Mark a Best Answer
Fortinet Community
Recently active
Hi, We are planning on rolling out a handful of Fortigates 90G - currently we have 3 setup in a non-production environment. We are receiving a TLS link between some sites and other sites will use ADVPN Hub\Spoke with SD-WAN and dual ISP. The VPN part is working fine and so I've removed those links for the time being. For the TLS we have 2VLANs on our hub FortiGate (200,300) setup under port3. Our PC connected to the main Fortigate can each all other Fortigates. The other PCs connected to the other Fortigate can reach the hub but cannot each the Fortigate at the other end. The reason looks like BGP is not interesting the route into the routing table. As it is the only path to the destination, I am not sure why and am clearly missing something. Willing to post any config that will help. Here are screen captures of what I'm referring to. The first one is the main Fortigate where the trunks for the TLS from our ISP will come in and the second one is th
If I follow the suggested steps below to remove my switches from management prior to exchanging the fortigate appliance, can someone please clarify what happens to the switch configuration? I've seen references to Fortigate specific items being deleted but can't find a definitive answer about the config in general. Trying to prepare for and avoid potential disaster when we change management. Thanks. On the root FortiGate, go to Security Fabric -> Fabric Connectors.In the topology tree, click on the FortiSwitch device you want to remove.Select the option to Deauthorize the device.
Has anyone used FortiConverter, and if so, what are your thoughts on it? I am replacing a 40F with an 80F. There is a fair bit of configuration on the 40F, I would think doing it with FortiConverter might take an hour as opposed to about 3 hours manually.I am planning to buy "FortiGate-80F 1 Year FortiConverter Service for one-time configuration conversion service. " Do I need any other licenses with this?
Polling resources using fortiweb api and send to influxdb. Using grafana for dashboard. Steps1. Linux Server preferably Ubuntuset static IPset NTPapt update && apt upgrade2. Install Dockersudo apt install apt-transport-https curlcurl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpgecho "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/nullapt updateapt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin -y3. Install Influxdb & Grafana Dockeruse provided docker compose file.take note of the influxdb details:org: my_apibucket: fwb_prodtoken: token <-- your tokenadd influxdb datasource in grafana4. Install python3 on Linux Server with modulesapt install python3-fullapt install python3-requ
Hello, we have installed two switches model fortiswitch-m426e-fpoe.The access points connected from port 17 to 24 does not come UP all patterns because the APS need 802.3bt (poe ++). Regarding this device, this model support poe++.How can activate this option in the 8 ports what support this option? Best Regards,
greetings guys,I am trying to understand how the sd-wan performance SLA probing traffic (for example, Ping/ICMP) is steered.I have configured the SD-WAN performance SLA, two member interfaces are selected in the SLA, let's say, port1 (MPLS in the picture) and port2 (OL_INET in the picture). the SLA is using Ping as the probing protocol probing the detect server 10.74.x.x.port 1 is an MPLS underlay interface, port 2 is an overlay based on Internet IPsec tunnel. If I use the CLI in fortigate, I do see the probing traffic (ICMP echo/request) is flowing through the member interface added in the SLA. diag sniffer packet OL_INET 'dst host 10.74.x.x' 4 0 ainterfaces=[OL_INET]filters=[dst host 10.74.x.x]2025-02-24 06:43:45.156019 OL_INET -- 10.250.a.b -> 10.74.x.x: icmp: echo request diag sniffer packet OL_INET 'src host 10.74.x.x' 4 0 ainterfaces=[OL_INET]filters=[src host 10.74.x.x]2025-02-24 08:01:03.828714 OL_INET -- 10.74.x.x -> 10.250.a.b: icmp: echo reply the 1
Installed Forticlient VPN on Macos 15 Sequoia.After trying to connect I'm getting the message "Initialize VPN system extension was failed" when trying to connect to our VPN. Also Forti Tray is nowhere to be found on Network extensions to turn it on.Do you have any solutions? We tried uninstalling/restart/reinstall but the problem remains the same.
Boa tarde Implementei uma regra baseada em usuários do Active Directory para o grupo de marketing.Neste grupo, bloqueei a categoria de compras (block), mas tenho alguns sites que se enquadram nesta categoria que permito (web rating overrides). Esses sites não são mais permitidos. Em outras palavras, pelo que percebi, todos os sites que estão nesta categoria de compras não estão mais respeitando as regras da whitelist. Como podemos fazer os ajustes para ativar isso mesmo que a categoria seja negar e permitir os sites?
Hi All, I am trying to find information if we can use "any" as source and destination interface in the security rules which are allowing traffic that will be routed base on the SD-WAN rules via the respective members of the SD-WAN zone, or it is mandatory to specify the zone in the the security policy. Thank you!
Despite having set "Assertion consumer service URL" in "config user saml" as "https://FQDN:PORT/remote/login?realm=REALM", authentication call always shows:AssertionConsumerServiceURL="https://FQDN:PORT/remote/saml/login"> The result is that after successful azure authentication, Fortinet VPN SSL clint tries to connect to:https://FQDN:PORT/remote/saml/login"and it fails because the Fortigate does not respond to it. The correct URL is: https://FQDN:PORT/remote/login?realm=REALM
hello everyone , i have problem FAZ version 7.4.6 is losing logs day over day i can't create reports i have 1 Ter disk , is there any suggestions on how to solve this problem thanks in advance .
Hi sir, I got issues on my new FortiSwitch FS-108F which bought on two days ago. In switch idle and standalone mode, and without any other Fortinet product connected to it: 1. There are several events about CPU_SENSOR reached/exceeded the threshold value, is it related to HW issue? 2. In the idle mode, no idea why the memory always over 60% utilization, and the system temp around 39~40 degree C. I am considering to return this device back to seller and request refund, but before that, I'd confirm if the device has problem to use. BTW, I have also export the debug report and sent it to Fortinet customer support for above issues. Thanks,Jacky
Hi Team, Can you help with the following issues:I want to restrict the number of mails received from incoming emails from Gmail, Yahoo, and Outlook domains. However, the session profile can only be applied to the IP Policy and not directly to domains. What solution is available?Is there a way to see the sender's IP address (not the sending server's IP) for an email on FortiMail?Thanks.
Hello on the forum! We have a configuration need where the SSL VPN tunnel mode user gets assigned a single static IP assigned via the portal when they sign in, and this IP must be the same with every login. The appropriate IPs assign correctly among the different users logging in, but I noticed with split tunneling turned off, the VPN assigns a gateway on the Forticlient PC incremented +1 from their fourth octet on the IP. For example: user gets assigned 192.168.1.1, and the gateway on the Forticlient PC = 192.168.1.2 and so forth (IPs used are just examples). I've noticed that turning on split tunneling eliminates this gateway, but we don't want these clients to have internet access. In the Addresses assigned through the VPN portals, I've tried assigning: a subnet = 192.168.1.1/32, and an IP range = 192.168.1.1 - 192.168.1.1 with no prevail. I've even tried configuring ippools with no prevail. I do have a static route in the firewall SSL interface
hi Guys, is there any explanation of why the documentation is providing wrong instructions on ansible fortimanager https://ansible-galaxy-fortimanager-docs.readthedocs.io/en/latest/docgen/fmgr_firewall_address.html#notes in the docs it mentions that to create a firewall address object with ansible the task, the yaml file has to look like this tasks: - name: Configure IPv4 addresses. fortinet.fortimanager.fmgr_firewall_address: bypass_validation: false adom: ansible state: present firewall_address: allow-routing: disable associated-interface: any name: "ansible-test1" visibility: disable now after a stupid amount of time troubleshooting with direct api calls to fortimanager and running a debug on fortimanager where direct api calls are working but the ansible yaml call doesnt and thats when I realized that the visibility: disable is the cause of the issu
Hello I'm trying to connect the EMS Server to an LDAPs Server and when testing, it return a "Protocol Error"The connection to LDAP it's strictly just for AD? Doesn't work with an OpenLDAP or FreeIPA? It´s possible to do with an OpenLDAP or FreeIPA? Or just doesn't work, thanks to brand integration? All the firewalls work like a charm with OpenLDAP and FreeIPA Ldaps. Thnks to all, for any advice!
Hi, we upgraded our core network by replacing the core firewall with FortiGate-600F and Aruba Switch 8360v2.The issue is with the interconnection between the FortiGate and Aruba switch. The 25 Gbps port (x5) on the FortiGate-600F is not working when the DAC cable is connected to the Aruba switch. There is no link on the port.We tested several DAC cables – original Fortinet DAC cable, and original Aruba DAC cable – but none of them worked.Interestingly, if the DAC cable is connected to two interfaces on the same unit, the port starts to work. There is a link on it. We connected the DAC cable to ports x5 and x6 on the FortiGate, creating a loop. Both DAC cables from Fortinet and Aruba were working. Similarly, on the Aruba side, creating a loop brought the interfaces up.Could you help me to fix this issue and understand why the interconnection between the two network devices is not working?Thank you
Dear Team,In the article "Prevent firmware upgrade depending on the current firmware license's expiration date" (7.4.2), it states that "In FortiOS 7.4.2 and above, enforcement of an active FortiGate firmware license to allow firmware upgrades has been improved. Enforcement is based on the expiry date of the current firmware license compared to the release date of the first GA release of a major version. For example, for FortiOS 7.4.x firmware upgrades, enforcement is based on the expiry date of the current support contract compared to the release date of FortiOS 7.4.0 GA." This means the FortiOS license expiration date must be later than the "first GA release" of a major version (e.g., 7.2.0, 7.4.0, 7.6.0, etc.). For instance, if the current FortiOS license expires on February 1, 2025, and the version is 7.2.x, it can be upgraded to 7.4.x because the 7.4.0 GA release date was May 11, 2023. It can also be upgraded to 7.6.x because the 7.4.0 GA release date was July 25, 2024.Further ass
Good morning everyone, I can't so much as ‘unravel’ a configuration and I'm trying to ask some of you if you can give me some advice. Host from network 10.0.0/24 ping host to network 192.168.0.0/24 all ipsec between the three firewalls are configured and workingI can only configure the first two firewalls (from left to the right)i have tried putting static routes, adding the 192.168.0.0 network in the vpn tunnels and also in the policies but i still cannot reach the host 192.168.0.20 from 10.0.0.20 Thanks a lot
unable to ping from FortiGate VM throw Port2 and Port3 to any connected device throw these two ports and also we enable Ping under each interface instead of can ping and hear Arp throw port1 when connect it throw any device.Can any one help me ?
Hello, Few days ago we've started having trouble with our Active Passive cluster of two 1000F fortigates running 7.2.10 firmware. After making changes on the primary unit, those changes does not propagate to secondary and after few minutes we see HA cluster out of sync. We've waiting couple of hours but they didn't synchronize. The only way to get synchronize back is to manually force it by CLI: diagnose sys ha checksum recalculateexecute ha synchronize start After executing those commands couple of times on both primary and secondary cluster becomes synchronized. Any ideas what happened?
We're having Fortigate 1000F in AP HA cluster. We're having an IPSEC tunnel with remote location where we have Wireless access points. Those access points are authorizing clients via NACVIEW radius server which is located on our side of IPSEC tunnel. Everything was working fine until we've upgraded our fortigates from 7.2.10 firmware to 7.4.7. After the upgrade all RADIUS traffic via IPSEC tunnel stoppped. No traffic is seen on policicies in traffic log. Log is set up to ALL and before the upgrade we've had all the traffic logged. And of course RADIUS authorization stopped working. No request are arriving to NACVIEW radius server from the AP controller on other side of IPSEC tunnel. After downgrading back to 7.2.10 everything started to work again. Is there any bug in 7.4.x firmware reguarding the radius traffic over IPSEC tunnel that anyone know of? We would like to upgrade to 7.4.x firmware due to new policy layout which is much more usefull than t
Hello, Currently I am working on configuration below and can not make it work. Point is that local PC and EC2 PC must communicate with each other. There is APN router which is not managed by me , so using red ipsec2 network to make required site to site connection. This scheme was used for long time but with additional PC in local network which was making required IPsec. Now I want to get rid of it and move everything to FortiGate. This is FortiGate F40 OS 7.0.0 . Ipsec configuration Could any body take a look and advise if this is even possible ? If it is maybe there some some special (like "site to site") name for configuration I could google? Thanks in advance.
I have 2 different internet connection on my fortigate, then i build vpn site to site from internet-A to the azure and configure the BGP and the connectios was established with below details.Azure BGP ASN is 65515 and peer ip is 172.16.0.64Fortinet Local ASN is 65103, then in the interface tunnel i set the IP 10.103.103.103 for local peer and remote IP is 172.16.0.64 255.255.255.255 When j try to build 2nd vpn site to site from internet-B to azure, the tunnel is up but the BGP was not established because if i set remote ip in the interface tunnel to 172.16.0.64 255.255.255.255 the fortigate say that ip already used in 1st tunnel.Also in the BGP neighboor what interface should i use for interface and update source bexause i have 2 internet connection. If i create another local BGP ASN in the fortigate, when i specifiyng ip 172.16.0.64 the fortigate also say the peer ip is duplicated. Anyone know how we can setup BGP for 2 different connection if the destionation only hav
Hi Team I am facing very slow connection speed when I am connected with Fiber Internet Wifi. But work good on Mobile Internet. FortiClient VPN 7.4.2.1737 Please help. RegardsSivakumar
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.