Mark a Best Answer
Fortinet Community
Recently active
We have a scenario where an MSSP is facing a critical storage issue and needs an immediate resolution. They have a two-node replica setup and are considering deleting one worker from a shard to restore system functionality.The plan is to remove one worker, migrate the remaining worker to new storage, and then recreate the deleted worker.Would this approach be feasible? Could deleting a worker impact data integrity or overall system functionality? Any guidance on best practices for handling this scenario would be greatly appreciated.Version: 7.1
How to set an expiration date or period for an SSL VPN account? Device is currently running v7.4.6 build2726 (Mature)
Hi Guys, We have two sites connected together but we want to have two guest portals so that we can get a user from each site to approve the requests. Currently it is setup as one guest portal. Any guides or help to achieve this? We are on FortiNAC 7.6.2.0715 (GA) Thanks John
Hi!After on boarding many FortiGates into FortiManager (7.2.8) and using FortiManager's "Find duplicate objects" we see a very large number of duplicate Address objects in the GUI.However, there's no option to produce a report, or even download these out of the GUI. How to do this?Thanks!
Hi all, in a hand full of sites we have got problems with our dyndns connected ipsec sites.These tunnels have to be manually reseted from time to time. Within the logs I can see the tunnel is getting down and our HQ Fortigate tries to connect to the old public IP address.Also shown in the log, the new public IP is trying to initiate a connection to the HQ FG. Seams like the FG is not updating its dns entry for this site. After disable/enable the tunnel the site is up immediately. Anyone got an idea on this? Can´t be the solution to restart a tunnel from time to time. RegardsMarc
When using Teams and sharing my screens all kinds of updates try to occur. ( high bandwidtrh the VPN just drops ) it seems to always want to check for updates. and then with in minutes I'm disconnected, the vpn drops and destroys my ability to use the network at all. I am forced to reboot. Why we use this I do not know. Here is a small sample of the debug level logging. 3/12/2025 11:13:52 AM debug update get_soft_invent(), soft_invent item: 0 1^Microsoft Windows 11 Enterprise Edition#x64#en-US^Microsoft Windows Desktop Runtime - 6.0.36 (x64)#48.144.23186#Microsoft Corporation3/12/2025 11:13:52 AM debug update get_soft_invent(), soft_invent item: 0 1^Microsoft Windows 11 Enterprise Edition#x64#en-US^Microsoft Windows Desktop Runtime - 6.0.36 (x64)#6.0.36.34217#Microsoft Corporation3/12/2025 11:13:52 AM debug update get_soft_invent(), soft_invent item: 0 1^Microsoft Windows 11 Enterprise Edition#x64#en-US^Nmap 7.95#7.95#Nmap Project3/12/2025 11:13:52 AM debug update get_soft_in
Recently upgraded my firewall fleet (about 15 60f's, 2 100f's)We're experiencing a crash of some sort every 2-4 days.Of course a ticket has been opened and they're working it, albeit very very slowly. Pretty disappointed in their lack of urgency and overall continued lack of code quality.The crash debug logs from the console session has:NP6XLITE: __np6xlite_tunmgr_write:61 timeoutNot sure if anyone has seen this or knows anything about this issue ---- we're experiencing a high impact when this crash occurs, of course.
When is EOL and EOSL on Fortigate 1000D device?
Hello, I’m experiencing an issue with FortiNAC-OS 7.2.8.I’ve created a device profiling rule with the following settings:Registration: AutomaticType: WindowsRole: NAC-DefaultRegister as: Device in Host ViewAdd to group: XXXAccess Availability: AlwaysMethods:DHCP Fingerprinting with different custom attributes:Message Type: AnyHost Name: ICT-*Message Type: AnyHost Name: DSKT* However, Windows devices are detected but not properly profiled and registered. For testing purposes, I tried both creating a single custom attribute with Host Name: "ICT-*, DSKT*" and creating multiple rules with a single hostname per rule, but neither approach worked. I have another rule for IP Phones, which is working without any problems. What am I doing wrong? Any suggestions?
I had SAML to Microsoft Entra ID working fine for a little bit here, but then FortiClient started showing "Credential or SSLVPN configuration is wrong. (-7200)" on every connection attempt. SAML works just fine when connecting to the same system over WebVPN, so this does not appear to be an issue with the SAML config. Any suggestions for getting FortiClient to work again?
I have to configure HA in FortiNAC-F ver7.6.2 .I'm sure I do all of steps in documentation but when I reboot there is no HA in the GUI interface can some one help please.https://docs.fortinet.com/document/fortinac-f/7.6.0/high-availability-fortinac-os/760103/step-2-configure
How i can Connect Two Site through vpn in different countries and one country block ipsec VPN if i am usingsite a and site b two public ipor site a public and site b dynamic
Firmwarev7.6.2 build3462 (Feature)ModeNAT I have a FG with the Evaluation License running in a Proxmox VM. There are three interfaces configured: Port3 is the LAN and works fine, Port2 is set to WAN and is connected to Starlink and works fine. Port3 is set to WAN and is connected to Spectrum and no matter what I try, it will not get an IP via DHCP. I can move the modem cable to any other device I have in the building: A tp-link WIFI router, an MSI laptop, a Dell laptop, and they all connect and get an IP without issue. I've tried swapping proxmox interface and VLANs with Starlink, swapping cables with Starlink on the FortiSwitch, I've tried swapping physical ports with Starlink on the FortiSwitch, I've tried swapping the interface with Starlink in the FG, and just now I brought a whole new modem to the game. Nothing has changed. Starlink always comes up and Spectrum fails to connect DHCP. Oh, and I've tried both circuits in and out of SDWAN.Below is the interface...it is
Hi team i have fortianalyzer and i want to alerts of critical severity on mail but i am unable to do the setting in event handler list what is setting we need to do? or other solution is there
Hello,I have an IPSec VPN site-to-client configured on my FortiGate, and I would like users to use the public IP of my WAN configured on the interface.I’ve already created a policy from the VPN interface to the WAN with NAT, setting up an IP pool, as my WAN has a /32 subnet.However, I haven’t been successful with the configuration. Has anyone done this setup and can offer assistance?I’m using FortiOS v7.4.7 on a FortiGate 90G.Thank you!#fortigate
For all the issues we hear, I figured I would post a good story.Pair of 200E gates in HA. Was running 6.4.15, upgraded to 7.4.6.Upgraded per the upgrade path, however the Gate had a small difference in the path than the support site had. So I used the site path, and downloaded the updates and did not use the auto update in the GUI.Each step went well, with a few mins for HA to sync. Verified each step with each Gate for a double check and all was well. Up on 7.4.6, 5 Fortiswitch on a mix of 7.x firmware and all reporting as expected.No major hangups, gave HA time to sync between jumps and all devices were happy. (forced ha sync start on 2 jumps)Just wanted to toss out a happy story for the sub. Not that I have had bad upgrades, but wanted to highlight a good story of a multi line FW upgrade.
How we can deal with asymmetric routing in ADVPN if we have 2 connection from spoke to hub?We often facing issue where spoke can't talk to the hub if traffic in and traffic out using different interface.
When an Android phone uses FortiClient to connect to a VPN, the connection is successfully established but then automatically disconnects after 2 ~ 3 seconds.Do you know a solution, or is there anyone experiencing similar symptoms? forticlient version : 7.2.1.0118 android phone : one ui 5.1 / andriod 13one ui 6.0 / android 14 fortigate debug[13525:root:76f5]allocSSLConn:264 sconn 0x7f30c0541400 (0:root)[13525:root:76f5]SSL state:before/accept initialization (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 read client hello A (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 write server hello A (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 write certificate A (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 write key exchange A (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 write server done A (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 flush data (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 read client certificate A (106.x.x.x)[13525:root:76f5]SSL state:SSLv3 read client key exchange A:syste
Hi everyone,I’m currently looking for the recommended versions of FortiADC and FortiWeb for use in a production environment.Has anyone here had experience with the latest versions of these products and can recommend which ones are stable and secure right now? Are there any specific builds or patches I should be aware of?Looking forward to your responses and advice!Thanks in advance!
I have a Fortigate that has two vdoms (root vdom and OOB vdom). The OOB vdom is connected to the Forti-switch and the Forti-switch is being managed by the OOB vdom Fortigate. The Forti-switch has 3 Vlans and all the ports on the Forti-switch have been used. How can I configure a physical port of the Fortigate so that I can access the three Vlans on the Forti-switch Please help with configuration.
What is CVE-2014-100005? CVE-2014-100005 is a critical vulnerability identified in older D-Link DIR-600 routers. This Cross-Site Request Forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of administrators. By crafting malicious requests, attackers can alter router settings without the administrator’s knowledge, potentially leading to unauthorized account creation or remote management activation. The vulnerability is specifically noted in firmware versions before 2.17b02. How the Vulnerability Works: In the case of D-Link DIR-600 routers, the CSRF vulnerability allows an attacker to send a specially crafted HTTP request to the router's administrative interface, effectively causing the router to perform actions that would normally require administrator-level access. This could include: Changing router settings: For example, modifying network configurations or security settings. Creating unauthorized accounts:
Afternoon, I'm trying to customize the custom message for web filter blocks in FortiClient EMS. At this point, just getting started, I have a couple of questions. First, is it possible to customize the background color to something other than white?Second, when I load a custom logo, it seems that no matter how large I make it it's still tiny. Is there anything I can do about that? Thanks, -Mark
Hello, we have a issue with our FG-VM02V. At the beginning the vm had a evaluation license. A few weeks later we registered a normal license in the asset management portal of the vm. There the status seems to be fine, but the vm itself didnt updated the license status and the vm turned into grace period which will end soon. Later we registered a forticare support contract to the vm and the license status for the support was updated without any problem, but the normal license status of the vm didnt changed. We have already tried to download the license file (.lic) from the asset management portal and upload it to the vm. This was not possible due to a error that a manual upload is not possible. Also we run the cli-command "exec update-now" alone and together with debug commands. We need help to fix this issue.
Hi everyone,I’m encountering a 504 Gateway Timeout error when trying to access a FortiGate firewall through FortiPAM. The error states:Remote server did not respond to the proxy. I’m using the proxy feature in FortiPAM, which listens on port 8080.The FortiGate Web GUI is configured to run on a custom port, and I’ve specified that port in the URL while accessing it through FortiPAM.Has anyone experienced a similar issue or have any suggestions on how to troubleshoot this?Any help would be appreciated!Thanks!
Hi all,I would like to ban some IPs when an DoS attack ocurrs. I'm trying to do that using stitch, and "anomaly logs" trigger action. The problem is that I cannot stablish a count number or filter whith "anomaly logs". I don't want to ban an IP when is detected for first time by my DoS policy. I would like to ban it when it is detected, for example, 10 times during an attack. That is the problem: I can't use event filter or count for anomaly trigger. If I try to create a custom trigger, I cannot find the log ID 0720018432 or similar, to can customize it. Could you help me to create an automation trigger to detect malicious IP during an DoS attack? I need an IP to appear several times and I don't know how to set this counter, so as not to ban it the first time (it could be from someone who doesn't belong to the attack).1-->An IP appears X times in a short time several times with "anomaly event".2-->Foritigate ban IP (quarantine). Is it possible? Than
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.