Mark a Best Answer
Fortinet Community
Recently active
Hi, I have configure 3 60F like that: - 1hub- 2 Spoke In the Hub, the WAN 1 ip of the Remote-GW is: "set remote-gw 10.1.230.100"And in the spoke, IPSEC 1 show 10.1.230.100. But it's the lan IP. How to change with the wan ip ? Exemple: config overlaysedit "wan1"set overlay-tunnel-block 10.10.10.1 255.255.255.0set remote-gw 10.1.230.100set interface "wan1"set bgp-neighbor "10.10.10.253"set ipsec-phase1 "fabric_vpn_1"set sdwan-member 1next
Hello,I want to export logs for specific policy IDs and download the logs to then run a script over it.My problem is the following: The FAZ is unbearably slow. If I download the logs via "Log View-->FortiGate-->Filter with Policy ID --> download txt " It takes eons to prepare the logs before I can download them. At first its quite fast and then it slows down, to about 20-40 Logs/second. For Log Files that hit the 100k Log cap, this takes a long time. I have to move the cursor every few minutes as well so that my session doesnt expire. Is it possible to let this log preperation happens in the backround so I can come back and just download it instantly?Or should I use the raw logs from "Log Browse" with EVERY Policy ID and change my script so it sorts the Policies itself? Any Help would be great!
Hello admins, Are there openings to become moderators in Fortinet forum?if so, would you please share details.Thank you
question description:C:\Program Files\Fortinet\FortiClient>FortiClient.exeC:\Program Files\Fortinet\FortiClient>Error: Cannot open C:\Program Files\Fortinet\FortiClient\resources\app.asar\assets\js\guimessenger64.node: Error: A dynamic link library (DLL) initialization routine failed.C:\Program Files\Fortinet\FortiClient\resources\app.asar.unpacked\assets\js\guimessenger64.nodeat ./node_modules/guimessenger/guimessenger64.node (C:\Program Files\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:22:189)at __webpack_require__ (C:\Program Files\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:38601:42)at ./src/main/loader.js (C:\Program Files\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:23284:18)at __webpack_require__ (C:\Program Files\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:38601:42)at ./src/main/logger/logger.js (C:\Program Files\Fortinet\FortiClient\resources\app.asar\assets\js\main.js:24107:19) at __webpack_require__ (C:\Program Fil
I have 8 devices (currently on their own SSID tunnel on my home network that is Fortigate, Fortiswitch ad Fortiap) 6 that use 2.4G and 2 that can use and seem to prefer 5G. Last week they have begun requesting multiple IPs which has caused them to be "Removed due to IP conflict". 8 devices have filled up the whole DHCP table which at one point showed over 300 devices. This has been set up for almost 2 years and has run without issues. Current lease time on the gate is roughly a week which hasn't been a problem. I shortened the lease time to just over a day as apparently Ring devices can request a new lease every 12 hours and I cleared the table and factory reset one of the devices to attempt to reconnect but it will not connect even though the number of devices showing in the table was under 10. Has my gate somehow "blacklisted" the MAC of those devices? Ring cameras and the base station which are hard wired are working fine, this is a wifi issue. Is it best to try to avoid IoT wifi de
Good evening!I have a FortiGate 101E with two internet providers using both WAN ports. They are configured so that when WAN1 goes down, WAN2 takes over, but only for failover purposes.My goal is to use each WAN service for a specific VLAN. For example, VLAN 01 should use WAN1, and VLAN 02 should use WAN2.Is it possible to achieve this configuration?Thank you very much!
Hello, I have a question concerning OSPF with access-list and route-map.It has to filter permit 192.168.0.0/16 and deny any. When using an access-list, it works. When using a route-map it doesn't.Here is part of the configuration: FGT (ospf) # showconfig router ospf set distribute-list-in "access-list-01" config area edit 0.0.0.0 next edit 0.0.0.1 nextendconfig network edit 1 set prefix 10.0.242.0 255.255.255.0 next edit 2 set prefix 10.99.12.0 255.255.255.0 set area 0.0.0.1 nextend.......FGT (ospf) # showconfig router ospf set distribute-route-map-in "route-map-01" config area edit 0.0.0.0 next edit 0.0.0.1 nextendconfig network edit 1 set prefix 10.0.242.0 255.255.255.0 next edit 2 set prefix 10.99.12.0 255.255.255.0 set area 0.0.0.1 nextend.......FGT (ac
Dear Fortineters,I've a question about a particular Fabric configuration I would like to realize (if possible). We have a typical Fabric infrastructure:FORTIGATE --> FORTISWITCH --> FORTIAP We would like to add a FortiSwitch behind the FortiAP using one of its lan ports in order to extend the Fabric like this: FORTIGATE --> FORTISWITCH --> FORTIAP --> FORTISWITCH. Do you think it's possible?Have you already implemented this kind of scenario?Configuring FortiAP LAN ports may be useful?https://docs.fortinet.com/document/fortiap/7.2.5/fortiwifi-and-fortiap-configuration-guide/430146/lan-port-options Thanks in Advance Massimiliano Pontarollo
I am new to FortiClient EMS, I am installing and configuring at the moment. I can see that the FortiClient download URL is https://servername:1443/installers/ I am planning to configure IIS to run another website on port 1443. Is there a way to change the FortiClient download URL to a different port? I am not sure if I can have 2 websites running on the same server with the same port.Please advice
Hello Fortinet Community, I have configured a traffic shaping profile on my FortiGate firewall, along with a traffic shaping policy where I have assigned a Class ID. However, I am unsure about the correct way to apply the traffic shaping profile to interfaces and set the outbound bandwidth.In my traffic shaping policy, I have selected the destination interface as the virtual-wan-link (WAN1 + WAN2) as the outgoing interface. My question is: if I apply the traffic shaping profile separately to WAN1 and WAN2, will the traffic shaping function as intended? I would appreciate any clarification or best practices regarding this setup.Thank you!
hi, i am new to this i want to monitoring forti manager in zabbix using API or HTTP agent i dont know how to do it properly. so can anyone tell me how to do it. Thanks a lot
Dynamic IP addresses change regularly, making it difficult to identify the host associated with an IP address detected at any given time during incident investigations. Is there anyone who can give me a solution?, In my opinion, I think we can create a correlation rule that associates DHCP log events with assigned IP addresses to help maintain a correspondence between dynamic IP addresses and hosts, or use Lookup Tables to keep track of the history of assignments. Thanks,
I am having an issue with the Fortigate Web Filter Override. The option Allow users to override blocked categories is enabled and the override link on the Access Blocked Page appears, but the page times out. Policy and Web Filter Profiles are set to Proxy mode.
Post delete
Hello all - new to Fortigate Central Nat and just wanted to run something by the community here.Looking to exempt NAT for a specific source and destination - while maintaining NAT\PAT to internet bound destinations for the same source. My questions are, can a "No NAT" rule be created\utilized in Central NAT, and how are the rules parsed\ matched ? Assume top-down correct? Here's an example of what I'm after - 3 interfaces on the firewall. I just want to NOT nat the Forti voice ip when the destination is the CCUM server ip. Can I create a rule with those sources and destinations and just turn NAT off -then create a rule below for everything else internet bound? Thanks in advance all inside – outside – any – any – NAT\PAT - to internet hosted –outside – Fortivoice IP – CCUM IPs– no NAT hosted – outside – any – any – NAT\PAT - to internet
Good morning everyone.I need to configure an SMTP external to my administration on my FortiAuthenticator (v.6.6.2) to forward FortiTokens.I would like to use the Fortinet service "notification.fortinet.com" as SMTP, but I can't configure it to work.Can someone help me?Thanks.
There doesn't seem to be any way to report bugs like this so I'll post it here: Installing the free FortiClient VPN under Windows 11 fails with the nonsensical error message "FortiClient VPN requires Windows 10 or higher". This is due to a bug in the installer, it tries to call NetWkstaGetInfo() alongside the more obvious GetVersionEx() and if it fails it bails out with that error message.What's happening is that GetVersionEx() returns version 602 = Windows 8 while NetWkstaGetInfo() returns version 1000 = Windows 10/11. Since the NetWkstaGetInfo() call has failed and so the version is never updated to 1000, the installer continues while thinking Windows 11 is Windows 8 and bails with the nonsensical error message.
Hello everyone, I would like to know whether it is possible to generate and create a certificate on FortiMail for internal use for administrators only (ex : internal.example.net). If so, could anyone provide guidance on the process? Thanks in advanceBest regards,
Hi Team, I have created a bookmark for web URL in webmode clientless vpn but sometimes login button does not work & sometimes it works. Attached are the screenshot from inspect(console) output from browser. Kindly suggest here.
When I try to login in Fortigate 60D from wan interface IP (10.*.*.241) from another network. It logged in for few seconds(i.e. 3 second, 5 seconds) and automatically logout. when I saw in forticloud> Fortiview> Admin Session it shows a reason is Violation.as also i attached screen short.Please suggest a solution. I'm new in fortigate.But in same place when i tried to login from network behind the firewall. It's work fine.
Hi, I'm new with Fortigate and we have deployed an AWS EC2 Fortigate NGFW v7.0.0 build0066 in one of AWS regions.We want to allow internet access to users thru their Active Directory accounts/groups.And, we're testing LDAP as a possible solution. The firewall is configured in split-VDOM (Root and FG-Traffic)Creation of the LDAP in the console was successful. Testing of user and credentials are okay.And, directory tree was displayed when browsed. But when we closed and save the LDAP creation window and access it again the LDAP failed with an error of lda_-3 or Invalid LDAP server. Same thing happens if we repeat the same to create a new LDAP server in the console. In our troubleshooting, we found out that the console or GUI uses the Management interface to communicate with the AD server. While in CLI, the interface used was the interface we set in "set source-IP xxx.xxx.xxx.xxx. Testing in CLI seems consistently successful. Seems the set source-IP is not being u
Hi Community,We have been using FortiClient VPN 7.4.0.1658 (No Licenses). Recently this version was tagged for vulnerabilities. We looked into testing the new version 7.4.2.1737. This version seems to only work for a month without license. The old version had no issues working with full version being purchased.Will this version not work after a month? Is there no more free Forticlient VPN Version?
Good morning,I have a problem after fortigate deployment in a bank. Money gram application can't work in branches connected to the HQ with VPN tunnel. But the application work in the HQ, two branches connected with BLR via switches. Find attached the network diagram and notice that nat is configured in the router LAN.[image][/image]
Hi, I want to block custom files (bin, ova, ovf) on FortiProxy. I couldn't find these files in the file filter field. How can I block them? Has anyone done this? I would appreciate your support. Best Regards,İsmail Ürek
Dear Experts, When IPsec VPN at IPsec aggregation with SD-WAN is down, Trap fgTrapVpnTunDown(1.3.6.1.4.1.12356.101.2.0.302) is not sent,although "VPN tunnel down" is enabled at SNMP events.For information linkDown(2) of MIB 1.3.6.1.6.3.1.1.5 is sent. Can someone tell me how & what I should change so that fgTrapVpnTunDown is sent? Thanks in advance.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.