Mark a Best Answer
Fortinet Community
Recently active
Hi Community, We are using FG + FAC300 to establish sslvpn tunnel, with FotitokensMobile and FTM push. For some reason, somme phones are not able to handle FTM push properly (approx 3/100 users). We would like to disable FTM push for these users. On the FAC, i created a group "nopush", type remote-LDAP / importe-remote-LDAP users.This group is set with a radius attribute "fortinet - group - name" - static - string "nopush". On the Radius service, i created a supplemental policy, with highest priority, and RADIUS attribute criteria matching the previous fortinet group.This policy has an advanced option in Authentication factos, to not 'allow FTM push'. But every test i do, with an apporpriate user, i giving me a FTM push. What am i missing ? Ragards,
Dear All, I have come here to know whether it is known issue or not. My SSL vpn connection is getting established but when I try to connect RDP access at that time RDP connection gets freezed with forticlient. I have also seen that when SSL VPN gets connected at that time ping response was getting but after few seconds ping response not getting also RDP connection gets disconnected. Windows latest patch - KB5050578, KB5053602
I created a nice IPsec profile in my FortiClient so I could test out IPsec. When I look at the dialup IPsec config in FortiEMS Cloud very little matches up with whats in the client. Perfect example I cannot find the "Enable Single Sign On (SSO) for VPN Tunnel" option in EMS Cloud to save my life. I am sure its there but its where I am expecting it. Also the IKE: Version 2 setting under VPN Settings -> IKE Options is not there in the EMS Cloud. So to make sure I am configuring EMS the same way I have configured the client. Is it possible to export (backup) the config in the Client and import it in to EMS? If it is possible do I need to do a lot of hacking to clean up the "backup" config so EMS will be happy?
We are planning to put two Fortigate in line in HA active passive and transparent mode behind existing Cisco firewalls to inspect traffic.I was wondering if there are features not supported under this configuration?Can the incoming ports on fortigates be directly connected to firewall ports without going to a switch first? Firewalls are in HA as well. If it fails over, how will the Fortigates know to fail over to the other unit?If we turn on deep inspection, what kind of certificates are required and where should they be installed? Is it internal sub-root CA? For incoming traffic? For Outgoing traffic?
Hi Fortinet Community,I’m currently experiencing recurring issues with Microsoft Teams on my MacBook Pro (Apple M3 Max, 32 GB RAM) running macOS Sequoia 15.3.2.When joining Teams meetings that involve video streaming, I regularly encounter interruptions or complete application crashes. This significantly affects my ability to participate in video calls.My system is running both FortiEDR and FortiClient EMS (VPN connection active or inactiveAfter some testing, I’ve noticed that when I disable #FortiEDR, the crashes no longer occur. This leads me to believe that FortiEDR may be interfering with Teams or some system-level resources like video, audio, or network handlingHas anyone experienced similar issues or is aware of known compatibility problems between FortiEDR and Microsoft Teams on macOS?Any advice, workarounds, or recommended configurations would be greatly appreciated.
Hello I have a question: when using SDWAN rules with Maximize Bandwidth (SLA) or Best Quality strategies, what happens to sessions already started on an Internet link that no longer meets SLA requirements? Are these sessions terminated by Fortigate or do they remain on the low-performance link until they are formally terminated by the application?
I was not able to install forticlient on Ubuntu 24.04 LTS ~/Downloads/vpn $ sudo dpkg -i forticlient_vpn_7.4.0.1636_amd64.deb Selecting previously unselected package forticlient. (Reading database ... 234015 files and directories currently installed.) Preparing to unpack forticlient_vpn_7.4.0.1636_amd64.deb ... Unpacking forticlient (7.4.0.1636) ... dpkg: dependency problems prevent configuration of forticlient: forticlient depends on libappindicator1 (>> 0) | libayatana-appindicator1 (>> 0); however: Package libappindicator1 is not installed. Package libayatana-appindicator1 is not installed. dpkg: error processing package forticlient (--install): dependency problems - leaving unconfigured Processing triggers for hicolor-icon-theme (0.17-2) ... Processing triggers for mailcap (3.70+nmu1ubuntu1) ... Processing triggers for gnome-menus (3.36.0-1.1ubuntu3) ... Processing triggers for desktop-file-utils (0.27-2build1) ... Errors were encountered while p
Hi, - FortiOS 7.2.10Currently we are using Dialup Ikev2 with certificates and it is working, the issue is when some home users using latest NBN/Internet which by default use IPV6 are unable to connect to VPN and we are forced to change the source to IPV4 for the home users.We are looking the best way to fix this issue, thinking if we enable IPV6 on the firewall external interface, it might fix it. If we enable IPV6 support on the External WAN interface and ensure the new IPV6 public is matching the VPN gateway, so that VPN users using IPV6 can connect to VPN and use IPV4 for client to server communication. I can't see clear documentation for IPV6 on this. Any advise or suggestions is highly appreciated. TIA :)
Hello,My linkedin today was blocking by Intrusion Prevention security profile.But we know that linkedin is a safe website.How we can bypass or fix it to not block linkedin?Thanks guys, there is below the message.Attack Name WebRTC.Local.IP.Addresses.DisclosureAttack ID 40.038Reference https://fortiguard.fortinet.com/encyclopedia/ips/40038Incident Serial 824.415.275Direction incomingSeverityLowMessage web_app3: WebRTC.Local.IP.Addresses.Disclosure
I'm looking for configuration example on the FortiAP to solve this use case. Client connects to an Open SSID, gets an IP from FortiNAC's registration interface. It is then directed to FortiNAC registration portal. Once the user is authenticated, NAC policy is applied and the Wifi vlan is changed to allow access. On the "Main" SSID interface, should there be any IP address ?Should Captive Portal be enabled with the external IP of NAC's registration interface ?Would you have two SSID "subinterfaces", one for each the registration vlan and guest access vlan ? Or just one for the guest access vlan. Any example configs or guide on the AP side would be much appreciated. I believe I have what I need on the NAC side.Don
Greetings... I have a FortiGate 60F in a building that is central to three legs of a campus, south, west and north. Mounted on south, west and north exterior/outdoor walls of the central building are three FortiAP 234F units providing WiFi to each leg as noted. Some recent renovations have left the signal poor at the end of each leg inside buildings, so we have purchased three more FortiAP 234Fs and plan to turn the existing WiFi network to a Mesh Wireless Network and are curious as to the best route we should go to configure this. Currently, all three APs are directly wired to the FortiGate and use the same SSID to make connecting and roaming the campus seamless. Each leg will have two FortiAP 234F units, a total of six on campus, one direct wired connection to FortiGate as noted and one mounted at end of each leg to provide stronger signal. Is it best to set up each leg as its own Mesh Wireless Network with its own SSID, or can all six units use one, si
Hi Folks,Our current WAN backup line isnt working, passes traffic fine but we need to implement BGP. I am thinking of gutting it and starting from stratch. We have two fortigates HA A/P config. At the moment it just uses static routing. See below. This works OK but we need to implement BGP on the external switches for route advertisement for inbound traffic. (Static with our ISP atm). However we have a further issue. We are migrating to AWS. The AWS tunnel keys off our WAN1 (fortigate 123.123.123.2) address. Therefore if we get a senario were WAN2 has to take over traffic our VPN tunnel to AWS will drop. I am thinking of replacing the entire setup with the below. So remove WAN2 (as its IP would never connect to the AWS tunnel). Does this design make sense, using HSRP between the two external switches, the fortigate would have static external route to the HSRP address and the external L3 switches would handle the BGP (our ISP will only add these to the BGP nei
Over the past 3 weeks the VPN connection is showing the above error and can’t be stopped until you connect to a Personal Hotspot from a mobile device. This is happening to staff working in all area's outside the Wellsway school campus.As a admin user I can stop this message from appearing every couple of seconds, but a user can not until they connect to their phone. In the past the VPN connection screen would appear and the user could just minimize it and they could get on with their work. Please could you advise how we can fix this issue. This problem is stopping the user from being able to work on their laptop as the message wants to be in the foreground all the time.
Hi Team, I have several Fortiswitches managed via Fortilink, and I need to configure snmpv3 with one Read and one Read/Write user. This configuration must be done from Fortigate? Can you provide me the steps to follow to perform this configuration. Thanks and best regards,Juanmi
Hello, We hace Ha configuration, now we monitor the cluster, And I recieve information from the master, but I dont know nothing about the slave one. What I want to do is to monitor each node instead of monitor the HA cluster. Is it Possible? ¿What is going to be the afections?
Good day. My Fortigate 80E suddenly has no logs displayed. All logs were missing or not recorded even on my Forticloud. May I know the reason of this? This just happened today. Previous days it has logs recorded. Thank you
Hi,I am looking for some input in to what I might be doing wrong in our new Fortinet setup. We are migrating from another vendor to a full Fortinet access-network consisting of Fortigates, Fortiswitches and FortiAP:s. The config is coming along nicely and we are almost ready to start testing this new network on a larger group of users. We have 2 VDOMs and Global, 7 VRFs and use OSPF to route traffic to the rest of the corporate network. Setting up wired access was a breeze with fortilink and the WIFI for corporate users (using Cisco ISE as Radius) is ready to be tested across the company. However I am having some issues with what I feel should be the easiest WIFI SSID to get up and running. The SSID intended for Guest. We have 4 SSID:s, one for corporate users having several VLANS attached to the SSID interface, each vlan belonging to different VRFs. One IOT SSID and one SSID for developers doing testing and lastly the SSID for Guest. They are all tunneled SSID:s.&
Hello Expert, Can anyone provide guidance to configure stitch for the fortigate to send an email alter when HA is out of sync. Thank you Regards
Dear all. I need your support as today I have faced issue with routing. we have lower distance AD for two static route but higher distance is shwoing best route why. please have a look snapshot and provide your opinion what needs to be done. I want to make best route for two networks which are connected to ISP.192.168.99.0/28192.168.100.0/28as per lower distance above the both route should be consider as a best route. and 192.168.145.0/24 should not be considered as a best route because distance is 50.
You do not have sufficient privileges for this resource or its parent to perform this action.Click your browser's Back button to continue.
hi all,I have a SD-WAN performance SLA with two participant interface, I want to view the history curve in FortiAnalyzer but one of the participant interface is not there.however, another SLA with the same interface have the interface displayed in FortiAnalyzer.what could be the reason and how to fix it?1. SLA 2. SLA in fortianalyzer with all participants (OL_INET_SKO_112 and port17)3. SLA in fortianalyzer with only one participant (OL_INET_SKO_112)
Hello, When I try to install even the simplest change in a policy from FMG to FG, install sticks at 35% with no error message.Both FG and FMG are in 6.0.4. After that, the FG appears to be disconnected from FMG, although connectivity FMG to FG is OK. Any ideas what's going wrong? Thanks
I'm looking for NSE5_FMG-7.2 practice questions. Could anyone share the right study materials or insights from a recent exam pass?
Can someone explain to me the difference and application scenarios between SD-WAN DUAL HUB Primary/Secondary and SD-WAN DUAL HUB Primary/Primary?Note that I have 2 private data centers and different network spaces?
i have tunnel to connect from branch to the datacenter but the traffic seem goes to wrong path.In the BGP path i can see the next hops is right where pointed to the tunnel ip, but in the routing table traffic to datacenter forwarded to the internet gateway. Anyone why in the routing table the traffic forwarded to the internet?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.