Mark a Best Answer
Fortinet Community
Recently active
I'm trying to block iMessage for all iPhone users connecting to FortiAP. We tested both deep inspection and certificate inspection in proxy mode, but it didn’t work. None of the 2000 iPhone users have the Fortinet certificate installed. For testing, we installed FortiNet certificate in one test device, but iMessage was still not blocked.How can we effectively block iMessage for all iPhone users?
HI guys, Due to a ISP change my local Fortimanger is no longer reachable with the old address. I want to deploy a new FGT to my Fortimanager, but when I try this, the old IP is listed. Where can I change the IP to the new one? Best regardsVolker
Hi,i have disconection While I put my cluster. But while I put my fortigate on standolone, the issue disapear…an idée ? Sorry for my english I am french ! thank you
Hello Experts, Let us assume there is a SD-WAN aggregation with WAN-A and WAN-B.Can we have a configuration so that only WAN-A is usedwhen WAN-B bandwidth is less than a specific speed (eg. < 1Mbps)and WAN-B is automatically taking out from the aggregation? Best regards,
Recently upgraded my firewall fleet (about 15 60f's, 2 100f's)We're experiencing a crash of some sort every 2-4 days.Of course a ticket has been opened and they're working it, albeit very very slowly. Pretty disappointed in their lack of urgency and overall continued lack of code quality.The crash debug logs from the console session has:NP6XLITE: __np6xlite_tunmgr_write:61 timeoutNot sure if anyone has seen this or knows anything about this issue ---- we're experiencing a high impact when this crash occurs, of course.
Fortigate ver. 7.4.xFortimail ver 7.6.xFortimail is considered unauthorized in security fabric, but there is no option to authorize it.
I'm attempting to set up Azure AD authentication and I have followed the instructions at https://yura.stryi.com/en/2021-03-05/fortigate-ssl-vpn-azure-mfa/ to the letter up until the point where it talks about "FortiClient EMS setup" as AFAIK we don't have that and I can't find any reference to it. Regardless it seems to be talking to the azure app as when I login as an azure user I see in the logs[fsv_found_saml_server_name_from_auth_lst:123] Found SAML server [azure-saml] in group [ALM-Staff]but I then getlogin_failed:391 user[username@domain.com],auth_type=1 failed [sslvpn_login_permission_denied]Now ALM-Staff is a local user group that can already login to the VPN (which would've been nice to know when I was setting up the groups). Following the guide I set up azure-saml and SAML_AZ_ALL using something like config user saml edit "azure-saml" set cert "Fortinet_Factory" set entity-id "https://example-company.com:10443/remote/saml/metadata/"
Hello,Is it possible to restrict VIP objects to only SSLVPN users with split tunnelling enabled? I used the following KB article but it did not seem to work. The FortiGate we are using is 7.2. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-access-a-VIP-from-a-SSL-VPN-tunnel-mode/ta-p/196738 The VIP uses a public IP address to map to an internal IP address.
Hi Guys,Have everyone ever tried to config ADVPN with OSPF before? I am planning deploy ADVPN with OSPF between HQ and Brachs on next month. I want to do a lab with 1 Hub and 2 Spoke fisrt and follow the admin guide document, I have configured VPN and OSPF on all FG devices but the result is not as expected. All spoke can see the route from other, but the route always show the nexthop is Hub's IP. It means that spokes cannot establish neighbor together and cannot forward traffic directly. + HERE IS CONFIGURATION: ******* VPN config*********- HUB:config vpn ipsec phase1-interface edit "Hub2Spokes" set type dynamic set interface "port1" set peertype any set net-device enable set proposal des-md5 des-sha1 set add-route disable set dpd on-idle set auto-discovery-sender enable set psksecret ENC nsxqpsDPxjEVIkzt0I9tuJiVs+O2EesJODHPR21JdhMCbJNAxRwCNHmt4r9e7cBAdTGpRTbhegAA6yiVlgMaV0cNrP80m/7cVY2OdvRJWanFKO0yqnDR/ifXfT8NUo6UiljRzTkq6+fgD3+RCH8Bvw0Fy5rVu2unDl+hjh0bmmaFF70myq9
Hi Team,I need to access my client’s RDP system through a VPN connection. The client has provided VPN access, and I can successfully connect. However, when I connect to the VPN and attempt to access the remote desktop, the RDP session disconnects after a few minutes.Interestingly, when I use my home internet, the VPN connection remains stable, and I can access the remote desktop without any issues. This problem occurs only when I connect from my office network, which is behind a FortiGate firewall.My office LAN IP address is 192.168.1.100. After connecting to the client’s VPN, my assigned VPN local IP address is 10.1.0.15, and the remote desktop IP is 10.1.0.20.Could someone help me troubleshoot and resolve this issue?
Quick question. Is it possible to use a SAAS SSO provider such as Okta, MS etc and using SAML? This is our current setup for VPN, but there seems to be a hitch when you need to involve Authentication rules because of the interface and protocol preference. Is the LDAP portion required for this? And not just relying upon the SP user data base?
Hello :), I've previously had an offline CA setup and used it to sign certificate request for Fortigate. It was an easy process overall. However, I now have an enterprise CA. A new folder under my CA was created as "Certificate Template". I understand it's utilization and whatnot, but my troubles come with accepting Fortigate CSRs. I immediately get shot an error "Denied by Policy Module 0x80094801, the request does not contain a certificate template extension or the CertificateTemplate request attribute."That's fine and dandy but I can't seem to be able to add that attribute anywhere before generating the CSR. I've looked online and I'm instructed with a CMD process that applies the Template to use, but I have the upcoming project of signing more than 80 of these certificates. I'd appreciate the guidance on making this as simple as it was with my offline root CA :)
Should the certificates be imported into each firewall and then applied from Fortimanager to the cluster?
Hi,We have a FortiGate Active/Passive HA deployment in Azure, deployed across availability zones in the North Europe region.Currently, the following Azure VMs utilize public IP addresses based in the Ireland (North Europe) region for integration with a third-party vendor:- TEMPAZYHSCRPSC01- TEMPAZYHSCRSB01- TEMPAZYHSCRSQL01- TEMPAZYHSCRSQL02- TEMPAZYHSCRWEB01 *(this VM has its own separate public IP)*We have a vendor that has implemented geographical restrictions on their network, requiring public IP addresses originating from England (UK South).They have requested that we change the public IP addresses used by these VMs accordingly.Any changes to public IP addresses must include corresponding updates to all associated NAT and firewall rules within the FortiGate.## Technical Limitation> Azure currently restricts associating a public IP address from a different region (UK South) directly to an external load balancer deployed in the North Europe region.> This prevents us from simpl
I work for an MSP, we don't use Fortinet but one of our clients do business with a client that does. When they attempt to access their website to submit invoices, they aren't able to access this site. I was able to track it down to the IP address of my client being blocked. When we asked this company about this, we were told that we needed to reach out to Fortinet to get the IP removed from the Malicious Server List. Is there anyone here that can point me in the right direction to get this taken care of? I called support, and they told me to post here.
Hello, For FortiSwitch managed by FortiGate (FortiLink) and 802.1x (wired connection-Fortiswitch):- Which parameter configures the radius authentication timeout? In case of high latency, how long does it take for an authentication to fail with a timeout?- Which parameter configures the number of authentication attempts before the radius timeout? Thanks,
Switching fromcase1tocase2and then back tocase1results in an issue where obtaining an IP address fails, and even manually configuring the IP address does not allow normal network access. Changing the MAC address can immediately resolve the issue, or waiting approximately 5 minutes or restarting the Fortigate can also resolve it. This issue does not occur when bypassing the Fortigate.Below is my Debug Flow result:Packet Trace #8902025/3/18 20:25vd-root:0 received a packet(proto=17, 0.0.0.0:68->255.255.255.255:67) tun_id=0.0.0.0 from internal4. Packet Trace #8902025/3/18 20:25allocate a new session-0042a27f Packet Trace #8902025/3/18 20:25in-[internal4], out-[] Packet Trace #8902025/3/18 20:25len=0 Packet Trace #8902025/3/18 20:25result: skb_flags-06000000, vid-0, ret-no-match, act-accept, flag-00000000 Packet Trace #8902025/3/18 20:25in-[internal4], out-[internal3], skb_flags-06000000, vi
Hello. I am a network engineer working in an on-premises environment. There are intermittent slow internet issues, but it is not due to CPU or memory overload on the switch devices. When I monitored the situation using the diagnose switch physical-ports datarate command, I noticed a sudden increase in usage on both the TX and RX sides. What could be causing this issue? Also, are there other ways to check this in FortiGate or via CLI?
Hi, I am after some guidance on anyone who has setup a DMZ Server to utilise Google re-CAPTCHA. The DMZ area is restricted for outbound Internet access and any server that requires a service is locked down to only what it needs. What is the best action to allow a DMZ server to Google re-CAPTCHA on a Fortigate 600F Firewall? Info. Google apparently uses https://www.google.com/recaptcha/api/siteverify & https://www.google.com/recaptcha/api.js DNS to resolve to google.com The odd guide recommends allowing access to the following subnets but this equates to around 212,992 IP Addresses.The reCAPTCHA servers can be located on any IP address owned by Google. While we can not provide official support for IP Address-based ACLs, Google's public IP space can be found by issuing the following command from a Linux/Unix box:dig -t TXT _netblocks.google.comThe result right now is:ip4:216.239.32.0/19 ip4:64.233.160.0/19 ip4:66.
Hi, I have a simple setup right now, with a Fortigate 600E on Floor 2, and a Cisco SG350 10G besides this, and I also have another Cisco SG350 10G on Floor 1. Each floor also have a storage server.Workstations from Floor 1 and Floor 2 are connected to the respective floor Cisco swich, and the Fortigate has X1 interface for internet in, and x2 interface to connect to the Floor 2 switch. The Fortigate is the router and dhcp server. But now the bosses want Floor 1 and Floor 2 to be completely separate, and only share the x1 internet connection (which should be also be filtered to only allow certain internet destinations) but worksations from Floor 1 cannot "see" workstations from Floor 2, and viceversa. Can you guide me how to setup something like that, preferably from the GUI of the Fortigate 600E ?I assume I will setup different VLAN's on each switch, with Trunk configured to communicate between them, but then what should I setup on the Fortigate ? Thank you
Hi,I seem to remember that I ones saw a DSL tranceiver for fortinet. when you have a DSL and not like a 60E-DSL but you use an EDGE-switch to split the connection to 2 firewall. But I can't seem to find the DSL tranceiver anywhere. Anybody knows some documentation about it?
I have FortiAP FP431G running v7.4-build0591, which is managed by a FortiGate 1101E running v7.0.13 build0566 and I am unable to get the 6 GHz network working. The security mode for the SSID is set to WPA3 SAE. When the platform mode is set to Dual 5G the SSID broadcasts, I get connectivity via Dual 5GHz and 2.4 GHz. However, when I set to Single 5G the 6GHz radio does not broadcast nor the 2.4GHz or 5GHz. Any advice on how to get this configured properly?
How to enable MFA for Fortigate Admin Users?
Hello everyoneexample i have three spoke under same advpn, but i wanna isolate spoke A from other spoke B & C, can i do that ?
Good day, This is URGENT.I am seeing “No license” for features Virus Outbreak & Antispam. These features were always in the green during my 2024 subscription and even after renewal license in January 2025. Last time I checked, even last week, these 2 features were in the green/licensed. I Logged on this morning and now realizing this. What is the cause for this change? Contact Fortinet support or something i can do from cli etc.? This is very strange. HELP!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.