Mark a Best Answer
Fortinet Community
Recently active
Hello community, Is there a way to block MAB for rogue devices in FortiNAC? The issue i'm facing is with a Cisco Switch with the following configuration in the portsinterface GigabitEthernet1/0/9switchport access vlan 31switchport mode accessswitchport voice vlan 18authentication host-mode multi-domainauthentication order mab dot1xauthentication priority dot1x mabauthentication port-control autoauthentication periodicauthentication timer reauthenticate 180mabsnmp trap mac-notification change addedsnmp trap mac-notification change removeddot1x pae authenticatordot1x timeout quiet-period 10dot1x timeout server-timeout 30dot1x timeout tx-period 10spanning-tree portfast This port is intended to work with MAB for a Phone and with 802.1x for PC, however when a PC with no supplicant with certificate connected to the phone, the switch sends mac to FortiNAC, and I see Login OK with mac address, and therefore the device is able to receive the Default VLAN (in this case VLAN 31 whi
I cannot see the device hostname within Fortigate logs when they communicate internally, meaning within LAN but when the devices access the Internet meaning from LAN to WAN, i can see the hostname just fineDevice detection is already turned on for the LAN interfaceIs there anything else I should look for?
Fortiguard Servers unreachable via 2 Different Locations with two Different ISP'sDNS Debugging followed and ping responses from Fortigate's both show 290ms response times.Fortiguard Servers are set to use lowest latency location as well.Still unreachable, Is there an outage ?
Hi,After upgrading the FGT100F from 7.2.10 to 7.2.11 we are now seeing a user certificate prompt each time we attempt to connect to the admin interface for the 7.2.11 firewalls. I found the below article and run the following two commands, it appears we have already met those conditions.FGT100F # show full-configuration | grep admin-https-pki-requiredset admin-https-pki-required disableFGT100F # show user peerconfig user peerend Certificate prompt on Admin interface - Fortinet CommunityIt looks like we had the same issue as for v7.4.6 and v7.6.2 but the article states it is currently under investigation. I checked as well the upgrade path for FGT100F and it seemed upgrading to 7.4.8 and 7.6.3 is not an option for the fixed version.For your advise. TIA :)
Hello everyone, I wanted to share an odd issue we're encountering while using Let's Encrypt certificates (TLS-ALPN challenge) with FortiWeb. We're running FortiWeb 7.2.10 in a HA active-passive configuration, set up as a reverse proxy. The setup involves serving multiple sites under SNI, all using a single Let's Encrypt certificate with multiple domain names. To ensure everything is done over HTTPS, we chose to use the TLS-ALPN challenge, and everything worked fine during the configuration and certificate issuance stages. However, now that the sites are no longer required, we decided to revoke the certificates. That's where the problem starts. The revocation process appears to go as expected. I can see that the revoke requests are properly sent to Let's Encrypt, and when I check via OpenSSL, the certificate shows as revoked (verified against the certificate's OCSP URL with openssl). Additionally, the certificate's status updates to "revoked" on both the primary and secon
The 601e only has a single management port. I would like to configure one of the 1G physical ports, or something else, for management purposes. I ran across "https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/313152/out-of-band-management-with-reserved-management-interfaces" and "https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Reserved-Management-Interface/ta-p/190132". Are these the best approach? I don't need or want to be able to access this remotely. Simply for those times when someone is physically present, they can connect a device, and have access to the GUI/CUI without having to swap any existing management cable connections, and without having to go over the network.Note there are two 601e units in an HA configuration and is in a secured location. If it matters, it is also connected to FortiManager.
I have different 2 internet connection connected to my fortigate. Anyone know how we can build site to site VPN to azure with redundancy for my 2 internet line?
Hello guys. We have a couple of HTTP 1.1 web sites which sit behind our FortiWeb and we're having some issues with the chunked transfer encoding configuration. We're trying to follow the fortiweb troubleshooting guide instructions on the topicHow does Web Protection modules support Transfer.Encoding: chunked . According to the docs, we should set chunk encoding to enable and this should be enough for ensuring that buffering won't be used for those type of requests. Unfortunately, this isn't what we're seeing after enabling this setting. For starters, all the resources from the HTTP server are returned to the clients as chunked (even those that aren't being encoded into chunks by the http server), ie, fortiweb is transforming all http server responses into chunked transfers after enabling the previous setting (ex.: the http server will buffer js files before returning them and these requests are transformed into chunks which are then sent to the real client).&nb
Hello guys, Even though I'm still not sure on how FortiWeb supports chunked encoding, I'm hoping that someone can help me understand the faq's content on this topic, specificaly on the behavior form 7.0.2 onwards. The doc starts by saying the following: From 7.0.2, FortiWeb replaced set chunk decoding enable/disable with set chunk encoding disable/enable.The default configuration is disabled, which equals to set chunk decoding enable in 7.0.1; FortiWeb will decode chunked response and convert it with Content-Length.When configured as set chunk encoding enable on 7.0.2, FortiWeb decodes and reassembles the chunked response, performs the WAF modules’ operations, and encodes the new content with chunked again, then sends it to the clients. I understood it as saying that whenever FortiWeb detects a chunked encoded response from an HTTP 1.1 server, it will receive all the packets from the server, decode it and then apply all
Hello guys. Quick question: is there a way to completely bypass #Fortiweb (7.2.10) for specific URL request? For instance, suppose we have a web site with a config that looks something like this (this config inherits a default web protection profile which is shown at the end): edit "test" set server-pool some_pool set http-content-routing-id 11698441117558787025 config content-routing-match-list edit 1 set match-condition equal set match-expression site.something.org next end next Is there a way of saying that all the requests for a specific url (ex.: https://site.something.org/someuurl) should completely bypass the request and response validations performed by ###Fortiweb (Ie, for this URL, #Fortiweb should not apply any scans to the HTTP request and response and shouldn't also buffer the HTTP response before sendi
Hello guys. I'm trying to use an openapi doc to validate all the web api calls made to one of our web apps. I've already uploaded the openapi doc and set everything up. However, there's an issue: it seems like FWB can't handle array parameters passed through query string and it will always consider them a violation of the openapi docs. Here's a snippet of our openapi doc that is used for validation: openapi: 3.0.1 ... /api/pedidosassistencias/pesquisa: get: ... parameters: - name: estados in: query schema: type: array items: $ref: '#/components/schemas/EstadoPedido' description: Estados do pedido a filtrar ... `EstadoPedido` is an enum and the openapi doc does enforce those values (the ones passed on the next snippet are all valid). We've tried several different strategies in order to pass the array through the query string: // several parameters option 1 (
Hi all,I have a situation where there is a Wi-Fi network with 45-50 non-Fortinet APs, meaning the APs can't communicate with the Fortigate Wi-Fi Controller.On these APs, two SSIDs (with their respective VLANs) are defined: one for GUEST users and one for PREMIUM customers. What we want to achieveReplace the current gateway with something more robust, considering a Fortigate 121G.Enable a captive portal for the GUEST network that requires users to enter their email (email collection).Enable a captive portal for the PREMIUM network that requires authentication via username/password (using local users, FortiAuthenticator, or a RADIUS server)Questions:From the manuals, I saw that the type of captive portal must be defined in the SSID settings under "WiFi & Switch Controller."I read that it's possible to choose between Authentication, Email Collection, and other options.The issue is that we do not have Fortinet APs, so we cannot configure the SSIDs in this section.Is there a way to
Hello everyone!As part of our network infrastructure, we currently have a HEADQUARTER "A," which houses a datacenter with servers and services accessed from all our LANs (both in branch offices and headquarters).We are considering establishing a second HEADQUARTER ("B"), which will contain a mirrored datacenter to that of HQ "A."Considerations:Both HQs have Fortigate edge firewalls:HQ "A": Fortigate 600EHQ "B": Fortigate 900GBoth HQs and BOs are connected to a common MPLS service and have internet access through one or more ISPs.There is a dedicated fiber optic connection currently in use between HQ "A" and HQ "B."The objective is to ensure that, if the datacenter at HQ "A" becomes unavailable due to a technical issue (e.g., failure of HQ "A"'s firewall), the rest of the LANs can continue consuming services through HQ "B" until HQ "A"’s firewall is restored and resumes its primary role.Therefore, we would like to ask for your guidance on which Fortigate features and functions we can ut
Hello,i have a FW policy rule that allow traffic flow based on address object with type FQDNmatch based on FQDN "*.taobao.com"-when i start browsing main page is opening normally-when i start clicking on random sections , some of them is re-directed to alibaba CDN *.alicdn.com which is not included in FW policy address -so i added *.alicdn.com also to address group to be matched-blockage reduced significantly but still see some traffic not matched by the FW policy , and web site performance become very slow-up on checking found that FQDN address is not populated with all DNS queries customer doexample if opened item.taobao.com , will be dropped , i have to manually do Nslookup inside windows CMD , then IP will be populated inside Fortigate , then customer will be able to browse it-Note there is no proxy server used -if IP of subdomain is not included here , traffic destined will be droppeddiagnose test application dnsproxy 6vfid=1 name=*.taobao.com ver=IPv4 wait_list=0 timer=
I realize the following is a not so great idea but would like to know if this is even possible since management may require it.Is it possible to give all users with a valid AD account permissions to create pre-provisioned guest wireless accounts in FortiNAC? Based on the following snippet from the FNAC admin guide, I can't use the AD Domain Users group: "The domain users group cannot be used to set administrator privileges because user details for users in that group are not populated in FortiNAC when a directory synchronization is done." So, before I ask our AD admin to create a new group named something other than Domain Users and add all user accounts to it, I'm posting to see if this is even possible.
 Hi, we have two remote users accessing via mobile hotspot, and they encounter this problem: when the FortiClient establishes a connection, they lose their internet access. If they press diconnect the VPN, the internet returns.Be aware that when they are linked to the VPN, their internet symbol changes to this ( screenshot1) and when they disconnect it goes back to their hotspot symbol.( screenshot2)screenshot 2  screenshot 1 
Hi community I have Fortinet firewall 60F and want to attach 2 fortiswithes (48 ports each) as a failed backup. If switch A goes down then Switch B picks up. Any Idea how to make it happen ? thank you.
Hi everyone,I'm having a problem when I'm trying to access my Forti web interface through my network. It's accessible when I'm connected localy and the gear under it can be pinged and accessible through the network. My managment interface is situated in a VLAN reserved for every managment access in my network. Also I have two forti101E in HA mode active/passive, and therefore only one address for my mgmt interface. The ping, http and https are activated in my configuration. If you need any other info for troubleshooting, please feel free to ask me.Thanks in advance for your answers
Hi,As a replacement for SSL VPN for remote users, we have implemented IP SEC dialup.Users connect with forticlient. Everything works fine.However, I would like to be able to force the disconnection of sessions after a set time (i.e. 12 hours), even if traffic is generated.I have not been able to test any functional solutions.Do you have any idea how to do this?
good to all,I find myself in this situation: The goal is to allow the management of the FortiSwitch directly from the GUI of the FortiGate 91G located on site, even if the firewall and the switch are not directly connected via the FortiLink port. However, as shown in the diagram, there is an IPsec VPN tunnel.As per the attached diagram, the configuration already presents the IPSec VPN tunnls with related policies and static routes.
Hello,I used two fortigate 200E, i have an issue with the vpn.I'm on the IT team,I can connect the site with the vpn client (forticlient 7.0.3.0193) but only the files of our serveur file.No ping is working through the VPN or RDP or anything else except the file of the server file.I have an administrator acces on the VPN and i allow everything but it isn't workingHere is the configuration of the vpn.I made a user group "G-SSL-ADMIN" with the users allowedScreen 1On SSL-VPN Portals i made a full access groupScreen 2SSL-VPN Personal Bookmarks. Someone has an idea ? 
Hello,we have two Fortigate 1000F run in HA (Active/Passive).We will Connect to Cisco C9500x they run in SVL. The Connection from Fortigate (Fortinet SFP28) to Cisco Switch (Cisco SFP28) not work.Two Ports are in Aggregation/Portchannel to the Cisco Stack (4 Cabel Connection)We Test and have set the Port Speed to 25000full or the FEC disable/cl74 etc.Not work.At a Cisco sfp10g and in Fortigate we set the Speed to 10000full the link work.BTW a Cisco sfp with 1G work with the 25g port by set the speed to 1000full. The Cisco SFP28 works to outer Cisco Switch with the same model of SFP28.We have test this with an outer cisco 9500x with SVL an this dose not work.Version is on Forti 7.4.7The Aticel have we Test.25 Gigabit Ethernet connection between Fo... - Fortinet Community
Is there a way to keep a active VPN connection on a FG52E permanent alive even when there is no traffic?
Our FG120G started alerting to ISC.BIND.Multiple.Options.Processing.DoS blocked DNS traffic this morning, just occasionally (let's say 10 alerts in 10 hours), all from different Windows laptop clients talking to our DNS servers at the datacentre.I don't have any particular insight as to why this might have started. Perhaps a false positive. Perhaps Fortinet updated signatures. Perhaps Windows patches changed something.Just wondering if anyone else is noticing this issue. Hoping it isn't just me ...
We have recently had a 400F installed with three DIA lines. We have been set up with an SD-WAN configuration where traffic is spread over all 3 lines. This seemed to work great and the lines were balanced but we started to notice that certain websites would drop out, logging people off and applications such as Outlook would loose connectivity.We have narrowed it down to the fact that session traffic which starts on port 1 can then jump to port 2 or 3 changing our outbound IP and thus breaking any session the user had with the website they were visiting. We would ideally like to keep the round-robin approach where data is spread over the 3 lines automatically but we're not sure how best to configure the gate so traffic gets around this issue. Some research is pointing towards having the SD-WAN set up so that all traffic goes to port 1 and then to port 2 on a failure but is there a way to have traffic move to port 2 after a certain utilisation is reached
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.