Mark a Best Answer
Fortinet Community
Recently active
Hi, Like the title suggests, like trying to configure a Hairpin-NAT ( SSLVPN > LAN ) I got across the most annoying thing ever. I did configure some so far, but only from LAN > LAN this one I think it's a first. This works ( SSLVPN > LAN ) for some reason if I enable WAN > LAN , but I dont want access from WAN to the VIP, only from SSLVPN. id=20085 trace_id=13771 func=print_pkt_detail line=5869 msg="vd-VDOM:0 received a packet(proto=6, 192.168.220.100:64947->PUB-IP:3050) tun_id=0.0.0.0 from ssl.VDOM. flag [S], seq 1209702776, ack 0, win 8192" id=20085 trace_id=13771 func=init_ip_session_common line=6048 msg="allocate a new session-ef2fd6a5, tun_id=0.0.0.0" id=20085 trace_id=13771 func=iprope_dnat_check line=5338 msg="in-[ssl.VDOM], out-[]" id=20085 trace_id=13771 func=iprope_dnat_tree_check line=827 msg="len=1" id=20085 trace_id=13771 func=__iprope_check_one_dnat_policy line=5198 msg="checking gnum-100000 policy-2" id=20085 trace_id=13771 func=
Hello Community!I am attempting to install additional features to my Forticlients in the field, specifically, the SSOMA feature.I have created a package with the features I want.I have created a "Managed Deployment" and linked it to an OU that has clients that are going to need the feature, and the deployment is Enabled.In the EMS, I can see the endpoints being notified they need the install (the endpoint does show in the client that the administrator has scheduled an install). The installation finishes - the EMS reports (with a green checkmark) that the deployment was successful. The feature that I pushed, unfortunately, does not appear, even after reboot. What am I doing incorrectly?Is there a log I should be looking at? Attempting to push the package via a 3rd party agent using msiexec (with the transforms.mst) shows that the local .mst file from C:\windows\installer\ is being used, which doesn't have the feature needed.Am I using this "Managed Install" feature
Greetings all I have an interesting issue on a FortiGate 40F, with OS 7.0.18 (soon to be upgraded to 7.2, then 7.4.7, to see if that solves the issue). I have done BGP routing before without issues, but over MPLS lines between FortiSwitch ports. In this case we have dual, redundant, IPsec VPN connections over a single WAN interface The IPsec's run fine, and both Pri and Sec are up. Then there are the BGP links, which I created via a BGP loopback interface, with primary IP 172.26.200.21 (just did the secondary link first) and secondary IP 172.26.200.1. The BGP links are also running fine, with packets processing, and both advertised and received routes visible on both sides of the VPN.BGP Pri: 172.26.200.1 (Mine) <> 172.26.200.2 (ISP)BGP Sec: 172.26.200.21 (Mine) <> 172.26.200.22 (ISP) However, the received routes are not being inserted into the main routing table, and thus any packet I receive over the IPsec to my VIP fails the return path check and is d
Hi all, I hope you're well. I am migrating a site with existing Cisco switches to FortiSwitch but will not be using the default FortiLink interface since the VLAN's are already created under the existing aggregate interface. Templates have been configured and will be pushed out via FortiManager however, in order to add the switches into FortiManager I must issue set fortilink enable as a FortiLink interface must exist on the FortiGate. If I make the interface a FortiLink interface by using this command, does it remain as a standard trunk so that the Cisco switches and assigned VLAN's remain servicing clients meaning I can do this in hours or does this interface only work when a FortiSwitch is detected making this service affecting in hours if connected to Cisco switches? My thoughts are that this would not affect anything, but I have not tested issuing this command with anything other than a FortiSwitch attached so wanted to confirm. &nbs
In TCL scripts, the "exec" command is used to send text strings to the Fortigates and Fortigate output is then returned to the TCL script which can then be processed by TCL.A typical example would look like: exec "get system status\n" "# " 10 The first parameter is the text to be sent to the Fortigate with \n being the new line character used to terminate the command.The second parameter (in the above case, "# ") is the string that the Fortigate should return to exec which exec should wait for before moving on.The third parameter (in the above case, 10) is (perhaps suspected to be) the timeout value which tells exec to wait up to 10 seconds for the "# " string to be returned by the Fortigate before exec will give up waiting and move on.However, I have searched for details on the second and third parameters and have not been able to confirm the precise usage requirements for either parameters.In the case of the second parameter - the matching string. Is the string a regex or j
Short version of the story, I've got an external SDWAN provider but traffic through the SDWAN provider is doubling my ping latency. The provider says it's a routing issue that's outside of their control and they've submitted a ticket but if or when their provider supplies a solution is a question. In my Fortinet, I can set the ping source as my WAN2 interface (that's where the SDWAN solution is plugged in) and manually run a ping from there. However, I'm wondering if there is some way to track this in a more automated way from the FW itself? I'm thinking perhaps through some kind of automation stich but I'm not sure if it's really possible or not.
We have this issue, where some clients are getting a lot of legitimate URLs blocked, because they seem to be "unknown", although they are not unknown. These are common sites from Microsoft for example. This happens with remote clients that use FortiClient Webfiltering: blocked traffic log in ForticlientWord security warning because of FortiClient certificateFortiClient certificateNow the users get certificate error messages in Word for example, because Forticlient blocks the URL and provides its own certificate.Why does this happen? Client has proper internet access, DNS is working accordingly. Problem happens with FortiClient 7.2.5 and also 7.2.8. Any ideas?
Hi Team,I am currently using FortiClient VPN on my users' laptops, all of which have Intel Core processors. However, I recently purchased a new Microsoft laptop with a Snapdragon processor. When attempting to install FortiClient VPN, I encounter the error: "FortiClient VPN Setup Wizard Ended Prematurely."Is there a solution to install FortiClient VPN on my new laptop? Your assistance in resolving this issue would be greatly appreciated.
I already try but no success at first try. as when i update from 6 to 7 now is the same i believe that there's an issue with deep inspection. someone has experienced ther same?. I don't wanna live the headaches again.
Hi everyone, Does anyone know why there isn’t a Cybereason Antivirus product available for validation in the FortiNAC endpoint compliance scan? I managed to create a custom scan, which is working well, but now I need to validate either SentinelOne or Cybereason, and with Antivirus plus Custom scan I did not found a way to do this, because there is no OR between them, only AND. FortiNAC 7.2
Hi folks,i deployed the FAC for eap-tls authentication on my network and it's working fine.Now i'm asked to setup sso login in order to login on the FAC without using the local admin account, i can't understand how to do this although the documentation i found.The sso is already deployed for my fortigate login, how can i do the same thing for the Fac, i'm using azure to achieve this task.Do you have any advice? Thank you
hi,just would like to confirm if my conversion below is correct?it's for NAT between two internal networks in our environment to reach the MGMT subnet 172.29.0.0/16.do i also use the "nat-source-vip enable" so the "mapped-ip" will be be used for SNAT in the reverse direction? interface Port-channel101.61 nameif outside security-level 0 ip address 172.20.248.78 255.255.255.248 interface Port-channel101.60 nameif inside security-level 100 ip address 172.20.248.70 255.255.255.248 object network obj-172.16.7.70 host 172.16.7.70 nat (outside,inside) static 172.20.32.1route outside 172.16.7.0 255.255.255.0 172.20.248.77 1route inside 172.20.0.0 255.255.0.0 172.20.248.69 1-----config firewall vipedit "vip-172.20.32.1"set extip 172.20.32.1set mappedip 172.16.7.70set extintf "po1.60"set nat-source-vip enableend config firewall security-policyedit "DNAT for 172.20.32.1"set srcintf "po1.60" set dstintf "po1.61"set srcaddr "any"set dstadd
Hi Guys, I just enrolled in to the course recently and i was given a task at work to try and connect to my firewall remotely and some of my clients are not connecting to the network due to insufficient IP's. Any suggestion? Rgards
Hello i have topology to azure like below pic and found asymmetric routing.Azure by default will use both tunnel simultaneously but when in the fortigate set traffic to azure only to peer 1 so azure can't communicate with the onprem.Anyone know how to make FortiGate can accept traffic from both tunnel?
Hello, I'm trying to set up threat feed (external connections) via Fortimanager (v7.0.13) for my 2 Fortigates (v6.4.12 and v7.0.15). They are in two corresponding ADOMs on Fortimanager (6.4 and 7.0). Syntax in the file according to the documentation (the same for both versions) 1.1.1.1 # This is a test However, for version 7.0, comments are recognized correctly, but for version 6.4, they are not. (screenshots). Tell me, please, what the problem might be?
Hopefully someone can help with this as my knowledge with BGP, ADVPN, Hub\Spoke is not strong - but it is growing. We plan on having 4 spoke devices and 1 hub device all with 2 wan interfaces (if we get things working we may introduce a second Fortigate in HA mode at the hub). Some locations will have a TLS link back to the hub but not all locations will.Currently I have 2 spokes and 1 hub setup all with 2 WAN and 1 TLS in a lab environment. For the TLS spoke 1 is on VLAN200, spoke2 is on VLAN300 and the hub has a trunk with vlan200 and 300 on port3. This configuration is how our ISP has told us they will be setting up the TLS. The WAN links are using VPN with ADVPN (dialup tunnel for hub) - no VPN for the TLS\LAN links. iBGP is setup for routing with SDWAN advertising our private network and the TLS VLANs. The TLS is the preferred route and the VPN is backup. If we only use the VPN everything works - if we plug in the TLS links - everything works. Once we lose a spoke TLS li
Hello,After we added 8 different new “Domain Name Threat Feed” as External Connector to our FW device and activated it, the device CPU reached 99-100% in a short time and the systems became inoperable and could not be operated from the interface. Is this an expected situation, do you have any suggestions to prevent this from happening again, what can be done for CPU-based interface access problem? Below is the list of 8 added;Threat Intelligence Feeds DNS Blocklist - mini version https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/tif.mini.txt Threat Intelligence Feeds DNS Blocklist - mini version only domains https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/tif.mini-onlydomains.txt Fake DNS Blocklist https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/fake.txt Fake DNS Blocklist only domains https://raw.githubusercontent.com/hagezi/dns-blocklists/main/wildcard/fake-onlydomains.txt Encrypted DNS/VPN/TOR/Proxy Bypass DNS Bloc
Hi I've noticed that every time I create batch guest users, the number in the username keeps increasing: user0250user0251user0252 ...and so on. I have already deleted all users and the guest group. However, after creating a new guest group and generating new batch users, the numbering continues from the last user (e.g., user0253, user0254...). I can't find where this counter is stored or how to reset it.Thanks.
Hi Everyone, We've been struggling with this for a couple months now. I'm wondering if anyone has even had a similar issue like this. This location switched to ATT fiber a few months ago. Right from the start we've never been able to get more than 10MB down when running speed tests. They have a 50/50MB connection. The bandwidth monitor on the status page also confirms download never getting above 10MB. Upload gets up to the mid 40s during speed tests every time. We connected a laptop directly to ATTs equipment, ran a speed test and get 45ish down as expected. Naturally we've been treating this as a firewall config issue up to this point. Here's a list of everything we've tried so far ATT asked to have us set our WAN port to 100full duplex which it is. We also tried auto negotiate and 100half duplex. disconnected all equipment from the firewall except for one computer. Created a bare bones policy for that computer and put in at the top of the internal to
I know how to use the FortiGate GUI to run a Cable Test diagnostic on a given interface, but I need to know how to do the same thing via FortiGate CLI. Does anyone know the command for this?
Hi People!, I just want to ask regarding the IPsec VPN logs. We found a malicious remote IP address in our logs. I want to ask what the status = Success and 1 is negotiate_error, and the message = progress IPsec phase 2 and IPsec phase 1 SA mean. Does this indicate that the malicious IP has successfully penetrated? What are the possible troubleshooting steps or solutions to stop this? Thank you!
I am a student trying to learn FortiGate Firewalls on EVE ng using KVM images but I am facing license issue as i activated one firewall before and it become registered on my profile as KVM Evaluation license but i deleted the previous lab and started a new one then deployed a new firewall, now there is no way I can activate it as the activation is associated with the SN of the device. I tried to download the activation and upload it on the new device but it seems that it works with only on one firewall that become registered the first time by it's SN. now how can i activate another KVM image or transfer the same evaluation license to a new SN ? as you know there is no way i will get the same SN again on EVE deploying new device.
Hi all,I'm hoping someone here has successfully been able to set this up and can give me some pointers.I'm running 6.0.4 on a 200E and need to allow Symantec LiveUpdate to run through the F/W.The updates work when I allow all traffic from DMZ -> WAN, so I know the Symantec software is installed fine. However, when I block internet traffic, allow DNS lookup to pass through as LiveUpdate uses FQDNs and follow the Symantec tech article to allow it through the firewall, it fails every time. The tech article in question can be found here: https://support.symantec.com/en_US/article.TECH102059.html I've done some packet tracing when all traffic is allowed and it looks like LiveUpdate has multiple CNAMEs returned from the DNS. Should these CNAMEs be added to the policy as allowed or should the firewall be able to deal with them? It's getting to the point where I'm considering setting up LiveUpdate to run once a day and to allow all traffic out to the internet for a 10 mi
I am looking for a bit of guidance on how to get captive portal access to resources working based on firewall policies on a Fortigate (currently running 7.2.x). More specifically, I want to restrict management access to devices to authenticated users while allowing full access to the services running on those devices. For example, if I have users on Vlan 10 and Vlan 20 with Windows servers on Vlan 30 and Linux servers on Vlan 40, I would like to restrict RDP from Vlans 10 and 20 to Vlan 30 to only authenticated users while allow SMB through for everyone. At the same time I would like to restrict RDP from Vlans 10 and 20 to Vlan 40 to only authenticated users while allowing HTTP and HTTPS through. Can anyone point me at a complete, end-to-end How-To on how I achieve this, including where the (FQDN) captive portal could/should sit, please?
New Firewalls HA Setup with Reserved Management Interface- I have a FortiGate400F internal firewall(not directly connected to internet) with HA A/P mode and three VDOMs.(root, vdomA and vdomB)- I use my OOB mgmt interface as reserved mgmt in order to monitor both the primary and secondary firewallFW1 mgmt IP : 192.168.1.1/24 (port 'mgmt)FW2 mgmt IP : 192.168.1.2/24 (port 'mgmt)- I also want OOB mgmt interface to use for other services such as SNMP, Syslog.- Therefore, I have config 'ha-direct enable' so that the Syslog and SNMP traffic is passing through via that OOB mgmt interface.- However, after reserved interface config, FortiGate is unable to reach to FortiGuards services due to no routing via reserved mgmt interface.- i want the mgmt interface handle all the things (mgmt, FortiGuards, License, SNMP, Syslog, RADIUS, etc) How can I archive this setup or what will be the best approach to meet my requirements.thank you.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.