Mark a Best Answer
Fortinet Community
Recently active
Hello everyone, When generating a DKIM key for multiple FortiMail appliances across different sites, should a unique key be generated for each FortiMail, or can a single key be used for all of them? If it's the second case, how would the other FortiMail appliances obtain the private key? If it's the first case, do I have to upload all public keys on the DNS ? Thank in advanceBest regards,
Hello,We are currently running FortiWeb with WS_OnDemand 7.4.2, build0622 in our production environment on AWS. We would like to upgrade to a more stable and recommended version. Based on recent information, version 7.4.6 appears to be the latest recommended firmware for AWS deployments.Could you please confirm if 7.4.6 is the best choice for a stable production environment, or if there is another version you would recommend?Kind regards,
I have a ClearPass setup with Fortinet products (FortiGate, FortiSwitch, and FortiAP). Goal is to configure wired and wireless authentication with OnGuard health check. Wired authentication with health check is successful with the whole flow being as follows:User is not connected to internet. User has OnGuard installed on Windows PC. User health status is unknown. User connects to ethernet cable and gets authenticated initially but as UNKNOWN health, thus the enforcement policy enforces the UNKNOWN VLAN profile.Agent gets connected to ClearPass OnGuard when in UNKNOWN VLAN and performs the health check required. User in this example is healthy. Thus it will send to the ClearPass that the user is healthy. The health check policy is hit and it enforces a CoA bounce port message to the FortiSwitch port the user is connected to.The user gets disconnected for a few seconds then reconnects with the new information that the PC is healthy, thus it gets its IP from the HEALTHY VLAN.We want to r
We are planning to utilize a RADIUS server for LDAP and OTP authentication. Our objective is to send the Username, Password, and OTP in a single request. To achieve this, we need to create a Custom Vendor-Specific Attribute (VSA) in the FortiGate firewall. This will enable us to include the OTP along with the Username and Password for authentication purposes. Could you please provide the detailed procedure for creating a Custom VSA in the FortiGate firewall? FortiGate
Hi my fortiwan https certificate has expired, so I need to regenerate onebut I can't find a way from fortinet documentif regenerate self-sign, service will affect? Thanks.
Hi All, I have a question regarding a FortiSwitch managed by FortiLink. We have two data centers (DC-A, DC-B), each with a standalone FortiGate. Under each FortiGate, there are two 1048E switches serving the servers. There is a dark fiber link between the two data centers, which connects the FortiSwitches.Since there is L2 connectivity between the two DCs, I encountered an issue where the FortiSwitches from DC-B also appear on the FortiGate in DC-A (and vica-versa), prompting me to authorize them. Currently, I have set them to "Reject," but I'm not sure if this is the official solution or if there is a better approach.Could you provide guidance on the best practice for this scenario?
Hello, I would like to install a Fortigate 200G with active/passive HA.That's mean that only one Firewall is running, the second, just in case of problem on the primary. Our reseller said that's it's required to have both licences and maintenance same on both firewalls.Is that's correct ? Thank you.
Hi guys,I need some assistance in clarifying some of the information I'm seeing in log 99 from my fortiproxy, particularly the rcvdbytes and sentbytes.Question 1: Does the received bytes refer to the amount of bytes received by the fortiproxy from user or vice versa?Question 2: Does the sent bytes refer to the amount of bytes sent by user to the dest or vice versa?Question 3: Does the HTTP method or any other telemetry within the rawlogs that may affect the order of how we see the bytes?This is crucial because it allows me to understand if there are potential malicious exfiltration happening in my environment.Thanks!
I have challenge concerning the setup diagram provided below. In this diagram, VLAN 30 is designated as the out-of-band (OOB) management VLAN, with the corresponding OOB management network IP address being 192.168.30.0/24. Each device intended for management via the OOB network is connected to the management VLAN ports of the Forti-switch through their respective physical management ports, as illustrated in the diagram. My objective is to manage the Fortigate firewall B using its IP address, 192.168.30.10, which is configured on the physical management port. In pursuit of this objective, I attempted to configure the static route outlined below. However, I encountered an issue where the command SET DEVICE MGMT was not accepted, even after I had removed the management port from being designated as a dedicated port. Could you please advise on the most effective method to achieve my goal of managing the Fortigate firewall B through its management port? config router staticedit 12set d
AWS EC22 is running Fortigate 7.2 on vCPU, and the license is using 2 vCPU.Display 1/250% of allotted vCPUs after license change.I'm using 2vCPU, is there a reason why it only shows up as 1?Can't I get them to use both as basic?
I've setup ADVPN using BGP on loopback design with SDWAN. Traffic flows and failover to another link when when it disconnected on all devices. Right now I have 1 hub and 2 spoke. I can steer traffic from spoke 1 out the correct interface - but the ADVPN shortcut is sending traffic into a different interface on spoke 1. A practical example - I would like to send all backup traffic out our second ISP - WAN2 on spoke1. This works no issues. The traffic however ends up coming in on WAN1 on spoke2. This would normally be fine - except when it comes to traffic like an off-site backup I would prefer it not to be on our primary link.Is it possible to steer traffic to take a certain path if using BGP on loopback - I believe this is possible with BGP per overlay but don't want to invest a significant chunk of time on that design if what I'm trying to accomplish is possible with the loopback method. I am also waiting for a call with Fortinet support but hoping to get so
For some quick background, I'm trying to establish IPsec VPN tunnels with a fleet of transit buses to allow access to some on-prem servers at our headquarters. Each bus has a non-FortiGate cellular router using the same 192.168.x.0/24 internal subnet. Equivalent devices on each bus use the same IP address from that subnet (Device A on every bus is 192.168.x.100). To overcome the issue with 150 or so tunnels all using the same 192.168.x.0/24 remote subnet, someone at FortiNet suggested I use VRFs to isolate each of the tunnels, and that seems like a workable solution. Traffic comes into the VRF from the IPsec tunnel and as it passes through the VRF it is SNATed to a unique 10.x network. It can then flow from the VRF across a VDOM link into our HQ internal network to the servers it needs to reach. Yes, doing it with VDOMs would potentially be better, but I can't afford the licensing nor the hardware it would take to do that. I've got the IPse
What is the impact of implementing SAML Authentication for Access to Fortigate Devices?
I have installed the latest VPN client from https://links.fortinet.com/forticlient/win/vpnagent After installation accomplishied, I promptly noticed the lack of the tray icon (that indeed arise on other Win10-22H2 Win11-23H2 installations). Anyway I tried launch the client console configured and saved VPN settings according to my firm's guidelines (SSL-VPN on custom port).Unlike the other OSs mentioned above, the client remains stuck on the connection mask without any status/progress expected (indeed the client doesn't connect). I have already tried the solutions proposed herein, but without any success:https://community.fortinet.com/t5/Support-Forum/FortiClient-VPN-only-with-Windows-11-24H2-issue/td-p/348662 https://windowsreport.com/windows-11-forticlient-vpn-not-working/
Planning on doing some route-map and prefix-list renaming. When testing i didn't see any impact when i just create new routing objects with the same content but different names. When i then change them for example at router bgp route-map-in or out it shouldn't cause any interruptions, might have to do a execute router clear bgp ip x.x.x.x soft though. Anyone with different experience?
Yes, I know that there have been many posts about this, but I still don't get it how in 2025 there is no support for Windows on Arm. The feature has been requested since like 2019, and it becomes a lot more pressing nowadays with the success of the Qualcomm-powered Windows laptops. All I see is this post getting "updated" (i.e., changing the date) https://community.fortinet.com/t5/FortiClient/Technical-Tip-FortiClient-Support-for-ARM-Architecture/ta-p/248361 to remind everyone that there is no support for Windows on Arm. We urgently need this at work. At least release a beta or something. Impossible to believe that, after so many years, they don't even have something close to a beta.
Was searching how to set up for a small network/lab and came across a company called Smallstep that provides free server and certificate services for small networks. They also offer corporate and enterprise solutions. Does anyone know if they are a legitimate and secure source for this? I had also read that setting up your WPA3 radius network using EAPS could be done somehow without using certificates but I can't find any material on this. Also would this usually require a static IP from my ISP? Can anyone direct me to relevant resources?
I noticed a problem. When the updated version is the same (31.962 at the time of posting), the signatures under the v7.2.10 build1706 (Mature) version are much less than the total signatures displayed on Fortiguard, only 12,346. On the 0S6.2.16 system, it is 18,861, which is close to the total number of entries, and on another OS7.4 device, it is also close to the total number of entries. I have followed the tutorial to turn on extended signatures and set exclude-signatures to none.Will this affect Fortigate's security features?Update record query:Intrusion Prevention Service | FortiGuard Labs
Here is the overall architecture200F(X3 and X4) <->(port 23 and 24) T1024E <--> 424E <--> 231GFirmware: 200F (7.4.4), T1024E (7.3.4), 424E POE (7.3.4) The issue is between the 200f and T1024E. The design was working great until I started working with the fortinet engineer on the 231G wifi connection issues. The engineer disable cap-wap offload and since then the switch randomly disables the ports connected to the fortigate (fortiswitch port 23 and 24) which completely brings down the network. What it feels like is happening is a network loop which locks up the switch but I am guessing here because that is just what it looks like when its happening. A reboot of the T1024E fixes the issue. After back to back outages I disabled capwap offload and the network stabilized. My plan is to bring back the customers old switches to stabilize the network and get the fortiswitch setup downstream from their switches until I find a root cause. I will set it up as a standal
Recently upgraded my firewall fleet (about 15 60f's, 2 100f's)We're experiencing a crash of some sort every 2-4 days.Of course a ticket has been opened and they're working it, albeit very very slowly. Pretty disappointed in their lack of urgency and overall continued lack of code quality.The crash debug logs from the console session has:NP6XLITE: __np6xlite_tunmgr_write:61 timeoutNot sure if anyone has seen this or knows anything about this issue ---- we're experiencing a high impact when this crash occurs, of course.
I am in process of downgrading a firmware of 124E however encountering following error when trying to do so: ""Downgrade WarningSome incompatible administrator accounts were found with FortiSwitchOS versions<7.0.0. if desired, convert incompatible accounts using the "execute system admin account-convert <admin>" commandUnconverted accounts will not be able to log in with FortiSwitchOS versions < 7.0.0."" I executed the the command multiple times then it prompts for New Password then I am unable to type anything in CLI. Current BIOS Version: 04000008Firmware Version: v7.2.5.build0453.230707 (GA) Trying to downgrade to: FSW_124E-v7-build0444-FORTINET.out
Hello everyone,I have noticed that there is a redundant entry in the Administration Guide (https://docs.fortinet.com/document/fortigate/7.4.7/administration-guide/443323/dialup-ipsec-vpn-with-certificate-authentication). It appears that the subject field of the certificate can be verified in two ways: once with "set subject" and once with "set cn" along with "set cn-type". However, "set cn" and "set cn-type" can only be configured via the CLI.Is there a specific reason for this redundancy?
Hi,Don't want to start with the boring stuff, it's below.I have a FortiGate FG-120G-BDL-950-12 with FC-10-F120G-131-02-12 what will replace a NSE-3000 (only) all other switches AP's remain Cambium.Is there a comprehensive detailed design, implementation guide available what is fairly recent and up to date.Recently tasked to replace a NSE-3000 router with something capable of BGP and have at least 3 SFP+ port, it was a long and slow process navigating through the sales team to acquire the correct hardware and licensing for it as they just wanted to sale the most expensive product they had in the catalogue :rolling_on_the_floor_laughing:I have no experience deploying Fortinet product but have managing 3x F40 & F60 for over a year, most of my knowledge of FortiGate product is from experimenting, self paced learning portal and web sources and their paid support service.I have heard in one of my conversation with the sales team from FN that there is implementation
greetings all,I created two SLAs, they have the same settings (same interface participants, same SLA target, same link status metrics) but only with different detect server (probing target). SLA 1 probing 10.74.a,b, SLA 2 probing 172.29.x.y. And, I added the two SLA under the same SD-WAN rule, which is with lowest cost (SLA)the question is , what is the Boolean logic here? Let's say, 15 consecutive times of probing failure occurs to either one of the two (1 out of 2) SLAs , will the related interface become inactive? and will the SD-WAN switch to the secondary interface (the interface with higher cost)?AND, what about if I add the two probing detect servers to the same SLA? and only use the one SLA under the SD-WAN rule?Thanks,Sean
Dear All, I am trying to reset fortigate 60F because i forget the password and using reset pin to reset but cannot can any one tell me easy way how to reset fortigate using reset button without console.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.