Mark a Best Answer
Fortinet Community
Recently active
We have a problemThe bandwidth we applied for was 300Mbps, but the actual bandwidth was only 150Mbps.Is it related to the internal function restriction of the firewall? If it is unavoidable, do I need to upgrade the hardware? I have checked the CPU and RAM first and they are all normal.The product we use is FortiGate100D
Hi, the title says it al, how to block internet except one (or two) address (or IP) without using web filtering. We don't want to make a rule to enable internet then filter, that's something our auditor does not allow, so we have to make a rule that denies internet, then add exceptions.I tried to make a firewall policy from the Internet interface to the VLAN we want to block for internet, but then if duplicate the same rule but this time add one previously created FQDN address to allow, it does not work, all internet is still blocked
I tried to block all social media for my wifi. So i enabled app control with ssl inspection and i tried both deep inspection and social media inspection. But Insta app is working fine. But all other apps like youtube etc etc are blocked. I is not opening. Can you please share me what can i do to block the insta in android app . Because i tried all yt tutorials, but none of them are working
Goal is to create identity based FW policy. We are looking at using FCT Mobility Agent and FAC Cloud. Trying to wrap my head around the impact in the event of a loss of connectivity anywhere in this path. SSOMA <--> FAC Cloud <--> Fortigate. How long by default does the Fortigate cache the user/ip correlation ? Any ideas ? Don
I have a FortiGate 50E, unlisense, firmware v5.4.1When try setup 2 vlan, vlan10 ip 192.168.10.1/24vlan20 ip 192.168.20.1/24if I enable DHCP on VLan then it wont give ip to any PC but DHCP on port still workAnd no matter how much i try, i cant seam to get Vlan routing to work, i can still route vlan to the internet but vlan to vlan is impossible.I try create vlan via GUI, CLI (dont think this make much different?),config ipv4policy so it allow any type to any any destination, for both way, vlan10 to vlan 20 and vice versaconfig static route to 192.168.10.0/24 interface vlan20 gateway 192.168.10.1 and to 192.168.20.0/24 interface vlan 10 gateway 192.168.20.1I try run "show system route" cmd and all netwok is connect normally "c 192.168.10.1 255.255.255.0 is directy connect"-something like this, I cant get logging to work, I have enabe logging in policy, log security and log everything,I try to ping client from fortinet CLI "exec ping 192.168.10(.20).1(.2)" it wor
hi Team, HA : A-Pmodels : 901G so I connect to the mgmt interface of the fortigate with RJ45 to setup the cluster. everything is going fine I setup the member that I'm connected to to be the primary. after the cluster is up I changed the mgmt interface ip from 192.168.1.99 to an ip of our network 10.189.1.25/29 with command :set ip 10.189.1.25 255.255.255.248 set allowaccess https ping ssh and I also change the ip of my PC that im connected with to the mgmt interface to 10.189.1.26/29 and set the default gateway to 10.189.1.25(also tried without gateway and didnt work) so after I done so the connection was lost and I couldnt connect back. so I ran a ping from my PC and then I ran a debug flow and I only see some multicast DNS traffic from my PC but no ping traffic. then I set the ip of the mgmt interface again but this time I used : set management-ip 10.189.1.25 255.255.255.248 and the access worked again. the problem with th
We have a network topology like below. If we put a traffic shaper of 50 Mbps on Fortigate (Central Site) to limit some traffic (windows update) on site 1 and site 2 and site 1, for examples, in some moments, produces more than 50 Mbps , network is not congested but traffic shaper drops a lot of packets and windows update will fail? Thanks
Hello Team,Referring to:Introduce simplified ZTNA rules within firewall policies | FortiGate / FortiOS 7.4.0 | Fortinet Document Library I found some points that I need to digest regarding the two modes (simple,full) of ZTNA policies: 1- what cases exactly do I need to choose full mode against the simple mode2- in the above doc, quoted: A simple ZTNA policy cannot control access based on the destination interface or the real server’s destination address. I understood the "destination interface" part, but how the full policy controls access based to real destination address? 3- regarding authentication, quoted: Authentication for ZTNA policiesAuthentication remains largely the same between both ZTNA policy configuration modes. You can specify user groups under Source to define the groups in which the access control applies to. However, the underlying authentication schemes and rules must still be in place to direct the traffic to the ZTNA ap
Dear All,, Anyone has faced issue with evaluation license while creating SSL VPN for remote users. I have created lab for understanding functionality SSL VPN using Fortigate evaluation license, have created everything as per the document but unfortunately SSL connection is not getting established. it seems to be limitation of license according to me. I have also tried other VPN that is Ipsec vpn with forticlient using set wizard for remote users but that is also getting.failed. Do let me know is really issue with evaluation license or I am missing something wrong as I have been trying so long period. May be I am wasting time with it. thanks for your right direction answer.
i try it and worked but i shutdown the VM and try again become invalid
Hi I am doing some lab with fortimanager VM on vmware workstationsWhen i want to connect a FGT VM (TRIAL), I got this messages:The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number _______________________________________________FMG config config system globalset enc-algorithm lowset fgfm-ssl-protocol tlsv1.0set oftp-ssl-protocol tlsv1.0set ssl-low-encryption enableset usg enableend__________________FMG-VM # get system statusPlatform Type : FMG-VM64Platform Full Name : FortiManager-VM64Version : v7.2.5-build1574 240313 (GA)Serial Number : FMG-VMXXXXXXBIOS version : 04000002Hostname : FMG-VMMax Number of Admin Domains : 2Max Number of Device Groups : 3Admin Domain Configuration : EnabledFIPS Mode : DisabledHA Mode : Stand AloneBranch Point : 1574Release Version Information
Hello, In the EMS portal you can see the public IP of each registered forticlient user (on or off VPN), it's obviously collected data. Unfortunately the API only retrieves their local network IP address. Is there anyway to fetch the public IP address of a user that is not connected to VPN? Some useful scripting that could be done. I also noticed in FortiGate the endpoints API endpoint seems to have similar data, short of a public IP address.Just curious if anyone knew if this was doable with the tools available via FortiClient EMS. EDIT: Others have added replies and context expanding on my initial request. The idea of ingesting the active public IPs of all FortiClient agents (NOT connected to VPN) into a dynamic object list/group to be used for policies is spot on in what I'd ultimately like to do. There would be real value in having public policies locked down to the active public IP of all employees, provided that dynamic list is updated at a frequent interval. It wo
Hi, our FortiMail operates in gateway mode. When users are logged into their personal quarantine and delete a mail from the inbox a notification pops up telling users that the mail has been moved to trash. However, users do not see a trash folder. I've talked to other users of other FortiMail customers and some have a trash in their personal quarantine. They do not know why though. I explored all clickable UI features within the personal quarantine and also went through the FortiMail documentation but found nothing about this topic. That's why I decided to share this with the community. Any ideas why this is, are highly appreciated. Thank you.
Hello everyone, I have a connection issue with the FortiClient VPN. I am using the Ubuntu 24.10 operating system and have installed the forticlient_vpn_7.4.0.1636_amd64.deb client. The installation has no issues, but when I try to connect using the graphical interface, it stays pending on the connection without being able to establish it. Could you please help me resolve this problem?
Hi All, I am facing a problem that 7.4.6 running Fortigate VM (running on EVE NG) is not adding to the Fortimanager VM (running on VCenter) running 7.6.2. While adding the FGM IP from the fabric connectors in the fortigate VM blow error is prompting " The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager. Could not connect to the FortiManager to retrieve its serial number " Can anyone suggest me a workaround for this ?
Hello to everyone, and thanks to read me. First of all, wanted to say that I wanted to follow this schema: I have an Active Directory Server, cluster Fortigates and an EMS Cloud. My main objective:Permit to remote users (employees working outside our network) with AD integrated laptops to connect to forti SSL-VPN before login, and permits to have all policies loaded at the start of the session.The remote user will turn on its laptop, put its AD credentials to connect to the VPN and will enter to its session to work as it would be inside the network.After adding the AD user in the right AD group, being able automatically to connect to all the permitted ressourses. As described in the schema, I did the connection between EMS Cloud and AD server, using a Windows VM as a AD connector. It permits to retrieve all device laptops from the AD to install the product or adding the users AD in EMS too.Then, I did the connection between the fortigate and EMS Cloud. I thoug
Hi Guys, I Have a problem with SSLVPN.After upgrade Forti OS 7.0.14 and FortiEMS 7.0.11, then i try VPN and successfully,someday later I try again and their status stop at 48% with warning "Credential or SSLVPN configuration is wrong (-7200)".I haven't change anything in Firewall or Policy.Anyone has any idea about this issues.
Hello everyone, I'm a newbie~ Currently, my situation is that the FG connected to an Layer 3 switch. I would like to see the user's PC name or MAC address in the FG logs.From what I understand, since the Layer 3 switch uses IP routing, it doesn't obtain the MAC addresses of devices connected downstream from the switch. I’d like to ask if anyone knows a way to achieve this.
Dear Team, I have been observing since morning at FortiGate forwarding logs one of the websites is getting blocked by the SSL. please have look the image what I have taken. let us know what I do for so that websites should be blocked.
Here's the dealCurrently have 2 101F's in HALots of remote users-Use SSLVPNUsing SAML with AzureAD as idpNext year we're moving to new space. I usually take an opportunity like that to buy new stuff and get it setup at the destination. I'll be keeping an eye any new firewalls. Maybe a G model??From what I read; IPSec can work over 443 (TCP) I would need that due to the amount of travelers/remote people.My question-We have a remote office running a 61F. What I'm thinking is to practice setting up ipsec vpn on this without messing up HQ (where everyone vpn's into).Any suggestions are appreciated.
Hi everyone, I'm not so familiar with FortiSandbox at the moment and it's really hard for me to estimate the scanning settings compared to the resources I have on available on my FortiSandbox. Is there some kind of chart that can guide me with recommended settings depending on the licence and resources I have? I'm asking that because I've recently did a test, I've change the number of url scanned on my FortiMail from 3 to 10 but behind that my FortiSandbox has a URL Depth limit of 3 with URL content limit of 50. If I understand correctly, it can scan up to 10*50*50*50=1 250 000 urls per email. The result was a queue getting longer and my emails got delayed by 20 minutes. Now I went back to 4 URLs on my FortiMail, 3 URL depth and 50 content limit but I don't know if this is the recommended settings for my Sandbox. I have FortiSandbox 1000F with 14 clones. Regards, Lionel
I have downloaded FortiClient VPN from the iOS App Store. However, after connecting to the VPN, I found that the internet is not working. On the other hand, it works fine on the Android platform. I would like to ask if you can help resolve this issue.
Hi all, Using Forticlient IPSec VPN to connect back to office network unable to access network shared Please help. The shared folder is only shared by domain PC. I can ping IP, nslookup and ping hostname of the PC. Thank youRegards,RTuesca
Hi everyone! Where can I check the license information for a FortiAp and a FortiSwitch? both are managed by a FortiGate
We are pleased to announce the latest updates to the FortiSOAR platform, bringing enhanced capabilities and new integrations designed to further empower your security operations. This release introduces several new Solution Packs and Connector updates that will enhance your ability to manage and respond to various security threats more effectively. Among the updates, we have introduced Solution Packs such as the FortiManager ZTP Flow, multiple Outbreak Response packs covering critical vulnerabilities and attacks, as well as an upgrade to the Threat Intel Management pack. These additions are designed to address emerging threats and streamline incident response workflows. In addition, several Connector updates are now available, including enhancements to platforms such as Exchange, Fortinet FortiAppSec Cloud, Google Gemini, and Mandiant Threat Intelligence, among others. These updates offer improved integration, expanded coverage, and more reliable data sources for your sec
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.