Mark a Best Answer
Fortinet Community
Recently active
Hi all, completely new into FortiEMS or in generell into Fortinet.Right now we are running on FortiEMS Cloud 7.2.5.1061 and would like to upgrade to the newest version. Found this article:https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-upgrade-the-firmware-of-EMS-cloud/ta-p/216177 Unfortunately there are no informations about what time (only day) this will happen or something about how long this will take (will there be any downtime?). Thanks, regardsMarc
hello people. i need to upgrade my firewalls, and i want to upgrade to version 7.4.5, so, its recommended that i upgrade also the FAZ to version 7.4.5 Fortinet Security Fabric upgrade now the FAZ is in version 7.4.2, the upgrade path suggest to version 7.4.6 M, but here Recommended Release for FortiAnalyzer suggests to 7.2.9... what to do?should i ignore the fortigate recommendations? or ignore the recommended release path? or follow the recommended release path, and downgrade the FAZ? and it that way is he still compatible with fortigate 7.4.5?this way, this is not easy...thanks to all
hi,been trying to google search the "F" series platform/model (i.e. 40F, 101F) but got limited info/data sheets.just would like to ask:1.why is it called "F"? is it just an upgrade/iteration from previous "E" series2.is "F" series only got an upgraded ASIC/chip, i.e. SOC and CP and added number of CPUs?3.is item 2 above the only "selling" point of the "F" series?4.any other "unique" feature/distinction for the "F" series platform?
Hi,I'm trying to configure our Fortigate v7.4 to provide dialup IPSec VPN to FortiClient on Windows. The VPN works fine with user certificate but if I want to use computer certificate instead, or enable VPN before login, the VPN failed. I tried to give user access to the certificate key of the machine certificate without success. Any advices are much appreciated. Here is an abstract of the FG config: config vpn ipsec phase1-interface edit "Staff VPN" set type dynamic set interface "portn" set ike-version 2 set authmethod signature set peertype peergrp set net-device disable set mode-cfg enable set ipv4-dns-server1 x.x.x.x set proposal aes128-sha256 aes256-sha256 aes128gcm-prfsha256 aes256gcm-prfsha384 chacha20poly1305- prfsha256 set localid "StaffVPN" set comments "VPN: Staff VPN (Created by VPN wizard)"
Hello,i was looking for the OID in the FortiAP showing the number od client connected for each AP.Any guess ?Thank youB.
Hi, Based on document, I try to download and install evaluation license. But I got the error message. Anyone can help to take a look at it? Thank you very much. HQ-FW # execute vm-license-options account-id daxxxxx@gmail.comHQ-FW # execute vm-license-options account-password ayyyyyxHQ-FW # execute vm-licenseThis VM is using the evaluation license. This license does not expire.Limitations of the Evaluation VM license include:1.Support for low encryption operation only2.Maximum of 1 CPU and 2GiB of memory3.Maximum of three interfaces, firewall policies, and routes each4.No FortiCare SupportThis operation will reboot the system !Do you want to continue? (y/n)yRequesting FortiCare Trial license, proxy:(null)Forticare response error 61.Failed to download VM license. HQ-FW # get system statVersion: FortiGate-VM64-KVM v7.2.4,build1396,230131 (GA.F)Virus-DB: 1.00000(2018-04-09 18:07)Extended DB: 1.00000(2018-04-09 18:07)Extreme DB: 1.00000(2018-04-09 18:07)AV AI/ML Model: 0.000
Hi, last week we updated our FG cluster to FG200F with 7.4.5.We had some problems but in general it seems quite OK. Only with SSL VPN we still have problems and we cnat get it functioning.1. Connecting with Local User it works fine, I get the certificate window and I can login, no prob!2. User from LDAP, connection to LDAP works fine, I can even test my credentials and OK but than connecting to the SSL VPN I dont geht the ceretificate pop up and after 48% I get Permission denied and -455We did the same as in all other FGs. We imported the same remote certificate and everywhere it works. We checked groups and everything and it should be OK.In System Events VPN I get:Action ssl-login-failReason sslvpn_login_unknown_user What else can we try? It seems like the FG is not checking the certificate and we try with "Require Client certificate" and without and no change Thanks!
Good morning everyone,I am experiencing a problem in my environment. Sometimes the 60F firewalls in version 7.2.10 are losing communication with the LAN and the WAN remains normal. In the ping test, I do not have continuous feedback from the LAN and it remains like this, losing many packets, consequently I lose connectivity from the location where the fortigate is located.
hello, On a Fortinet vdom I need to migrate current SSL VPN with LDAP Auth to Azure SAML Auth.There are LDAP Auth UserGruups, every UserGroup is mapped to a single VPN SSL Portal.What I need to achieve is to set up Azure SAML Auth and map new User Groups to the same VPN Portals. UserGroup-1-LDAP -> Portal-VPN-SSL-1UserGroup-1-SAML-AZURE -> Portal-VPN-SSL-1 Is it possible without compromise or modify actual VPN SSL Portal configuration? Thanks a lot, Graziano
So i recently set up an Authentik radius server it works properly as tested by radtest and NTRadPing Authentik itself also returns "accept" when asked by fortigate But fortigate refuses to acknowledge that anything is properly configured debug response:RTR-032 # diagnose test authserver radius VFX_Authentik pap test testauthenticate 'test' against 'pap' failed, assigned_rad_session_id=103199522320389 session_timeout=0 secs idle_timeout=0 secs!Does anyone have any idea what could be wrong?
Trying to register a FortiGate 60F Firmware 6.4.6, clicked Register, Login, filled-in Email, Password, and Country, but the Reseller field has no drop-down.How do I register?
Many moons ago, when I was first learning FortiGate firewalls, I was taught to use the VPN IPsec Wizard to create the initial VPN but then convert the tunnel from a "Site to Site - FortiGate" tunnel to a "Custom Tunnel". At the time I wasn't doing many VPN connections to other FortiGates, so that is always the way I've built a tunnel. Now, I'm doing more FortiGate to FortiGate VPN connections and I'm wondering if the "Site to Site - FortiGate" tunnel template is "better" for FortiGate to FortiGate connections? It seems like using the "Site to Site - FortiGate" on each side reduces the chances of misconfiguration but perhaps it's also a security concern? Either works for me, I'm just curious if one or the other is considered "better" or if it's just sort of "dealers choice".TIA!*****EDIT*****There seems to be some misunderstanding with what my question is. Let me try and clarify. When creating a FortiGate to FortiGate VPN using the IPse
Hi FG admins From this tech tip:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Most-common-cases-of-SIP-implementation/ta-p/190676 I have this scenario (phones behind NAT): Did all the required config, and even more:config system settings set sip-expectation disable set sip-nat-trace disable set default-voip-alg-mode kernel-helper-basedendconfig system session-helper delete 13endconfig voip profile edit "default" config sip set rtp disable set contact-fixup disable end end... Played with the above parameters and FG reboot but didn't work. I mean I have this behavior:Calling from internal IP phone to external mobile cell phone (GSM): It rings but no voiceCalling from internal IP phone to internal IP phone: IP phone doesn't even ringIn the traffic logs I could see some "TCP reset from server" on SIP connections.So I'm starting to think that probably on server side must be somehow configured to accept calls from IP phones behind NAT. Anyone knows somet
I'm having an hard time to forward internet traffic over IPsec tunnel for specific subnets, basically i want that computers in the siteB subtnet access the internet though SiteB gateway via the IPsec tunnel. This is the official documentation: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Forward-internet-traffic-over-IPsec-tunnel-for/ta-p/328628 First of all it's poorly explained how to add the gateway to the phase 2 selectors (Note: make sure to include the gateway IP in phase 2 selectors of the tunnel to allow traffic) Can someone more advanced that me explain how to do it? Many thanks
Hi, since this connection is new for us we dont have a lot of experience. The headquarter is in EU with 200F 7.4.5 and the new office is in the US 100F 7.4.5. Users are working with IPSec between the FGs and working on File Servers. In the HQ we use dedicated 1/1GB access for this VPN and in the US we have 1/1GB for all traffic for this >30 users. First thing, one week they dont complain at all, than another week all users complain every day. Checking our internet access we never find a problem. There it is more complicated since there is no technician but doing speedtest on pages in Europe he downloads test files with 1GB almost as fast as we do here. When it is getting really bad, they say e.g that working on a Terminal Server in our HG the mouse moves really, really slow. Than we started doing testing with iperf and with VIPs on both sides to the iperf server. We tried also from other FGs in Europe to our HQ and we got always > 300-500mb to this iperf server beh
Hello experts, I want to implement SAML authentication for some web application.The trick is that, I need the on-prem users, who already signed in to their domain accounts to be given the assertion directly without being re-directed to a login form. I did integrate FAC with the DC using "windows event log " method. Is there anyway to link a user who is redirected through SAML to FAC by his IP address with a user that already has an SSO session, so that the user is not prompt to actively login again?
Hello, I have a multisite(a,b,c,d) Fortigate setup and plan on turning on Site-to-Site VPN.That part is fairly straight forward. I also plan to connect one of my sites(a) to AWS via a site-to-site VPN. Will it be possible to have sites b,c,d talk to AWS via the tunnel at site a?I want to avoid connecting all FortiGate sites to AWS, as AWS charges per VPN connection. Thanks for any information
What is the user limit of the FortiAnalyzer-100C device? Is there any supporting documentation?
i have enabled syslog logging for 1x FG100E and 1 x FG100F.but the log collector does not seems to receive any logs from these 2.Only the main firewall FG401E is able to send logs to the log collector without issues.is there any limitations for FG100 series ?
Hi,I am now facing an issue. My internet connection is using pppoe with dynamic ipv6 prefix.Device: fortigate 60eFirmware: 7.4.7 When my pppoe connection is disconnected, reconnected or other reasons causing this interface down. After a few seconds, pppoe connection is up again, fortigate gets a new PD /60 range from ISP and delegates new IPs to internal devices.PCs are assgined a new ip separately, but the old one is still existed, and contiune to use the old one to initiate new connections.I find some information using below command, these are two Windows devices:Actually the first(already deprecated, waited for 48 hours ), second, and third addresses are invalid, but the second, third ones are still in 首选寿命(preferred state), Windows still uses it to initiate new connections. netsh interface ipv6 show addresses 接口 3: vEthernet (VLAN101) 地址类型 DAD 状态 有效寿命 首选寿命 地址 --------- ----------- ---------- ---------- ------------------------ 公用 反对
Fortianalyzer running on v7.2.9 facing issue related to logs are not being deleted.IN the Data policy - Keep Logs for Analytics is 60 days & Keep Logs for Archive is 365 DAys. I have enable auto deletion under file management - delete file older than 365 days. but in the storage info, i see in the Archive(actual/config days) - 683/365 days... As per the config it should delete the archive logs older than 365 days but it didnt instead showing 683 days.. if i check in the log browse, it shows only last 3 months of archive data... please guide me on this - How to delete the archive logs older than 365 days and why the automatic deletion not working... FortiAnalyzer PFA
I am having trouble deleting an Access Point on the FortiWLC 8.4-3build-4 | FortiWLC-500D The error message reads as follows:ERROR: Ap is being used by a Service Connect's Location Profile. Any tips would be great.
Good day,I need an explanation or on the contrary a solution to the following problem(Note: I am an amateur in this world and my English is not very good) I have a machine with IP 192.168.1.10, I also have two ISP channels, these are located within the virtual-wan-link SDWAN zone and finally I have a rule for the Internet output of the mentioned machine When reviewing the machine's traffic, it is evident that its output is being generated through my first Internet channel and in addition, packets are seen sent but not received by the destinations, that is, web pages. As a solution to this problem, an SDWAN rule was created so that all traffic to the Internet from said machine was carried out through my second Internet channel, which generated an effective response, that is, packets sent by the source (Machine) were shown as packets received by the destination (Web pages). We consulted with the provider of our first internet channel to determine if the public
I would like to permit only screenconnect (cloud hosted) on a computer that is in network. This computer does not need internet but we would like to be able to connect to it remotely via screenconnect in case of troubleshoot. We already do this at another site but with logmein (similar product) and it works perfectly but in that case I can select all the logmein destination (internet service) but there's is no screenconnect or connectwise entry in the internet service section on the fortigate. Is there any way that I could do this?
Dear All, I am experiencing an issue with the built-in SSL VPN on Windows 11 version 24H2. While the VPN connection is successfully established, no traffic is received on the FortiGate when attempting to access applications through the VPN. We suspect the issue may be related to FortiClient. We are using the FortiClient application from the Microsoft Store: Notably, I have tested the same setup on Windows 11 version 23H11, and no issues were encountered. Please advise on how to proceed with troubleshooting this issue.Best regards,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.