Mark a Best Answer
Fortinet Community
Recently active
Can I just flip the switch on IPSec XAUTH² to 'inherit from policy' and use the same rules as SSL-VPN, where you have to specify a Source and User/Group? Last time I tried this, the FortiGate acted as a MITM for IPSec users and redirected HTTPS³ to its own IP, causing a certificate error. I had to roll back without investigating further. FortiGate 200F 7.2.11² XAUTH is set to a group containing a remote group which is a radius of our 2FA token.³Split Tunnel, so not all HTTPS requests, only the ones where a FW rule was hit.
Hi Team, There are certain users facing random wireless connection on the FortiAPs. For an example two users facing the same problem and they are connected to the same AP. Do you know what is causing this problem? Here is the following error message: Action: client-disconnected-by-wtpReason: "Disassociated due to an excessive number of frames requiring acknowledgment, which are not acknowledged because of AP transmissions and/or poor channel conditions." Model: FAP-231FSoftware: 7.2.4-build0395
Hi, I am trying to setup Survivability branch with no luck:I have Main FortiVoice 5000F, and FortiVoice LSG unit with different models in branches, among them I have FVE500F, both have version v7.0.5(GA), build232, 2024.09.19.All My FortiFone 380B are registered to FortiVoice 5000F.I following up the tasks listed in below link in order, to make the survivable branch works with no luck:https://docs.fortinet.com/document/fortivoice-enterprise/7.0.5/fortivoice-local-survivable-gateway-deployment-guide/119483/deployment as below:1.Change the deployment mode from PBX to survivability branch on the FortiVoice LSG unit2. Add or import branch extensions to the primary FortiVoice phone system at the main office.3. Add a survivability branch to the FortiVoice phone system at the main office, with Management mode Partially Managed.4. Apply the branch configuration from the main office FortiVoice phone system to the FortiVoice LSG unit at t
Setup a Fortigate 60E with the SSL-VPN and it works fine for most users but one user is having a permission denied (-455) error which I cannot work out what is wrong. The password is correct, 2FA code on Forticlient has been setup correctly (twice now to confirm). It was working yesterday fine but the user tested today and it has this issue. I tried logging in with a different user on that device and it works so its user related but cannot work out what it is. The logs show little info other than SSL VPN exit error so looking for opinions?
Hi Fortinet Team, We are trying to bring up Dial-up vpn tunnel between FortiSASE POPs and Fortigate SPA Hub. Fortigate SPA Hub BGP neighbor range is 172.31.2.0/24. Fortigate SPA Hub loopback ip is 172.31.2.1/32Spoke ip is 172.31.2.2/32But when we assigning BGP Router ID Subnet is 172.31.2.0/24. FortiSASE POPs are getting assigned with 172.31.2.1/32 (Primary POP) and 172.31.2.2/32 (Secondar POP), but those IPs are assigned in our SD-WAN SPA Hub and spoke, due to that BGP is not coming up. We referred this FortiSASE POP to FortiGate SPA Hub BGP co... - Fortinet Community still facing the issue. Expecting clear recommended config and config #Fortisase Thanks,Ajay M
Hi Guys, Can't connect FGT (ver:6.0.5) to FAZ (ver: 6.2.1 FortiAnalyzer), connectivity test fails; FGT been added to FAZ devices;exec log fortianalyzer test-connectivity Failed to get FAZ's status. SSL error. (-3) Capture shows that FAZ sending RST back to FGT: 66.345323 port10 out 172.16.102.248.13765 -> 172.16.102.247.541: syn 1195392681 66.345952 port10 in 172.16.102.247.541 -> 172.16.102.248.13765: syn 1231566839 ack 1195392682 66.346003 port10 out 172.16.102.248.13765 -> 172.16.102.247.541: ack 1231566840 66.346728 port10 out 172.16.102.248.13765 -> 172.16.102.247.541: psh 1195392682 ack 1231566840 66.346857 port10 in 172.16.102.247.541 -> 172.16.102.248.13765: psh 1231566840 ack 1195392682 66.346885 port10 out 172.16.102.248.13765 -> 172.16.102.247.541: ack 1231567207 66.346990 port10 in 172.16.102.247.541 -> 172.16.102.248.13765: ack 1195392843 66.347044 port10 out 172.16.102.248.13765 -> 172.16.102.247.541: psh 1195392843 ack 12315672
I have two 80F fortigates that i am trying to lab vxlan on for production. One system is on 7.2.4 and the other is on 7.2.2. Following the documentation it says to add the vlan interface and the vxlan interface to the switch for the last step. On the 7.2.2 version it has the vlan system interfaces available to add to the switch. These are identical configs on each side I have them set up as policy based and vlan switch mnode. Not sure if this is a bug, but I am using this guide to set up the vxlan
HelloAfter pentests we have issue about showing SSLVPN webpage. I need use SSLVPN only in tunnel mode (this is not problem), but without showing any page in browser. I looked on cli and gui and can`t still found any solution, how disable web page, but still have actvite tunnel mode.Do you have any idea?Thank you
I have a Fortigate F100 with rules in place for the management address of my company's UPS. One policy allows SMTP traffic from that address to our mil server. The other allows DNS traffic from that address, nothing else. I'd like to log any other traffic from the address in question that doesn't match either of these two rules; what's the simplest way to configure such a policy? Just clone the 'UPS Management Address to DNS' rule, set it to DENY instead of ACCEPT, choose every service other than DNS, and hit the log option?
Hello, My fortigate has 2 IPs: 192.168.1.1/24 and 192.168.2.1/24 Clients are set up in these two different subnets with their corresponding gateway (192.168.1.1 and 192.168.2.1).How can I isolate these 2 subnets to block traffic between them? I know it's not the proper way to isolate subnets but I need it for now. Thank you
Hello,In EMS I configured a FortiClient installer, and generated a link to users can connect and download the forticlient installer.For example:https://link.domain.com:10443/installers/Default/WIN-INSTALL_7.2.8 It works but when users go to this link it presents a warning in the browser because the cert in self-signed(not trusted by browsers).Where is in the EMS that I can change this certificate? I have already a valid cert uploaded to the EMS but I do not know where to apply it for this.. Thank you.Regards
Hello guys, im trying to find a solution in order to block malicious ip automatically via an api solution or something else. Does anyone ever done something like this? What i am thinking is to create an external connection an push an api from there but i am not an expert in terms of api stuff and will take some time to figure out things. If anyone ever done something similar in a more easily way please share your thoughtsAll help appreciated.
Hi, after playing around with ZTNA, some things are not clear to me and maybe, someone has the same struggles and / or "caps" in the head. a) To reach out a certificate based authentication and to remove the VPN gateway, you have to work with full ZTNA servers which than, the Fortigate acts like a proxy for. What I am missing; you can do a kind of load balancing with the real servers behind a HTTPS ZTNA server, but there is no option to do a health check like you could do on a "normal" virtual server. Also, it would be interestesting, if real SSL offloading works and deep inspection is done in a correct manner, so IDP/IDS and all traffic is inspected well and no signifcant security risk will raise here. Same with encrypted traffic, like SSH over a TCP tunnel. b) The most - maybe stupid - issue I ran with the following issue:- Let´s imagine you have a service like a git repository server on your site, behind a Fortigate. You can protect it using ZTNA, but you also m
Hello,Is posible to intergrate FAC to security Fabric? Is there a link you can point?We have a couple of FGTs ,FAZ and want to add a new FAC to the sec fabric...I did not find this info. thank youregards.
hello all, i have 6 floors in a company , each floor has 2 or 3 edge switches and each office in the floor has a small tp-link switch (5port) that compine the PCs, and this small switch connected to the edge and all floors connected to two core switches working as MCLAG and all the switches are managed by fortigate.i have 3 connection connected direct to the fortigate (ADSL , MPLS , Leased Line).on the fortigate i have configured a vlan for each floor , when i enable these vlans and assign them to each floor i found a big packet loss in the network but when i work with one vlan for all floors all thing work fine with no isuue.can anyone help with this issue?
hi,i recently encountered a network issue and found out the subnet mask was wrong (/32) and it should be a /28 instead.i suspect i've overlooked the subnet mask 255.255.255.255 it auto created.is there a way to disable the CIDR subnet mask auto fill in FMG? i fear i might make the same mistake again in the future.
Hello everyone,I'm not sure if I'll get any help on this topic here, but I'll give it a try anyway.We primarily use FortiClient VPN to establish a VPN connection to our Fortigate via IPsec using SAML.Some employees who do not work in the company, but are mainly in the home office or work on the road, have the Microsoft Global Secure Access Client installed on their Windows devices.With the background of tunneling the Microsoft365 connections and web connections via the EntraID GSA without FortiClient VPN.https://learn.microsoft.com/en-us/entra/global-secure-access/overview-what-is-global-secure-accessIn exceptional cases, however, these employees may still require an IPsec VPN connection in order to access various VLANs behind the Fortigate.The problem is as follows. The employee can connect to the FortiClient VPN, but the connection is terminated after approx. 10 seconds. Nothing can be seen in the FortiClient VPN for incoming traffic.The FortiClient VPN log files there is nothing use
Although my SSO credentials work fine to connect to Forticlient (7.2.5.1053) from my Win11 24H2 laptop, when I try using the same credentials on a Windows 365 24H2 (with Forticlient 7.2.5.1053) machine, it gets to about 48% and then gives me a Permission Denied error.I'm not being prompted for MFA on the Windows 365 PC so am I missing something there?Can anyone shed any light on why this may be?Many Thanks,Steve
Hello All,while pinging 8.8.8.8 from lan source in sdwan its not pinging, but no issue in traffic of internet and intranet what could be the reason logsfrom Lan source its not pingingexecute ping-options source 110.18.8.254 # execute ping 8.8.8.8PING 8.8.8.8 (8.8.8.8): 56 data bytes --- 8.8.8.8 ping statistics ---5 packets transmitted, 0 packets received, 100% packet loss without souce its pinginging execute ping 8.8.8.8PING 8.8.8.8 (8.8.8.8): 56 data bytes64 bytes from 8.8.8.8: icmp_seq=0 ttl=118 time=26.5 ms64 bytes from 8.8.8.8: icmp_seq=1 ttl=118 time=27.0 ms64 bytes from 8.8.8.8: icmp_seq=2 ttl=118 time=26.2 ms64 bytes from 8.8.8.8: icmp_seq=3 ttl=118 time=29.3 ms64 bytes from 8.8.8.8: icmp_seq=4 ttl=118 time=38.9 ms --- 8.8.8.8 ping statistics ---5 packets transmitted, 5 packets received, 0% packet lossround-trip min/avg/max = 26.2/29.5/38.9 ms
Have a user every week, that submits a ticket for being unable to connect to VPN. I connect with them and the configured connection appears to still be there, but if you "Edit This Connection" there is nothing there, only the name. It removes the Remote Gateway, Description and custom port. If I try to add it back, it fails to do so. I have to complete delete that connection and readd. It seems like every week when they work from home this happens. What I have done:Looked through logs, updated software, uninstalled/installed, restarted, tried not saving username/pw, disabling the auto connect and always up. It's still happening. Any tips on how to get this resolved so I don't do the same ticket every week, would be greatly appreciated. Thank you!
I have a very interesting problem that I have not been able to figure out yet. I've searched the internet and haven't found anything with this exact problem. I have a FortiWiFi 40F-3G4G that I upgraded all the way to 7.6.1 build3457 before I did any configuration on the device. I finally got the Sandbox working with FortiCloud, but I noticed that when I try to configure the antivirus policy, there are no entries listed in the GUI for Inspected Protocols. Since they aren't listed, it will not let me proceed to turn on or off any settings or even give it a name. Has anyone else seen this before?
I have been working through the process of connecting our Azure AD domain to our Forticlient EMS Cloud and Fortigate to allow for using windows creds to authenticate to VPN as well as enable autoconnect when off fabric.I followed the steps in the fortinet documentation and am able to attempt to sign into the VPN at my windows login screen but the connection times out. Using a Debug to see if there is traffic reaching the fortigate I see that my authentication request is hitting the fortigate but not being forwarded on to Entra. I have a ticket submitted with forticare but wanted to see if anyone else experienced the same thing
Hi! All KBs and documentation (except very early v5.0 Handbook) documents "vlanforward" field as being functional ONLY in VDOM configured in Transparent Opmode. However, this field is allowed to be set (using CLI/GUI/FortiManager) on a vlan-type subinterface whose VDOM is configured in NAT/Routed mode. Normally, if a field is not appropriate in a particular context, FortiOS syntax disallows it to be set. So, is ability to set "vlanforward" field in subinterface with "vdom" field set to VDOM configured in NAT/Routed mode - a bug? Thanks!
greetings friend,I created an IPsec tunnel named OL_INET_AZ, and it was added to an SD-WAN zone. but there is NO SD-WAN rule using this IPsec tunnel as the outgoing interface. there are 3 static routes:S 10.74.0.0/15 [10/0] via 1.2.3.4, port17, [1/0] [10/0] via OL_INET_SKO tunnel a.b.c.d, [20/0]S 10.75.0.0/23 [10/0] via OL_INET_AZ tunnel v.w.x.y, [1/0]Now my LAN network want to talk to 10.75.1.68 via OL_INET_AZ. From the routing table 10.75.0.0/23 via OL_INET_AZ is the best route as it is most specific. When I ping 10.75.1.68 from the fortigate itself, the traffic is going through OL_INET_AZ, but if I ping from a LAN host behind the Fortigate (and behind the core switch) , it will hit the SD-WAN rule with destination 10.74.0.0/15, and going through port17.From SD-WAN routing logic, it said SD-WAN rules are matched only if the best route to the destination points to SD-WAN, will this
I have a Surface Pro Windows 11 running Snapdragon X 12-core @3.40 GHz, 32GB Ram, 64-bit OS. It has Qualcomm FastConnect T800 Mobile Network Adapter. I cannot get the FortiClient VPN software to install. It gets all the way through and then rollbacks every time. I'm running as an administrator and I have admin rights on the computer. Any idea what the issue is? I've never had this problem before. It says FortiClient VPN Setup Wizard ended prematurely. Thank you!Stacy
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.