Mark a Best Answer
Fortinet Community
Recently active
Dear Team,We are experiencing an issue with SSL VPN authentication when using email-based OTP and custom realms.**Device:** FortiGate 100F**Firmware:** v7.2.8 build1639 (Mature)**Authentication type:** Local users with two-factor authentication set to email**Issue:**- When users authenticate via the **default realm** (i.e., no "set realm" in the authentication rule), the OTP email is sent, and login proceeds successfully.- When configuring a **custom realm** and associating the same users via an `authentication-rule`, the login fails with **"permission denied"** and **OTP is not triggered**.- Debug logs show: `two factor check for [user]: off`, even though user configuration includes `set two-factor email`.**Troubleshooting done:**- Verified user has `set two-factor email` and valid email address.- Tried assigning user directly in `authentication-rule` and via user group — behavior is the same.- Reset password and email OTP on the user — no change.- Verified that SSLVPN works in both r
Hi,I've created virtual servers on Fortigate (eg: mail.customer.com, phone.customer.com...) and all works on LAN, but when i connect my pc to a VLAN i can't reach no one of them, so if (for example) i want to connect to my mail server it didn't works.I'm able to ping mail.customer.com (return public IP).I've created firewall policy rule but i'm not sure how to create static route and/or policy route.Can you help me?Thanks.
Is there a way to Block all Internet traffic except Veeam Malware detection URL?The DNS is changing every time (IP's) so based on IPaddress Its not working always.And I also created a DNS filter But I see still traffic to others based on IP (I think) Is there another way to fix this? Kind regardsDaag
I'm trying to lock down some of my web rules. The issue is many of the server owners don't understand what web access they "need" so I resort to turning on full logging. I put a more restrictive rule above the less restrictive rule, and check the logs on the less restrictive rule. The end goal being that eventually there will be no more traffic on the less restrictive rule and I can remove it. I've got logging turned on, but sometimes the logs can be a bit deceiving. For examplewdcp.microsoft.comresolves to something likewd-prod-cp-us-east-<number>-fe.<east or west>us.cloudapp.azure.comOften times I'll see in the logs that the server accessed wd-prod-cp-us-east-<number>-fe.<east or west>us.cloudapp.azure.com when, in fact, they actually accessed wdcp.microsoft.com (but I don't know that fact). I'll put *.<east or west>us.cloudapp.azure.com in the rule that I use above the more restrictive rule, but then the next day
Hi all, the FortiGate VM appliances clearly contain binaries whose source code is licensed under the GPLv2, e.g., the Linux kernel. It is also evident that Fortinet made modifications to this source code, e.g., the rootfs decryption, and distributes these modified binaries. The GPL is pretty clear that the source code of those modifications must be made available. After some reseach I was not able to find out where to obtain this source code. Does anybody know how to get it? Best,Zhu
Hello EMS admins There was a post about EMS behind a Web proxy where @xshkurti (Fortinet staff) replied that EMS 7.2.1 doesn't support to access FortiGuard through a Web proxy.https://community.fortinet.com/t5/Support-Forum/EMS-server-through-Proxy-server/td-p/91031 Now I'm on FortiClient EMS 7.4.1 and I have the same issue.Anyone managed to get this to work?Or anyone knows if this is planed to be be fixed in a future release?
Hi all,I have a setup consisting of 2 FG100F in HA mode and pair of FS124F connected to both chasis in HA as follows:FS SW01 port24 to FG primary port18, port23 to FG secondary port17FS SW02 port24 to FG primary port17, port23 to FG secondary port28SW01 and SW02 are interconnected port22 to port22. Server load has redundant interfaces connected to both switches to their respective ports.Ok, everything works fine, if one switch fails everything is still up. My question is: how to "force" SW01 to become primary again after some sort of temporary failure? Many thanks and please dont ask me why customer didnt went to MCLAG supported switches.
Hi all, I hope you are well. I have a customer who has two MPLS links. He bought fortigate and wants to replace the router CE he has with FortiGate. Is it possible ? Thanks in advance.
Hello, we like to change or cross-upgrade from FortiClient EMS cloud FC1-10-EMS05-538-01-DD) to FortiClient EMS cloud XDR FC1-10-EMS05-1041-02-DD). And because of the fact that You cannot mix different types of licenses in EMS cloud we need a migration to the new product. Is there any documentation on how to migrate from any FortiClient #variant to Forticlient XDRIs there a way to preserve the settings for clients w/o exporting settings as XML one-by-one?Has somebody made experience with such a case already? best regardsMartin Haneke
So instead of the FMserialnumberhere.Assign a value based upon say hostname, domain name etc?Currently using the LEC built in functionality. Thanks.
Hi team, I have configured ztna agentless feature which introduced in 7.6 version (using 7.6.2) but getting 'site can't be accessed' error while accessing the web bookmark. redirected url: https://10.10.1.17:4434/XX/YY/ZZ/webservice?bmgroup=bookmark&bmname=fmg&cookie=DB2B48CEE7376444186CBF70E25D1257 Why this XX/YY/ZZ is showing here ?? Kindly suggest.
I have DC network space 10.10.0.0/16 with Hub-Spoke model. I am building more DR with other DC network space 10.200.0.0/16. So I am confused whether to choose Dual Hub Pri/Secon or Pri/Pri.
Hi engineers how can i check which and how many website falls under shopping category where i can find thanks in advance for support
I have 3 sites and connect to the datacenter using different wan connections. The simple topology is :Site1-wan1-dcSite2-wan2-dcSite3-wan3-dcWith this scenario it's possible to create advpn between every site to the dc? If yes, is there any tunnel shortcut across sites?
I have a FortGate 61F running 7.4.6 in my main office behind cable internet with a static IP. I have a remote office with a 40F running 7.4.5 behind a T-Mobile internet gateway. It was the T-Mobile FAST 5688W and we a dial-up IPsec tunnel and it worked fine.The site got a new T-Mobile TMO-G4SE gateway and now we have issues. The FortiGates on both ends show the tunnel as Up and I can ping from each side from the other (about 130ms). From the main office I can bring up the admin page for the remote FortiGate in a browser, but it is very slow. Speed test on the remote side shows 250 Mbps or better. Other web pages on the main office will not load on the remote side, and the remote side cannot connect to remote desktop hosted at the main side. Any suggestions on what I should look at? Thanks.
Hi ,I am new to the FortiGate system; I wish to know how to get a connected Windows PC activity log (last two weeks) from 60F 7.2.11.
HiI have 1 year forti analyzer license on my vm but it is expiring in 1 month. so what is the best way to get another 1 year license and not loose my vm configuration?
I do have a ticket open on this but getting little traction. Hoping I might get better traction here. My users currently use SSLVPN with SAML to our ADFS server perfectly. I read the docs and created a IPsec config for the users using a new IKE port. I created a new FSSO that only differs from the one used by SSLVPN in the port number. Created a new Relaying Party Trust which is a mirror image for the SSLVPN one (just changed the port number). All of the certs are exactly the same. When I test and debug I see the username and group coming back to the Fortigate in the debug. Right after that I see:__samld_sp_login_resp [830]: Failed to process response message. ret=-111(Failed to verify signature.) Which means its having Cert issues. Not sure I understand how this can be. The certs used on the fortigate are the same for IPsec and SSLVPN. The cert in the Relaying Party Trust is the same between the 2 config. I hav
Hello,Is possible to send logs from EMS to FAZ? If so what Adom should I choose in FAZ to get the EMS logs?In EMS settings there is the option to send logs to FAZ.... Thank you.Regards.
Hi I want to extend my Forti Analyzer disk but want to confirm that, I need to take backup first or it can be extended without taking backup of logs. Regards,MK
I'm using FortiClient VPN on my virtual machine with Linux Mint (ubuntu). I'm using NAT mode for my virtual machine and with such settings - FortiClient VPN for Linux (v7.0.0.0018) is not able to connect to remote server. I'm receiving such error:NOTICE::Insufficient credential(s). Please check the password, client certificate, etc.STATUS::Set up tunnel failedSSLVPN down unexpectedly with error:2STATUS::Setting up the tunnelPress Ctrl-C to quitClean up... In my opinion - this message is a root cause:STATUS::Set up tunnel failed What is the most funny - in Windows working as virtual machine in NAT mode - with FortiClient VPN (v6.4.1.1519) - there is no problem with connection. I've noticed a difference in settings between FortiClient VPN for Linux and Windows. Windows version has such option:"Preffered DTLS Tunnel" In Llinux FortiClient VPN there is no such option. I've noticed also such message in my FortiClient:"Upgrade to the full version to ac
Hi, I have done FortiAnalyzer deployment in Hyper-v and it's working fine, but given that my storage is full, it is causing denying some Fortigates. It shows only 50G while I have assigned 500G. Kindly let me know If I have to rebuild my hyper-v, and what is the correct to do to fix it. I have checked the below commands: FAZVM64-HV # execute lvm hwinfo/sys/block/loop0 -> ../devices/virtual/block/loop0/sys/block/loop1 -> ../devices/virtual/block/loop1/sys/block/loop2 -> ../devices/virtual/block/loop2/sys/block/loop3 -> ../devices/virtual/block/loop3/sys/block/loop4 -> ../devices/virtual/block/loop4/sys/block/loop5 -> ../devices/virtual/block/loop5/sys/block/loop6 -> ../devices/virtual/block/loop6/sys/block/loop7 -> ../devices/virtual/block/loop7/sys/block/ram0 -> ../devices/virtual/block/ram0/sys/block/ram1 -> ../devices/virtual/block/ram1/sys/block/ram2 -> ../devices/virtual/block/ram2/sys/block/ram3 -> ../devices/virtual/block/ra
We already have a FortiNet in place with "outbound" policies pointing to WAN1 because we were going to use an ISP aggregator in front of the FortiNet. Now things have changed and management no longer wants to use the ISP aggregator and use the built in FortiNet SDWAN. I don't have much experience with SDWAN on the Fortinet. Since I already have rules in place, can I just create an SDWAN Zone with just WAN2 (no rules currently are on WAN2 so I can add him). Once that is done I make a backup of my config, open it in notepad++ and change all my WAN1 destinations to the newly created SDWAN Zone instead. Then when WAN1 doesn't have any policies assigned to it anymore, it could also be added to the SDWAN Zone? Is that about it? Or are there other 'gotchas' I need to worry about? Like default gateways or something? I'd be doing this remotely (I'm in the US and the FortiNet in question is in AUS). While I can have smart hands on site
I have 4 spoke connected to the HUB.HUB LAN 10.103.0.0/16SPOKE1 10.107.0.0/16SPOKE2 10.100.0.0/16SPOKE3 10.102.0.0/16SPOKE4 10.101.0.0/16Connection from every spoke to hub use 3 different connection (2 using internet and 1 using WAN)if we see in the BGP routing why :route to 10.100.0.0/16 and 10.102.0.0/16 only have one entry?route to 10.101.0/0/16 and 10.103.0.0/16 (HUB) have 3 entry?
I'm wondering what encryption, authentication, and DH groups you typically use in this space for Phase 1 and Phase 2 of IPsec. Do you use just one group, two, or three?I use AES-256 - SHA-256, DH 14 and 27. How does it look on your side?Of course, on each device, I have a whitelist for my hub in the local-in policy, but I'm referring specifically to the IPsec configuration itself
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.