Mark a Best Answer
Fortinet Community
Recently active
Hi,I am facing the problem of occurring at similar time intervals (about every 15minutes) saturation of the ssl vpn link to the remote Fortigate device.The saturated outbound direction traffic reaching 70mbit/sec: When I go to Fortiview Destinations with destination network of the remote Fortigate I see that the traffic to this destination is partial about KB/s: How can I diagnose this, because when these spikes occur it severely drops the performance of this link, ping responses increase from 10ms to about 300ms and users on the remote side of Fortigate can not work normally?FortiOS is 7.2.11 Greetings
Hi Everyone, I have an issue that we can't find any solution to it. We have FortiGate 100F, FortiOS v7.0.3 build0237 (GA).I have 3-4 users that experiencing issues of duplicate routes in the routing table: 192.168.80.0/23 - Internal Network172.16.80.0/24 - SSL VPN IP pool192.168.136.197/32 - local gateway address. this effect on the access to internal resources, all the internal destined traffic is go through the 192.168.136.197 and not through 172.16.80.99.after deleting manually the route it is working fine,This is not happening to all users just for 3-4 right now (maybe the number will increase). Fortinet support claims that we don't have a license to Forticlient so they can't check at the user's end. They were connected to our Fortigate and saw that everything is set up as needed. Any suggestions? Thank you :)
I've followed some of the most posted protocols for preventing brute force on my vpn interface, biggest was to only allow US based traffic to the interface, but what I've found in the last coupld of years, is that all the open VPN environments in the US are used by threat actors constantly. I'm up to about 3000 failed login attempts in 6 hours time. This is just US based IP's and when I look them up, the bulk of them are associated to open VPN providers IN the US. I was doing some searching to see if there are geo lists of these open vpn providers that I could import. I've been manually digging up the blocks and doing ASN/Whois lookups to piece it together. I get it down to about 200 / 6 hours, but then in a couple of weeks, shoots back up to the 1K's of hits. Anyone have suggestions? Again, this is US only attacks at this point.
Hello all. Any and all help is greatly appreciated. We have two FAC400Es, both running 6.6.2. We recently changed the IP address of one of them and lost HTTPS access. The FAC is reachable from anywhere on the network, does not appear to be a routing issue. About 10 mins or so after the new IP was configured I cleared the cache on my browser and actually had HTTPS access. I tried to access the FAC roughly 24 hours later and it hasn't worked since. Other T-Shooting Steps/Points -tried multiple browsers including Chrome, Firefox and Edge-we do not have any security devices between the two points, HTTPS access worked prior to the IP address change on the FAC-power cycled the FAC multiple Times-confirmed we do not have access to the FAC from multiple source IP spaces ===========================================================================Config is below: > show configconfig router staticedit 3set device port1set dst 0.0.0.0
I am working a project which will see the customer inherit an existing FortiGate deployment. These firewalls reside in branch locations and are centrally managed using FortiManager in the data centres. They are also logging to FortiAnalyzer in the same location. My question is if the FortiGates are removed from FortiManager, will this impact the baseline configuration? My hope is that when removed from FortiManager, these devices can be locally managed with the configuration in tact.
Hello, Would appreciate any insightful details on why the installs might be failing SELinux is enabled, these followingpackages are also installed:policycoreutils-pythonlibselinux-utilssetools-console I don't have the logs yet but any insights as to why the agents are failing install. Also what is the absolute highest version to safely install on RHEL 9.4? ARe Fortinet haveing issue with this latest version? Agent Versions Attempted(Supervisor version 7.1.3):Version 7.1.3: FSM Linux Agent not updated with the latest certificate.Version 7.1.7: installed require Packages to enable SELinux still issue not resolved research done by vendor engineerand suggested attempt v7.2.4Version 7.2.4: Vendor engineering team updated parts of the script related to SELinux hence attempted this version Can anyone please verify if they have a functioning Lunx agent on RHEL 9.4 SELinux? We are stuck.Are we missing packages? what about these ? libcapauditrsyslo
I have topology like below pic, where i have 2 location and both location connected using advpn.Also both location have vpn site to site to azureFrom site-1 perspective the BGP status is connected to azure and site-2but from route table why traffic from site-1 to azure is learned by site-2 (10.201.0.0/16) as best path?since site-1 have direct connection to the azure why second path is not become best path?
Hello members.I recently upgraded firewalls from 7.2.10 to 7.6. I have 2 firewalls connected in fabric, the root fortigate at the headquarter connects directly to dns server and it is reacheable but it cannot reach the fortinet dns 96.45.45.45 or google public DNS 8.8.8.8. The down stream fortigate accesses the internal DNS through a tunnel.Clients can reach the internal DNS however when you ping directly from the fortigate the ping fails. I have noticed on the DNS settings with default settings the fortinet dns 96.45.45.45 shows reacheable while the internal DNS shows unreacheable but if I change the source IP address of local out traffic, the internal DNS shows reacheable while the fortinet DNS 96.45.45.45 and google public DNS 8.8.8.8 shows are unreacheable
Hi there,Our domain is still listed as Phishing here:https://www.virustotal.com/gui/url/904b0c0e0ed1239034a4e61588cf860f0841f967172392636be4c6d661d86916 The domain is: https://amazonswag.com/ This is affecting some of our customers raising support tickets using this url: https://www.amazonswag.com/support/Please can I ask that the malicious flag is removed from our site ASAP so our users are not affected?Cheers,Billy
One of the iPad has automatically updated the FortiClientVPN app to v7.4.2 from v7.2.5.While on v7.2.5 no issues encountered. However, once updated, no prompt for username and password. We have already reformat and uninstall multiple time, still the same output. v7.4.3 just released, already tried. No luck. The iPad Air 2 iOS version is 15.8.3 Appreciate any feedback on this. Cheers!
Hello All,kindly i need to know the supported Forti analyzer version that compatible with Forti Sandbox Version 5.0.1 as I cannot integrate Forti Sandbox with version 5.0.1 with Forti Analyzer version 7.2.8BR
Works with IPv4 & IPv6 local-in policies.Can auto-run when imported as Userscript.Purely reads and shows the config, not touching it.If you use it, please write a comment or click the Kudo button. Show custom local-in policies in FortiGate's WebUI with just a click! Login to your FortiGate's WebUI and open to the local-in policyEnable in System > Feature Visibility if requiredCreate a new bookmark in your web browser and copy the JavaScript code below into the URL field.Click the bookmark and enjoy viewing your custom local-in policies!Result:Copy & paste into a bookmark:javascript:(async function(){const ip4=await fetch('/api/v2/cmdb/firewall/local-in-policy');const a4=await ip4.json();const ip6=await fetch('/api/v2/cmdb/firewall/local-in-policy6');const a6=await ip6.json();const m=document.querySelector('.mutable-menu');const p=document.createElement('div');p.setAttribute("id","clip");s=t="<table style='width:100%;padding:0;border-spacing:0;border-collaps
when i am uploading the firmware image then its not working because that file is corrupted and asking to upload only virtual machine images in .ova file Please provide me virtual machine image of Forti Authenticator for Google Cloud Platform
Hello I had a problem with Web filter Service where all users could not browse because the fortinet block page was displayed. With the message 'Web filter Service error N/A' I checked the security profile that have the browsing policies and this has enabled the option “Allow websites when a rating error occurs” which in several forums indicate that it is a workaround for scenarios like this at the level of traffic captures the action was Passthrough. Can anyone help me understand what could have happened or what revisions I can make to understand. Thank you very much
Does the Enhanced Support Premium license for the FortiGate-100F include the provision of a replacement device if a malfunction requires repair at an external service center or replacement with a new unit while waiting for the repair or the new device?
Hello, we are currently running our Fortigates on FortiOS 7.0.13 and want to upgrade them as the version is coming out of support in next few months. we first considered 7.2.10 (7.2.11 now) but Fortinet recently changed their recommanded version to 7.4.7 for our models. Reviewing the release notes, I noticed this known issue : 1069208If the DHCP offer contains padding when DHCP relay is used, the DHCP relay deletes the padding before relaying the packet. From what I understand on various internet sources, removing padding from DHCP packets could be an issue for certain devices that could no more get an IP. I found nothing specific for Fortigate setup however. This is a major issue for us as our main Fortigate is used as a DHCP relay, and it is the only one so we cannot test it before. I was curious if someone encountered DHCP issues on 7.4.7 ?
Hi All, I am facing an issue with my IPsec remote VPN split tunnel configuration on FortiGate. When a user connects using FortiClient-VPNonly addition client software, it works fine. However, when the user connects using the FortiClient-ZTNA edition, the default route (0.0.0.0/0) is added to the host machine, forcing all traffic through the VPN, even though split tunneling is configured.Anyone has any idea?
Dear team, I recently upgraded my system from windows 10 to windows 11,after that have been trying to run some SQL jobs in SAP HANA studio but the SQL is getting terminated due to VPN connection failure the exception is "Data receive failed [java.io.IOException: The network connection was aborted by the local system.]. " anybody faced such issues in the past, kindly share possible trouble shouting areas to fix it, this is urgent.BR/Veera
Hello, I have question. How can I generate a report to view Bandwidth Per Link Internet?FortiAnalyzer firmware version 6.4.12
Hello Gentlemen, I want to redirect thehttps://exmple.com/entohttps://example.com/en/product-category/audio-visualhow can I do that with fortiWeb using URL writing in simple way? I need the correct steps Thank you
Hello Everyone,Is there a way to generate a daily report of connected VPN user data from FortiClient EMS that includes the following details:User ID / UsernameProfileRole NameLast LoginEmail IDFailed attempts Currently, the report export option is available only in CSV format, but it does not include the Email ID and Role Name. Also, all reports appear to be merged, making it difficult to isolate specific data.Has anyone configured a custom report in EMS to include these fields? If so, please share the steps or any guidance on how to achieve this.Thank you!
Hallo,i am using FortiEMS with 2 different Client licenses active, one for EPP and one for ZTA.I only have 25 EPP licenses that i want to give to specific clients.Is there a way to specifically use those licenses on those clients or will the EMS randomly assign them to the next best client?
Hello, I have a question. I have an FG 61E with Firmware 6.2.3 and a Bundle License. When I try to apply the license on the Dashboard, it shows that the license has expired. However, in FortiCloud, it shows that the license is activated. I have rebooted the device, but the license is still not activated.
We have security policies in place to block social media applications. However, in the past few days, these applications have been accessible without any restrictions. Upon investigation, we found that traffic over SSL and QUIC is being allowed for these sites. Please assist us in fully blocking access. Model : FortiGate 60FFirmware : v7.2.10 build1706 (Mature) Application Control Policy : Web URL Filter Policy : Log in which we can see that the websites are getting allowed :
Hi, Is it possible on a fortimail (6.4.x) to implement Web Rating override on URLs contained on incoming emails? Issue:A colleague will send an email containing a URL to an internal resource, with an internal only domain name.A response to the mail from the outside will be received by the fortimail which sees the internal domain as "Newly Observed Domain", and quarantined.On a FortiOS based device, we could override this web rating. I don't see this option on the fortimail.As it's an internal domain, it's unlikely to be accepted using https://www.fortiguard.com/webfilterWorkaround:Fortimail's URL exemptions are a stopgap, but prone to failing with port / hostname changes. Not keen on using regex's due to lack of info (Just documented as perl-regex-alike), and possibility of creating a security hole.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.