Mark a Best Answer
Fortinet Community
Recently active
Hi Everyone, We have several locations that need to RDP into our office to access the same PC via the same RDP port. Our current setup is: VIPName: VIP RDP PC1External IP: Our building's external/public IP.Map to: PC1's LAN IP.Port Forward to: 3390 TCP I created a Firewall Policy:Name: RDP To PC1Incoming: WANOutgoing: VLAN5Source: AllDestination: VIP RDP PC1Service: AllNAT: DisabledAction: Accept For some reason, I can RDP in from home. When a coworker tries to RDP in from their home, they can't. Before we could RDP in when we were using a different firewall, Netgate 6100, so I know it's not our home setup. We just installed this Fortigate 90G, which is very nice. Any assistance is greatly appreciated. Thank you very much,Sonny
I deployed a FortiNAC VM and configured policies to assign users to VLANs based on their department. To achieve this, I used an Active Directory attribute to assign a role to each user, which FortiNAC then parses via AD synchronization.  In the User Accounts page (first image), I can see that the correct role "112" has been assigned to the user. However, in the Hosts section (second image), the user’s laptop—where the same user is logged in—does not have the expected user role assigned (it should be 112 but is missing).This discrepancy prevents proper VLAN assignment. How can I troubleshoot and ensure that the role is correctly applied to the host?
Hello,I found a bunch of old FortiAP 221B.I'm wondering if it is possible to manage them via Forticloud.I'm trying to figure out what is the right config to register them with the cloud without success.If you have any idea please share itMany Thanks
Good day.I am using the VPN, and when I connect, I notice that the received bytes show as 0, while sent bytes are being transmitted. I would appreciate your assistance in identifying the cause of this issue and any possible solutions. I look forward to your response.
please I need to ask something we are blocking all VPN application but our employees are still able to connect to a free VPN application and break our security rules and policies we have policy to deny Facebook and Instagram but once the employee connect to a free VPN app he is able to break this policy and open Facebook and Instagram easily even though we have blocked these apps on the FortiGate security profiles. Any advise please
Hi all, I have a large LAN ReDesign Project. I will Change all Aruba Switches, which are EOL to new FortiSwitches. With this Change I will Change the IP-Subnets, too. My Concept is, that all FortiSwitches get a own VLAN. For CoreSwitch I choosed a FortiSwitch 1048E, which I connected to the free 10 GBit/s X2 Port on the Fortigate. So I configured the X2 Port with the following IP-Config: 10.100.99.1 / 24Receive LLDP: EnableTransmit LLDP: Enable Administrative Access: HTTPS, SSH, PING, FMG-Access, FTM, Security Fabric Connection I configured the FS1048E with the IP-Adress 10.100.99.2 / 24. I leaved a small Config first time. I connected the FS1048E on the X2 Port of Fortigate, but I can´t reach the FS1048E. Administrative Access on the FS is HTTPS, SSH, PING. I tried to ping the Fortigate from CLI of FS1048E but I can´t reach it. I tried to ping the FS1048E from Fortigate CLI and can´t reach the FS1048E, too. Normally it is an easy job, but in this time I don´t under
Hi Y'all, I'm attempting to deploy FortiGate NVAs on an Azure vWAN and I am stuck on the 'Configuring Internet Inbound/DNAT Policies' step: Configuring internet inbound/DNAT policies | FortiGate Public Cloud 7.4.0 | Fortinet Document Library The NVAs are running 7.4.4, its talking to Manager/Analyzer just fine, BGP routes to Azure vNets are populating fine as far as I can tell. It is probably as simple as me just not understanding the instructions but I'm not following the instructions about Internet Inbound settings all that well. Which IP addresses should I use for the source-address-prefix setting? Are the IPs in the example just for show? I can't find them referenced anywhere else in the deployment procedures. The command execute azure vwan-slb show returns failed to retrieve vwan slb settings. Am I correct in assuming that this result occurs because I have not configured azure vwan via the CLI yet? Is there any other documenta
I have configured SSL VPN on one of my FGTs using GUI, the same way as it was configured on another one (the idea is to move some business critical services from one office to another). Then I have discovered that FortiClient can't connect because of a connection timeout. Further debugging with packet sniffer has revealed that only SYN packets are coming from client, nothing goes back. The next step was the flow debugger:MyFGT # 2025-01-09 16:58:51 id=20085 trace_id=195 func=print_pkt_detail line=4489 msg="vd-root received a packet(proto=6, my.client.ip.address:51567->my.fgt.ip.addresss:10443) from wan1. flag [S], seq 1184327228, ack 0, win 65535"2025-01-09 16:58:51 id=20085 trace_id=195 func=init_ip_session_common line=4645 msg="allocate a new session-000fdb96"2025-01-09 16:58:51 id=20085 trace_id=195 func=fw_local_in_handler line=398 msg="iprope_in_check() check failed on policy 0, drop"I have read a dozen of pages on the internet, in Fortinet knowledge base and in this forum, als
Hello - I have a customer who updated to version 7.2.3 to be clear of the recent SSLVPN vulnerability; however, HA is out of sync and comparing out puts it is showing the vpn.certficiate.ca. This shows to be a bug in an earlier version. Any advice? Thank you
Hello, we are working on this problem for some time now and we dont quite understand the problem. We have FGs in smaller offices with MPLS connected to our mail firewall in a DC. We are using VMs in our local DC connected with MPLS (biggest ISP in the country) and also now some VMs in Azure connected via main Fortigate in DC and Fortigate in Azure Cloud (internet speed 200/200mb) The problem is that users in branch offices which are working with a VM file server in Azure via SMB are reporting problems because of low performance. The ERP system has to save some files on the Azure VM and it takes a very long time. Uploadig files (later we checked with a big ISO file) we get like maximum 5-10mbits to Azure. For the IPsec to Azure we use our dedicated WAN with 1GB and have like 200mb on the Azure site. So we started testing and checking the performance on all sides. From branches we have MPLS 1 GB (divided por streams so we are not 100% sure) to our DC. Downloading and
We currently have a Windows Server that not only serves AD, but also Radius and DNS servers, where this server serves other branches, where the FWs are connected via VPN (without significant packet loss, average amount of 0.5%).However, in one of our branches with high device density (you could say a second head office) we have been facing some difficulties with Wi-Fi connection. Today we use UniFi authentication on the SSID using Radius. However, all DNS and Radius requests are used by the Head Office infrastructure.I have a theory that perhaps this connection drop is related to the excess of Radius requests or even DNS requests, a number of requests that may be outside the scope of the Windows Server CAL licensing (I do not have this information).Considering this, I would like to know if it is possible to use Fortigate for DNS queries, but Fortigate should query the DNS addresses on the Head Office Server and store them in an internal database that is updated from time to time, of co
Hello Dears, Just wondering how I can rewrite the below host and the steps to do it. x.example.com/portal-clienty.test:9443/portal-client Thank you
I'm trying to modify/enhance our user VPN experience.While trying to add the FortiClient VPN to a Linux laptop, we could not see any of our configured IPsec tunnels.Later found out that the Linux client is not compatible with any tunnels configured with IKE 1.So, we will have to change to IKE 2. (lesson learned... don't use the 'Wizard')While asking these questions, I also asked how we could potentially create a Single tunnel that could access both of the IPsec VPN's on our 2 separate ISP circuits.I was shown that I can add multiple VPN's to the VPN 'profile' in EMSNow my questions are ... is that all/enough? Or do I also need to create a VPN 'Aggregate' on the FortiGate too ??How does the FortiClient profile determine how an end user connection chooses the appropriate tunnel?Round Robin by default ?? At least the 'Aggregate' configuration in the FortiGate allows me to choose between several methods.Then at the FortiGate, how do I modify each tunnel to enable 'ag
I am using FortiGate 91G firewall and recently done the configurations. I need to block all the VPN access to the network and to do that, i created separate application control and blocked the proxy. meantime as a override rule, i blocked VPN related network services such as IKE, ISAKMP and ESP.IP. But still when i am connecting to a VPN, its connecting without any issues. When inspecting the log, it is connecting through the DNS,QUIC network services. i cannot block these network services because of they are using by many other functions through the connections. what i need to do to block the VPN access. I am doing the testing with 1.1.1.1 Cloudflare VPN?
Hello,We have a problem with our VPN.We are experiencing an issue that occurs once every month, where employees (it changes - skipping between users) using only Mac computers come to the office (but happens also in their home wifi) and are unable to access internet when they are connected to VPN.We use:Forticlient vpn only free - last versionIPSEC VPNWhen they try to ping servers/addresses: sendto no buffer space availableWhen it happens I see many interfaces with addresses of VPN (192.168.11.0/24). After disabling interface with VPN: ifconfig interface utun4 down - internet works! Another user told me: WIFI works, VPN works. He leaves the computer, computer goes to sleep mode and after that Forticlient seems as connected but no internet!Another user reported: I was on the train, using HOTSPOT and Forticlient. Close the lid (So internet was disconnected). Went to the Office, I was connected to Office's WIFI and had this problem of buffering. Why are there
Hi All, I am in need of some expert advise on this after exhausting Forti TAC support. Details:FW: 7.2.4AP: 7.0 Build 0031 (latest).H/W: U231FProblem: The AP's are all using the same channels and because of that when users are roaming they get disconnected and I have to either reboot them or put them into a different AP profile and limit the channels they can use so that each AP uses different channels - this is particularly for 5Ghz.I don't understand why even with RRP - Enabled and DFC channels selected the APs are selecting the same channel and I can confirm the AP signals are overlapping so why is the AP not smart enough to move the AP's to different channels?Can someone please guide me on what am I missing here and Forti-TAC's suggestion is to create an individual profile for each AP and enable RRP but limit the channels or make sure they don't overlap. Your help is much appreciated. Wireless Controller, #firewal
Hi everyone,I'm new to Fortigate and want to thank you in advance for your support! I have a strange problem: After some hours, the prefix delegation gets lost. My setup:Vodafone (via calbe, provides a /59 net) > Cable Router: Fritzbox 6670 (7.6.3) > Fortigate 61 E (7.0.9 build 0444 mature)The Fritzbox keeps one /60 net for itself and delegates the other /60 net to the Fortigate. In the Fortigate, the WAN1 interface is connected to the Fritzbox and ipv6-setup is this: config ipv6 set ip6-allowaccess ping https set dhcp6-prefix-delegation enable set autoconf enable config dhcp6-iapd-list &
Hello,I am planning to purchase on-demand Lab Access for FortiGate Administrator and would like to know how the time spent in the Lab is calculated. Does the timer start as soon as you start the lab and stop once you leave the lab's page? Can someone please explain how the timer works? Thank you.
Hello All, I have FortiGate 601E, one of my outbound policy shows Active session about 15 but it doesn't show anything on the log when I do show matching logs on the policy. Does anyone have any idea? Thank you
Get the following error: Post vdom failed: error :-999 - invalid value - [line 2214] > edit 8 [datasrc invalid. object: firewall ssh setting.:caname. detail: g-Fortinet_SSH_CA. solution: data not exist]I do not have any reference to "firewall ssh setting" in my CLI templete. Has anyone see this before?
Hello @All can I use on FGT 1100e the two Mgmt/HA ports, both for HA only? Many thanks in advanced TBC
On our Fortigate 900g we cannot use the Firewall User Monitor Dashboard anymore. In 7.2.8/7.2.9 the top portion with the "stat circle" and search bar wasn't visible at all except once in a bluemoon if we rebooted the Fortigates and prayed. I upgraded to 7.4.5 yesterday hoping for a fix... the dashboard has changed and now introduces the filter option on the column header but they don't work like at all... This is pretty bad programming...
Dear Team, We have a FortiGate 400F Firewall and We have Four ISPs (Port1, Port2, Port3, and Port4) configured as a single SD-WAN zone. Our LAN network consists of multiple ports: Port7, Port8, Port9, Port10, Port11, and Port16, with each port assigned a different subnet. For example, Port7 is assigned 10.0.2.0/24.Traffic from Port7, Port8, Port9, Port10, and Port11 (LAN interfaces) is routed through Port1 and Port2 (ISPs).Traffic from Port16 (LAN interface) is routed through Port3 and Port4 (ISPs).Port7, Port8, Port9, Port10, and Port11 should not use Port3 and Port4, and similarly, Port16 should not use Port1 and Port2.We will configure the above topology next week. Please provide a solution for the mentioned issue.
Hello Team,I have been searching for the EOL/EOS dates for several products and have reviewed the product life cycle on the support portal, but the exact information was not available. As a TAC, could you please provide the EOL/EOS dates for the following products? Additionally, why are they not mentioned on the portal, and what should we consider if we cannot find the data on the portal in the future for any other Fortinet products?- FAZ-150G- FG-200E- FG-101F
Abstract:This study examines the impact of manual threat intelligence updates on system memory consumption in Fortigate 60E and 60F firewall models following USOM integration. Test results indicate that after performing a manual update, there is a significant increase in RAM usage, which eventually leads to the device crashing.Introduction:Fortigate firewalls work in conjunction with threat intelligence centers such as USOM to continuously update threat intelligence databases and prevent malicious network traffic. However, the effects of this integration on system resources are not always thoroughly analyzed. This study investigates the impact of USOM integration on memory usage during manual update processes on Fortigate 60E and 60F models.Test Methodology and Findings:USOM threat intelligence lists were integrated into Fortigate 60E and 60F devices.A manual threat intelligence database update was initiated.A significant increase in RAM consumption was observed during the update proce
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.