Mark a Best Answer
Fortinet Community
Recently active
Hi,updating an active-passive setup for a 120G, from 7.0.15, to 7.2.9 seems to break HA totally.It looks like the internal network can not be found anymore. I raised a ticket on that. Downgrade is possible, but takes time and nervs.Take care,Ronny 2024-08-21 13:15:18 <hasync:WARN> conn=0x476086a0 connect(169.254.0.1) failed: 113(No route to host)2024-08-21 13:15:18 <hasync:WARN> conn=0x476086a0 abort: rt=-1, dst=169.254.0.1, sync_type=3(fib)2024-08-21 13:15:21 <hasync:WARN> conn=0x476086a0 connect(169.254.0.1) failed: 113(No route to host)2024-08-21 13:15:21 <hasync:WARN> conn=0x476086a0 abort: rt=-1, dst=169.254.0.1, sync_type=3(fib)2024-08-21 13:15:23 <hatalk> vcluster_1: ha_prio=0(primary), state/chg_time/now=2(work)/1724238681/17242389232024-08-21 13:15:24 <hasync:WARN> conn=0x476086a0 connect(169.254.0.1) failed: 113(No route to host)2024-08-21 13:15:24 <hasync:WARN> conn=0x476086a0 abort: rt=-1, dst=169.254.0.1, sync_type=3(fib)
I have set up a DNS server on the flying tower. And it was referenced at the interface. There is normal internet traffic. But there is no record in the DNS query log
Hello, I would like to setup configuration using one virtual IP to connect multiple internal IP/host. How can I do the setup? Model: FortiWeb 1000e with firmware 6.3.1-build1056 Thank You
I have 40 windows servers that perform unique functions and want ZTNA access to all of them. I guess there are a couple of different ways:1) Unique public IPs for ZTNA TCP Forwarding Server with the same external port being 3389, and internally mapped to the single server on 3389.. Easy, but takes up a lot of addresses.2) Same public IP for ZTNA TCP Forwarding Server, with unique external ports, and internally mapped to the single server on 3389. Seems like a hassle for the end user to append a new port to and RDP session. Unless done using a SRV record in DNS with the unique port….. Does this sound correct ?Tom
Hi all,. I am having no luck finding these link again I need FortiSIEM Linux and Windows Agents downloads the actual files not the guides or pdfs. Thanks in advance. .
Hi, I have question related to filters and policies, I know that I can deny or allow emails with encrypted PDFs, but I need to do this:Allow X account to always send encrypted PDFs to everyone, but if someone who received the PDF replies with the PDF attached then allow it too, but if someone sends in normal circumstances a encrypted PDF to X account then block it.Is it possible to create a rule or something like this?: If X account sends something to Z account, then X account now knows Z account, and then if Z accounts sends/replies with a encrypted PDF to X account then allow the message, but if X account does not know Z account and Z account sends encrypted PDF to X account then block it.Is it possible to do what I want to do?Thank you and I hope I'm not bothering you.
Reaching out to the community to see what 61F owners have to say about VPN tunnel usage. Curious about things such as: how many tunnels, circuit speeds, SDWAN, performance, etc. Not asking for a lot, just a quick reply.Have two tunnels now and we get Conserve mode. We are reducing policies, logging, and UTM usage. We want to get up to 6.I have worked with 61Fs before and was impressed. We are just having tuning issues in this environment.
Hello,I’m using macOS Sequoia 15.3.1 with FortiClient VPN 7.4.2.1717, but I’m unable to connect to the IPsec VPN.I’ve seen other forum posts suggesting enabling FortiTray, FortiClientProxy, and FortiClientPackageFilter under Network Extensions, but these options do not appear for me.Is there a solution for this issue?Thank you in advance.
I have been trying to add SNMP on Fortianalyzer. I am able to get V2 working but unable to get V3 working. It have tried no auth/priv, auth/priv, auth/no priv but none seems to be working. I have followed this guide https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/62555 and wondering if i might have missed any steps?
At random moments, a user is incorrectly recognized by FSSO and does not receive the permissions they should. This happens sporadically but has been occurring more frequently lately.FSSO and the DC Agent are installed on each Domain Controller. They are configured so that each FSSO monitors all domains.Regarding the FortiGate configuration, the primary connection is set to the first DC, while the second DC is configured as a backup. FG ver 7.2.11Collector Agent version: 5.0.0319DC agent version 5.0.0315
So i was wondering if anyone has this working in production. Trying not to go the captive portal route. Can I achieve this with Fortiauthenticator, If yes what scep client are you using for devices to request their certs? Any input would be appreciated.
Hello, we utilized IPsec VPN last month, and several of our remote usersare expressing concerns about sluggish internet speeds when they activate the VPN. Certain users have had their connections reduced by 50%, while others have faced a decrease of 80%. Kindly be aware that the remote server is located a significant distance from the remote users.Is there something we can do to improve their speed?
Hi all, I have a FortiGate 100F series, and some devices are having internet, some are not, but all the configurations seem to be okay. Any suggestions?
Hi All,I've setup HA interface monitoring for FortiGate. When the link from primary unit down , the Firewall should Failover but it didn't failover and the primary unit still remain active regardless of the links fail.I tried removing both FortiGate from HA and reconfigured and tested but still the same , the HA failover is not happening. Are there any possibilities that could prevent from FortiGate Interface Monitoring to be stopped working? We are using version 7.2.0 .K7SRA1ITFWFG03 (global) # get system hagroup-id : 12group-name : HA-Groupmode : a-psync-packet-balance : disablepassword : *hbdev : "port21" 50 "port16" 22session-sync-dev :route-ttl : 10route-wait : 0route-hold : 10multicast-ttl : 600sync-config : enableencryption : disableauthentication : disablehb-interval : 2hb-interval-in-milliseconds: 100mshb-lost-threshold : 6hello-holddown : 20gratuitous-arps : enablearps : 5arps-interval : 8session-pickup : disablelink-failed-signal : disableuninterruptible-upgrade: enabl
Hi All, anyone experiencing issue with Fortigate Firewall sending delayed logs to the syslog server?I am experiencing an issue where the logs are only coming up 5-10 seconds after the connection has been established. Thanks
I recently downloaded the Forticlient VPN (7.4.2.1717) using the `FortiClientVPN_OnlineInstaller.dmg`.I'm using a Macbook Pro - Mac Sequoia 15.2 And after that, I received a warn saying "Please contact your administrator or connect to EMS for license activation.".And the Forticlient Icon App received a Lock and Key Icon at the left bottom corner. What should I do to fix that to use the Forticlient without a License activation.
Hi,Strange behavior happened after upgrade from 7.2.10 to 7.4.7.Whole Company started to lose connectivity both to Internet and internal resources. We rebooted the device and it resolved the issue for like 30 minutes and started doing the same behaviour. No major changes since yesterday whatsoever.It was upgraded during last weekend, but the problems started to occur this morning. For now, firmware was downgraded to 7.2.10 and it is stable again. Any of you had this issue?Regards
Hello, we have an issue with blocking hdfull.monster. We tried in Webfilter and URL filter and it would not work. Checking nslookup there are Cloudflare IPs and comparing with the test sessions I see other Cloudflare IPs. Any suggestion how to block this video stream monster? Thanks!
Hi Team, I need to know if it is possible to change the MTU on the ports of a Fortiswitch, I have been reviewing the config, and the only thing it allows me to change, is the MTU in: HOSTNAME # conf system interfaceHOSTNAME (interface) # edit internalHOSTNAME (internal) # set mtu-override enableHOSTNAME (internal) # set mtu 1600 HOSTNAME # config switch globalHOSTNAME (global) # set max-frame-size<integer> frame size between 68 and 10000 If I try it on the interfaces, I don't have the option to modify the MTU. HOSTNAME # config switch interfaceHOSTNAME (interface) # edit port1HOSTNAME (port1) # getname : port1description : (null)type : physicalnative-vlan : 1allowed-vlans :untagged-vlans :discard-mode : nonedhcp-snooping : untrusteddhcp-snoop-learning-limit-check: disabledhcp-snoop-option82-trust: disablearp-inspection-trust: untrusteddhcp-snoop-option82-override:stp-state : enabledstp-loop-protection : disabledstp-root-guard : disabledstp-bpdu-guard : di
Hello, We are a mid-sized school in Pennsylvania, 4 buildings + admin, 3000 students etc. We are looking to replace a couple of 7+ year old SonicWall nsa 6600 devices with compairable Fortinet or PaloAlto devices, and I'm heavily leaning towards Fortinet because of a bad PaloAlto experence a number of years back at a different job. What is the suggested Fortinet hardware that would be compairable to the SonicWall 6600s that we have now? Currently we have dual fiber lines coming in from our primary ISP and a second fiber line coming into from a fall over ISP, All connections are currently registering as 1Gbps connections, although I'm checking with our Primary ISP if that is the true speed or just what our SonicWall is tapped out at. thanks in advance.
Hi The company I work for has rolled out FortiVPN globally. We mainly use Macbooks but there are a few die-hard Chromebook / ChromeOS users still out there. Chromebooks can use Android apps and there is a Forticlient VPN Android app which could be used, but currently it doesn't work because, according to our IT team, "we use context aware access which requires Google Chrome, whereas the Forticlient VPN uses its own inbuilt browser". Can anyone suggest a workaround for this limitation? Or is the only fix for Fortinet to update the Forticlient VPN Android to use Google Chrome? Which I suspect is very unlikely to happen. Thanks Stuart
Consider that I have web filtering on a policy for my guest wifi users to block gambling sites. It works in that if I visit Draft Kings, I get served the SSL error, click advanced and continue on my browser and get served the "Fortinet has blocked this page". I browse any non-blocked categories just fine. I am wondering:What is the proper way to solve this for guest wifi? Even if I was willing to buy a Digicert certificate, what do I register when the URL is the site I'm visiting?A workaround I thought about: is there a way to possibly serve that blocked page as HTTP so it won't give that cert issue?
I have FG 100 E, and I have it setupDHCP ServerAddress range 192.168.2.2-192.168.2.254Netmask 255.255.255.0is there something missing so that some devices sometimes can't get the IP address Thanks.
Hi, I am experiencing problems with the vpn only client on an new hp pc witch intel network card, the vpn is not reaching the firewall, did turn off all firewalling and antivirus, checked with other pc's on the same network and vpn works fine so it look like a hp, intel vpn issue, i am using windows 11 last updates installed also last firmwares an bios HP Please advise. Dennis Kuipers
Hi,I am struggling with Fortigate VM evaluation license upgrade. My FortiGate VM had been deleted, it worked just fine, and I imported it from my backup. At first it seemed fine. I had correct serial number, I was able to reach for an evaluation license to the forticloud asset. Devcie has downloaded it succesfully and rebooted. That's were the issue begins. After reboot, name of the device has changed to Serial Number and the SN disapeared leaving VM with a wrong one. I did factory rest and it allowed me to restore proper SN for my device but issue is beeing repeated everytime I try to get the Eval License. Any idea where is the problem? Before license update.Device:Forticloud registration:Rebooting: After reboot hostname is changed to SN and SN is invalid Finally I am not able to upload Evaluation License.Maybe someone struggled with same issue?I will apprecaite any advise how to deal with it.Many thanks!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.