuration is correct. Could someone help me please? Thanks in advanceFrancescoMAS Consulting
Hi..My FGT Hub and Spoke run under verrsion 7.2.11, the hub act as SSL VPN and connection from spoke to hub using ADVPN.As we know in new version of Fortigate then SSL VPN is retired and replaced by IPSEC VPN. Witht his condition i want to know :What latest version where SSL VPN still supported? If hub and spoke have different OS version, this is compatible?
Hello All Kindly i need admin guide for deploying SPA FortiSASE with 2 FortiGate devices HA active - passive So please advice with the steps and guide Thanks
so, i have existing ICX8200’s in this infrastructure and older ICX6450’s. we’re replacing the 6450’s with 124F-FPOE switches, but i’m having trouble getting the 124’s to talk to the 8200’s. the 124’s are running 8.0.0(47). the 124’s will uplink to the 6450’s with no trouble, but will not pass traffic to/from the 8200’s. the link and activity lights come on, and in the gui the link and speed/duplex are correct, but both switches claim they are sending but not receiving. neither have errors in the log. so,fn124 → icx6450 → icx8200 works finefn124 → icx8200 link but no stp/lldp/trafficno cdp/fdp/lldp neighbors listed on that port when the 8200 is plugged into the fortinet. on either switch. when the 6450 is plugged in the middle everybody sees the directly connected neighbors. i’ve tried this with 2 separate icx8200’s and 2 separate fn124f-fpoe’s. i’ve pulled one set and experienced the same behavior on my bench using fiber patch cables. the ports on both ends are set to native
Hi FGT adminsFortiOS 7.4.12. All HTTPS sited are blocked with error: “SSL connection is blocked due to unable to retrieve server's certificate”.In the latest FOS updates the FGT probes the certificate itself (self generated traffic) before allowing or denying the traffic, right.I checked this tech tip and I know we can change cert-probe-failure as workaround.But I my case I know the issue is caused by my WAN interface having one primary private IP and one public IP as secondary IP (ISP constraint). I had to change source-ip for many services like DNS and FortiGuard in order to make them reachable. But can’t find similar source-ip for certificate probe traffic.I know one other workaround is to make public IP primary and private IP secondary but I prefer avoid this change in case there is “source-ip” customization for cert probe.Any useful info would be appreciated.
Hello,I've been working on setting up an IPsec VPN on our FG200E after upgrading to FortiOS 7.6.7, mainly so we can take advantage of DNS suffix assignment from the firewall.Our environment has two separate Active Directory domains in a trust relationship: old-domain and new-domain. In the config vpn ipsec phase1-interface configuration, I've defined DNS suffixes for both domains and configured the DNS servers with the old-domain DNS first and the new-domain DNS second.Everything seems to be working correctly for resources in new-domain, but for anything in old-domain, I have to use the full FQDN to access it. This creates a major issue because some of our internal applications reference hosts by short name rather than a fully qualified DNS name.We're currently using Cisco AnyConnect, and it works perfectly—users can access shares and applications using just the host name without any DNS resolution issues.I've already opened a ticket with Fortinet, but I wanted to check if anyone else
Hello, we have several Fortgates, swites and AP. But one of my former collegues. has not written down which Contract Registration Code was used for which device. Is there a way to check which Contract Registration Code was used on a device. w.k.r.Patrick
Hi allI have updated to FortiOS 7.2.3.And then I realized following bad configuration.----FG60F # config system email-serverFG60F (email-server) ## set reply-to noreply@example.comcommand parse error before 'reply-to'Command fail. Return code -61FG60F (email-server) #----By this Document, I can set 'reply-to'.http://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/526019/email-alertssomeone have how to config 'reply-to' in FortiOS 7.2.3?thanks.
Fortigate can block the Tailscale application with policy and application control; it will block both inbound Tailscale sessions and outbound Tailscale sessions. Is it possible to block only inbound Tailscale sessions, and still allow outbound Tailscale sessions on the firewall?
Hello there,I want to update FortiClient EMS signature manually. FortiClient EMS 7.4.7. My deployment mode is airgap. I have downloaded the service updates from support.fortinet.com.Now how I can insert it to EMS server.Kindly help me on this.
This week's updates deliver a broad refresh across FortiSOAR™, spanning Fortinet Fabric integrations, threat response content, and a large set of connector enhancements that strengthen automation across the security operations lifecycle.Several Fortinet Fabric connectors receive updates this week, including Fortinet FortiAI, Fortinet FortiAnalyzer, Fortinet FortiSIEM, and the FortiGuard family (IOC, Outbreak, and Threat Intelligence), deepening orchestration across Fortinet's threat intelligence and analytics services. Core FortiSOAR™ connectors such as AI Assistant Utils, Code Snippet, Utilities, and the FSR Agent Communication Bridge are also updated, improving the building blocks that power custom automation and distributed deployments.The integrations ecosystem expands with two new integrations, ANY.RUN Threat Intelligence Feeds and ANY.RUN Threat Intelligence Lookup, alongside an upgraded ANY.RUN Cloud Sandbox connector. Enhancements to more than a dozen widely used integrations,
Since last week we experiencing a lot of problems with Windows updates (mostly Windows 11, but there was one Windows 10 among them as well), specifically KB5040442. On about 10% of our Windows clients the update would start and go until 96% and stay there for 10-60 minutes, and then after a restart Windows would tell us that something did go wrong and it would reverse the update. This would require multiple restarts and anything in the order of 2-10h. The usual information sources did not reveal anything unusual with this update round, so it had to be some uncommon conditions here. When Windows was back online, it would sometimes (!) show an error code 0x800f0922, oftenly nothing, and on next restart it would try to install it again (and our employees losing again 4-10h with a working computer). First remedy, as described in the error code was to increase the size of the recovery partition to at least 250MB, but that helped only on one computer. No other things related to the code
Hello community, We are currently running Forti EMS Cloud 7.4.3 with several endpoint versions, mainly FortiClient 7.2.11 y 7.0.X on Windows 11 devices.We are working together with the customer and Microsoft support to troubleshoot an issue where Windows Update downloads do not complete and the update process becomes extremely slow or stuck. Issue Description:When endpoints have a FortiClient profile with Sandbox enabled, Windows Update shows the following symptoms:Update download does not completeIf we change the endpoint policy to Default profile (no Sandbox), the Windows Update process completes successfully. Tests Performed To verify this behavior, we performed the following tests: Disabled Sandbox profile → Windows Update completes normallyRe-enabled Sandbox profile → Windows Update fails or hangsWe tested with multiple Windows Update components excluded:TrustedInstaller.exeTiWorker.exe (Windows Modules Installer Worker)DISM.exeC:\Windows\WinSxS\C:\Windows
I have integrated Darktrace Syslog with FortiAnalyzer. When Darktrace sends logs in JSON format, the log messages are truncated in FortiAnalyzer. However, when I configure Darktrace to send logs in CEF format, the Message field in FortiAnalyzer is empty.Could you please advise on the cause of this behavior and recommend the appropriate configuration to ensure the complete log message is displayed in FortiAnalyzer?
Hi,I recently implemented FPAM and I have a strange behavior with all the web launching sessions.The FPAM is in a subnet dedicated.My pc is on another subnet and the internal services and external(obviously) are on other subnets.In the middle there’s a Fortigate.I have also an ACL for deny the traffic to the internal services from my pc, so I must traverse the FPAM to reach the services.I launch multiple web launching sessions to multiple sites internal and external and after so much time, I can’t define how much, I receive some ERR_CONNECTION_TIMED_OUT from random sites.If I try to reopen the site, I can no longer access it; I have to wait a long time before it starts working again.From what I've gathered so far, connections are more stable if I use the site's IP address directly instead of the FQDN, but sometimes are slowly(But at least they don't time out.)When I have the reset, the FPAM is capable of ping and resolve the destination internal or external site, seems to be a problem
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.