Mark a Best Answer
Fortinet Community
Recently active
Hi everyone,As the below error java applet not startup because fortigate firewall prevent it Fortios 7.6.2Added web server to whitelist but still the error I tried from ISP direct work fine Could anyone help me  
Although I have more than one vpn (ipsec) in the Active Administrator Sessions section, I always see this user login from the same vpn. what could be the reason for this?
I've discovered what looks like a bug in FortiOS 7.4.6 and am posting this in case anyone else runs into the same issue. It's not currently listed as a known issue in the release notes. After upgrading to FortiOS 7.4.6 on our FortiGate-80F firewalls, the connected FortiExtender stops working. The FortiExtender goes offline on the FortiGate. You can't re-authenticate the FortiExtender and if you delete it you can no longer add it again. This looks like a CAPWAP bug. This is reproduceable on FortiGate-80F firewalls and downgrading to FortiOS 7.4.5 resolves the issue. FortiGate-60F doesn't seem to be affected and I haven't tested any other models. I've logged a case with Fortinet so hopefully it appears as a known issue soon.
Hi, I wanna know if fortinet provides a pdf file from each lesson that we take in order to submit to a exam.For a example: To study for FCP - Administrator we have to watch videos that have transcription of audio in 'notes' tab.When i study from my NSE4 i use a pdf file FortiGate_Infrastructure_7.0_Study_Guide-Online. Is it possible to use it again to the new course?Also, if possible, can i get the same file for the FCSS Network Security - Enterprise Firewall and Sd-wan?
Hi All,My fortigate is sending all logs to the fortianalyzer just need the important one i have set the severity to the critical and disable the local traffic as well, But in analyzer in events log i am seeing that still informational and notice error logs are forwarding by the fortigate to analyzer how to fine tune the logs just want forward traffic logs and security events logs to analyzer how to configure the filter properly anyone can guide me ?. Regards,MK
I cannot install Foticlient VPN on my new windows PC.Installation fails prematurely PC configuation. OS Name     Microsoft Windows 11 Home Version     10.0.26100 Build 26100 Other OS Description    Not Available OS Manufacturer   Microsoft Corporation System Manufacturer     LENOVO System Model      83ED System Type ARM64-based PC System SKU  LENOVO_MT_83ED_BU_idea_FM_Yoga Slim 7 14Q8X9 Processor   Snapdragon® X Elite - X1E78100 - Qualcomm® Oryon™ CPU, 3417 Mhz, 12 Core(s), 12 Logical Processor(s) BIOS Version/Date LENOVO NHCN36WW, 5/23/2024
We have a Surface Laptop 7 with a Snapdragon X-Elite (ARM) processor that we are testing out. The one problem we haven't been able to overcome is getting the Forticlient to work reliably. We've followed this tech tip: https://community.fortinet.com/t5/FortiClient/Technical-Tip-FortiClient-Support-for-ARM-Architecture/ta-p/248361 Using the Windows Store Forticlient app and the Windows VPN settings, we can establish a connection every time. I can even get Azure MFA to work, though you have to establish the connection in the settings app or you won't get the prompt for the OTP. The problem is that probably 99% of the time, the connection shows traffic being sent but none received and after about 5 minutes it will disconnect itself. About 1% of the time, the connection works fine and will stay connected for at least an hour, we haven't tested past that. Does anyone have any suggestions on what might be the problem here? I'm not even sure where to look for logs. I can see eve
I would be grateful if those who understand more about the subject can shed some light so this makes sense to me. On the AWS Marketplace, the FortiManager 10 costs $4,730 per year (not counting AWS infrastructure costs).https://aws.amazon.com/marketplace/pp/prodview-4rgupihrc4lgq?sr=0-2&ref_=beagle&applicationId=AWSMPContessa If we commit to the one year contract it drops to about $4,080. If we go with BYOL and purchase the 1 Year Bundle from a Fortinet reseller (FC1-10-FMGVS-258-01-12), it costs about $350. I do not understand why buying from AWS is $4080 and buying from a Fortinet reseller is $350. What am I missing here as neither of the above include infrastructure so I believe I am comparing the same thing?
I have a SSLVPN working for my users. They authenticate using SAML to our ASFS server. I am trying to do a similar thing but now with IPSec. I have changed the port but my iDP is the same. When I try to VPN with IPSec the debug reports that its using the Assertion consumer service URL (login) url with the SSLVPN port number. Can I try to do SSLVPN and IPsec both using SAML and the same iDP server at the same time? I do not have a test environment so this is the only way for me to test.
GreetingsI have been looking for documentation on how to implement a VXLAN that can transport multiple vlan like a QinQ scenario.I appreciate any information that you can provide
Hi All,We have a VPN connecting to cloud AWS services. We have created policys to enable traffic from our cloud servers to the internet via our on prem Fortigate.However the traffic fails to hit the policy we have created and instead hits the implicit deny all. Not sure what is going on here, we are in the process of migrating our on prem servers to AWS cloud. I know with AWS we can give them public IPs so they can connect direct to the internet but we want to maintain some control via our firewall. The only think I can think of is that we are using the same connection (our WAN interface) to connect to AWS and the internet. Although when creating the policies you have the option of interface so we have AWS-VPN to External. any advice or help appreciated.regards,Chris.
Hello Everyone, I have 2 internet and I configured SD-WAN with load balance on the FortiGate firewall. I have inbound policy to my web server and it works fine from outside but when I'm in my local network and use the guest wifi it doesn't load the we server page. How can I have the return path from guest to my web server?Do I need to configure SD-WAN rule or ......? Thank you
I am trying to host multiple Application URLs on Fortigate's external interface public IP... can i configure it using Virtual IPs ? i need to use single public IP with same listener. If i create as follows will it work ? 1) website1@abc.com as virtual IP1 and website2@def.com as virtual IP2 with both of them having same external public ip and same port 2) create 2 policy for each website and tag certificate via ssl-inspection any help is appreciated.
HiI was wondering if anybody knows if it is possible share the "smartconnet" program from the fortiauthenticator portal(onboarding) with all users in a company?There is no backend identity provider, or anything like that. Just a very simple certificate trust chain (no subject binding) (local ca on fortiauthenticator).
I have come here to get the solution. not able to establish SSL VPN with Fortigate evuation license. Please review the logs may be I have missed someting .FGVMEVD9RPZGR-D9 login:FGVMEVD9RPZGR-D9 login: adminPassword:Welcome!FGVMEVD9RPZGR-D9 # diagnose sniffer packet any "port 4443" 4Using Original Sniffing Modeinterfaces=[any]filters=[port 4443]27.235570 port1 in 192.168.45.52.55327 -> 192.168.45.21.4443: syn 270181939327.235656 port1 out 192.168.45.21.4443 -> 192.168.45.52.55327: syn 2693275210 ack 270181939427.241739 port1 in 192.168.45.52.55327 -> 192.168.45.21.4443: ack 269327521127.252798 port1 in 192.168.45.52.55327 -> 192.168.45.21.4443: fin 2701819394 ack 269327521127.254279 port1 out 192.168.45.21.4443 -> 192.168.45.52.55327: psh 2693275211 ack 270181939527.256603 port1 out 192.168.45.21.4443 -> 192.168.45.52.55327: fin 2693275218 ack 270181939527.260577 port1 in 192.168.45.52.55327 -> 192.168.45.21.4443: rst 2701819395 ack 269327521827.860430 port1 i
Hi, I am getting serious crazy with an issue with ZTNA.Setup: I have two Fortigate, (Site A) and a Fortigate (Site B) with an IPSEC-Tunnel between.I know I have to work with ZTNA IP pool to reach out a destination on Site B.I want to have port 5060 (TCP) reachable over a TCP ZTNA Setup. I know, I have to setup Endpoints on the EMS, too.Fortigate does have FortiOS 7.2 running the latest Patch, EMS 7.4.1 on the Cloud. Test: Port 3306 for MySQL: works (TCP, not encrypted)Test: Port 22 for SSH, worksTest: SIP, TCP 5060, DOES NOT WORK I already disabled the SIP helper and tried with other incoming ports, nothing works. TCP with SIP works on the local VLAN indeed. If there is anyone with a good idea, I am here ;) Thanks
Good morning everyoneWe are experiencing a strange situation. The following is the scenario.The user connects via SSL VPN to the head office's fortigate and then, in this connection, with the head office's devices, the packet loss is minimal. However, this SSL VPN connection needs to access a server with an application hosted in a branch office. On this route, the SSL VPN to the head office and from the head office to the branch office has an average packet loss of 50%, sometimes 60%.Important information: communication between the head office and the branch office is normal, with an acceptable packet loss of only 0.5%.In short:User connects via SSL VPN to Fortigate at headquartersConnection established with headquartersPacket loss: minimalUser accesses devices at headquartersStable connectionPacket loss: minimalUser tries to access server with application at branch officeSSL VPN connection to headquartersConnection from headquarters to branch officePacket loss: average of 50%, s
Hi all, my first post here. Perhaps someone can help. Our firewall is configured to connect to an on-prem Radius server (NPS). Hybrid connectivity is setup so users are also in Microsoft Entra with MFA setup. Firewall is configured to point to Radius and only allow vpn connections if users are part of a group. For some reason, any new users that we setup do NOT get the MFA prompt in Forticlient (using either EMS client or standard) , However, old users' , setup over 6 months ago, work just fine! I did find this article and will try to determine if it's applicable:https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Failed-authentication-when-connecting-to/ta-p/287175 However, what baffles me is that old users are OK, but, new users are not. We've tried from the same workstation. The MFA prompt (that extra field in forticlient that asks for the token does not show) and it errors out at 45%. Has anybody encountered this before?&n
Hello, I am using FortiGate version 7.2.10. I am distributing DHCP via the FortiGate interface over VLAN. The lease time is set to 7 days, but when the lease expires, PTR records on the DNS are deleted. There are DNS-update commands available in the DHCP server CLI, but it seems like those commands are not working, as it doesn't allow me to run them. How can I dynamically resolve this issue and make it permanent so that PTR records are not deleted? Best regards.
Hi, we have Safesearch been enabled on FortiGate. Google & Bing does the safesearch, but other search engines like duckduckgo, startpage, baidu, aol etc doesnt. We would like to block all search engine, but only allow Google & Bing. How can I achieve this? Any help would be much appreciated, thank you.
Good evening!Friends, I'm using two images in EVE-NG, one from fortigate v7.0.9 and the other from fortimanager v7.4.5 build2553.I connected to both with the forticloud trial.I was configured a management interface on both and another Lan interface (where I would connect between them)They both ping each other and fortigate closes telnet on port 541 as I have checked. I activated FMG-Access on the lan port on the fortigate where I will communicate with the fortimanager.I reduced encryption in fortimanager, set low and also activated fgfm-ssl-protocol sslv3.I put the Fortimanager IP in the fabric connector > Fortimanager, on premises.I always get this error (not manage)as I enclosed snapshot. I tried everything possible, I have no more ideas. Please Help thanks in advanced. 
Hi Community,1. Issue: I have problem with some clients VPN. They can connect to VPN. They can ping everything. The only thing doesnt work is accessing network folders. Deactivating of IPv6 under network adapters didnt help.2. Issue: There are two users using DSLite connection. After VPN connection. In Explorer when I click on MyComputer, computer gets stuck, screen becomes black and I cant do anything, I have to just wait till screen appears and again same issue no network device access and the command gpudat /force fails after waiting long time.Thanks in Advance
We have two links configured using the SD-WAN feature for fail-over. Recently, one of our links went down, and the fail-over process took approximately 10 minutes to complete. what is the cause of the delayed failover? FortiGate
Just wanted to ask more information about this: FG-IR-23-407 does it mean site to site ipsec with dyanmic sources or is it talking about users being assigned a dynamic ip via ipsec
hello all , i have this solution in my network (Juniper EX4100 switch connect to Fortifone and pc connected to fortifone) integrated with clearpass.for PC mac authentication is successfully but for dot1x isnt authenticated , but when i remove the fortifone and connect it to the switch direct it authenticated successfully.all of fortifones are managed by fortivoice.this is my product in the network:#FVE-VM-10#FON-17#FON-38#FON-58so is there any missing configuration on fortifone?thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.