Mark a Best Answer
Fortinet Community
Recently active
Migrating a customer over to a FortiGate from a watchguard and they currently have fortiswitches managed via FortiEdge cloud. I want to migrate the management of these switches to the FortiGate via Fortilink - what are key things to consider for this process? Is this still considered a controller migration and will default the switches configs? Are the backups taken from the FortiEdge portal a compatible format to import into the switches after they are managed via the Fortigate, or to paste in the CLI? Thanks
Running Fortigate v7.4.5 and I'm trying to use a datadog collector to forward my logs up to datadog but the datadog isn't able to recognize individual lines/json object as disticnt logs. I was looking at some of the raw output and I noticed that there are some characters between the 2 json objects. Does anyone know what these are? ","mpsk":"N/A","msg":"Client d2:b6:1c:6c:c2:45 authenticated.","new_line":"/n"}1557 <45>{"date":"2025-02-26","time":"09:41:55","devname":"PGH-What is the "1557<45>" it' not part of the json object and I'm wondering if it is causing this.
About a year ago, we encountered VPN access that appeared to be using information from the account list we managed.There are three types of targeted VPN users based on logs and token reception status via email.・Email authentication applicable account・Non-multifactor authentication account・Deleted account  For accounts eligible for email authentication, token notification emails were received, but the logs for those users could not be confirmed.For deleted users, SSL-login-fail logs were recorded.For users with non-multifactor authentication, only tunnel-down logs due to timeout were recorded.When checking the normal logs, tunnel-up and tunnel-down are set as a set, but for non-multifactor authentication users, only tunnel-down due to timeout was recorded in the log.We inquired about this situation to the maintenance vendor, but they answered that due to the specifications, only tunnel-down is not recorded in the log.However, the actual declared contents are recorded in the logs, and I
Hi All, I have a ADVPN setup with certificate authentication. In firewall, we imported one local CA & root CA_1. IF any policy related changes pushed via Fortimanager to Fortigate, additionally VPN CA certificate also pushed to firewall along the policy change... so inthe firewall, we have 2 root CA's - root ca_1 & root CA_2. When the tunnel starts renegotiation, it takes the root CA_2 for cert authentication which caused "VPN certificate check failed " error and tunnel goes down. solution: i manually deleted the root ca_@ in the firewall and tunnel came up - it works.. Query: i need to know what is this behavior and how to stop pushing vpn ca certificate to be pushed to firewall in fortimanager. or any other solution for this..
hello, I'm trying to set up SAML VPN authentication with Azure using a Realm.I'm having trouble figuring put which is metadata link in Fortigate.Doc claims that should be like:/remote/saml/metadata or /remote/saml/metadata?Realm=REALM Both link returns:403 Forbidden Graziano
Hi All, I'm wondering if Anyone has used FortiAuthenticator to perform BYOD ?I'm testing FAC 5.1.2 in a lab envirement to authenticate WiFi users using EAP-TLS, the FAC has a CA certificate configured (signed by a Win2016 root CA). And I'm stuck at getting devices self-enrolled to obtain a certificate that they can use for EAP-TLS.I've enabled Device Self-enrollment using the CA Certificate Template (SCEP request is configured using Wildcard).At the moment, I'm unable to enroll a client device on the url : https://FAC-IP/cert/scep . I'm getting the following error on the Browser : "operation" parameter is required I've also tried http (enabled http on the Interface) instead of https and keep getting the same error. Has anyone faced the same problem before ?Has anyone succefully got device self-enrollment working on FAC using SCEP ?Do FAC provide an onboarding portal similar to other products such as Aruba Clearpass ? Your help will be very much appreciated.&nbs
Is it possible to make the Fortigate route traffic in this way:External dns pointing to fortigate public ip > fortigate external interface > route the traffic based on dns to a internal IP ONLY if it matches the requested dns?example using other dns names:google.com > 8.8.8.8 (fortigate external ip) > 192.168.1.200 (internal system) Essentially asking if the fortigate can serve the same purpose as a reverse proxy which checks source packets trying to match dns and redirect to a local server. I hope i explained in a understandable way and thanks in advance.
Hi all, We are seeing some strange peaks in our WAN bandwidth. Every 20 minutes, we get a peak of around 1.5Gbps which lasts for about 1 minute. We can not figure out what is doing this. We did a packet capture when the peak is going, but when looking in wireguard -> statistics -> conversations, we can only see 5 things that are around 15Mbps. To IP addresses that are not being used in any VIP. How can we further troubleshoot this? Edit: We've also checked all firewall rules comming into the fortigate, but none of them are producing this many Gbps..
HiAt my client I have made IPSEC tunnels between devices, Connections are Established on 2 phases, you can see the traffic that works, from the FG device I can PING, Tracert, works properly however from the workstation itself unfortunately does not work,I test Tracert from workstation:goes to FG and disappears (only 1 hop to GW fortigate).There are policies and routing set up. I'll add that I'm using a non-RFC address in local network 192.100.100.0/24 (could this be the problem?) in Traffic Monitor I can see that traffic is going into Tunnel
Hi, I have a problem with forticlient 7.2.2.0776 on Mac OS Sonoma 14.1.2.When I'm connected to forticlient for a specific customer, I can't access Internet at all (email, Teams, web browser...). However, when I log on to the same customer via forticlient on a Windows computer I don't have the problem. So it seems like an issue related to my Mac. But what is strange is that I have another customer who uses forticlient and when I log on to that customer on the same Mac, I have access to internet, so it doesn't seems related to my Mac after all. I'm very confused and don't know where the restriction is- Is it something that I should do on my Mac (but if yes why it's working for another customer on the same mac?)- Is it something that the admins of my customer should do on their side (if yes, do you know what they should do?) RegardsYoan.
hello team,I have configured mp-bgp with VXLAn between 2 Fortigates and everything is working fine,I need to advertise only connected IPs to the local switch to other FortiGates/VDOM via BGP.The same thing for both Fortigates.I need to do that because we have remote locations that we would like to connect directly to the Fortigate that has the Server IP instead of traversing the vxlan to reach the destination server.thank you
I understand the point of a NGFW is to consolidat a stack of security appliances into one. But isn't the fiewall itself subject to DDoS attacks - esp since it doesn't act in stealth mode? Wouldn't it be best practice to have either a cloud based DDoS service or a dedicated and stealthed DDoS security appliance like FortiDDoS infront of the gateway firewall?
Hi, i need help with radius, i don't know but sometime auth dont works. User client when open a browser must insert domain credential. autetication on the firewall works the tests are always positive, while on the client to navigate, credentials must necessarily be entered.thank you
Hi all, I am new to this product, and I am requesting for the procedure to configure DLP and DLP logging.
Hello everyone,I’m planning a new installation for FortiNAC and I’m trying to decide between FortiNAC 9.4 or FortiNAC-F 7.6. I’m not entirely sure about the key differences between the two versions and which one would be the best fit for my needs.Could someone please explain the differences between FortiNAC 9.4 and FortiNAC-F 7.6? Specifically:What are the feature differences?Are there any performance or scalability considerations?Which one is more suitable for a medium to large enterprise environment?Additionally, if anyone has experience with configuring either of these solutions, I would greatly appreciate any tips, best practices, or even a step-by-step guide to help me get started.NB: my licence is : FortiNAC Control and Application Extended VM Certificate (FNC-CAX-VM for 2 VMs)(LIC-FNAC-PRO-100)Thank you for your help!Best regards,
Hi. Can I know if upgrade FortiManager to 7.2.8 and FortiProxy to 7.2.11, will FortiManager be able to support FortiProxy? From what I read in FortiManager 7.2.8 release notes, FortiManager 7.2.8 supports configuration management for the following versions of FortiProxy:7.2.97.2.77.2.67.2.37.2.27.0.12 to 7.0.177.0.7 to 7.0.10FortiManager 7.2.8 supports logs from the following versions of FortiProxy:7.2.0 to 7.2.97.0.0 to 7.0.172.0.0 to 2.0.51.2.0 to 1.2.131.1.0 to 1.1.61.0.0 to 1.0.7 What does supports configuration management and logs means? If upgrade FortiProxy to 7.2.11 will it have any compatibility issue with FortiManager? Thanks!
Hello.Where i can download firmware for this Fortigate 200B?This is a old fortigate i want to use to learning. I don't have any contract.Thanks.
How can i setup an alert to be notified when Fortiportal which polls multiple FMG and FAZ,cant poll 1 or multpile devices and makrs thme as down. Polling is done daily.
Issue with WebSocket Connection Closing Prematurely in My Network SetupNetwork Setup Overview:In my current network setup:Incoming traffic first reaches the FortiGate firewall (version 7.2.9).It then passes to the core switch and routes to FortiWeb (version 7.6.1).From FortiWeb, it goes to an aggregation switch and finally reaches the application via a service HA setup.We have a published website that uses WebSocket connections for real-time reporting on a specialized application. The WebSocket sends data every 5 seconds to keep the connection alive.Testing and Actions Taken on Network Devices:Set session TTL to 1 hour on FortiGate.Configured the following on FortiWeb:set tcp-keepidle 300set tcp-keepintvl 60Removed the security policy profile from FortiGate.Set an alert security policy on FortiWeb.Checked switch traffic for any configurations limiting requests or sessions (found none).Observations and Issue:When the WebSocket connection originates locally (within the same VLAN as the s
Hello everyone, I have a problem with fortiClient it stops at 31% and right after I get this error message:Unable to establish VPN connection. The VPN server may be unreachable. (-4006)But the same Forticlient is able to connect to other SSL VPN customer, so I have this problem with only one customer Any help please Best regards
I cannot use the IP addresses from the IP pool as the source IP for ping commands.
Hi all I am very new to Fortigate. Just set up a FG 60F that needed port forwarding from a cloud service to an internal printer on port 9102. What I have done so far:Set up VIP with external IP of WAN interface and internal IP of printer: Created firewall policy with the source being the public IP of the cloud service, destination the VIP Debug logs give these messages:id=65308 trace_id=9 func=init_ip_session_common line=5995 msg="allocate a new session-0009a61c"id=65308 trace_id=9 func=get_new_addr line=1205 msg="find DNAT: IP-<printerIP>, port-9102"id=65308 trace_id=9 func=fw_pre_route_handler line=180 msg="VIP-<printerIP>:9102, outdev-wan1"id=65308 trace_id=9 func=__ip_session_run_tuple line=3413 msg="DNAT <WAN_INT_IP>:9102-><PrinterIP>:9102"id=65308 trace_id=9 func=vf_ip
As per the subject, how to duplicate the LAN to WAN traffic from FG-A to FG-B's LAN to WAN. The LAN IP is 172.20.1.254 and the WAN IP is 10.0.9.246. As shown in the image, how should this be handled?
HiWe have a small Fortigate with SSLVPN for home users.For a few months we have had more and more VPN login attempts. In the past from few IP address. We have blocked this on the firewall. Now we have ~100 attempts per day, always with a different source IP.This floods the log and important events can be missed.Geo-blocking is not an option as the CEO should have access even when on vacation.Can we configure that a denied is only sent for known usernames?Any other ideas?
Hello,Can I upgrade my FortiOS to 7.4.7 if I have Fortigate 200e?I have also FortiAP-231F v7.4.5, build0734, 250108 (GA)Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.