Mark a Best Answer
Fortinet Community
Recently active
Hello team! I enabled automatic firmware upgrade yesterday in many Fortigates for mondays, between 23:00 and 00:00 hs.Today I saw that no one was updated.Looking up in one of them, I see the following log generated in the time range specified for the upgrade: date=2025-02-24 time=23:15:54 eventtime=1740449753919494910 tz="-0300" logid="0100032263" type="event" subtype="system" level="notice" vd="root" logdesc="Automatic firmware upgrade schedule changed" user="system" msg="System patch-level auto-upgrade new image installation scheduled between local time Mon Mar 3 23:27:11 2025 and local time Tue Mar 4 00:00:00 2025." No one changed the settings.Any idea? Thanks in advance.Regards,Damián
As per - https://docs.fortinet.com/document/fortiauthenticator/6.5.0/cookbook/578250/fortiauthenticator-as-a-wireless-guest-portal-for-fortigate it says at the end "Configuring firewall authentication portal settings on FortiGateThe following settings are required to avoid certificate and security errors on the client. After the user is authenticated using the external captive portal, the browser redirects briefly to the firewall authentication portal over HTTPS. The browser then redirects the user to the original URL or a specific URL.The specific URL needs to be configured in the Redirect after Captive Portal option in Create New SSID dialog.To configure firewall authentication portal address from the CLI:Enter the following commands to set to the firewall authentication portal address:config firewall auth-portalset portal-addr <addr> #portal-addr setting must be an FQDN that resolves to the interface IP address of the guest SSID. The client must b
I have a user that can't connect with vpn, at 40% it stops with no error message.Credentials work in other pc and it doesn't work even after reinstalling the client.Those are the logs: error sslvpn date=2023-03-01 time=13:01:02 logver=1 id=96603 type=securityevent subtype=sslvpn eventtype=error level=error uid=20D6F7F9ABF846289AB9F8EB73145321 devid=FCT8003723094774 hostname=XXXX pcdomain=XXXXX.local deviceip=192.168.1.10 devicemac=xxxxxxxx site=N/A fctver=7.0.5.0238 fgtserial=FCT8003723094774 emsserial=N/A os="Microsoft Windows 10 Professional Edition, 64-bit (build 19041)" user=xxxx@xxxx msg="SSLVPN tunnel connection failed" vpnstate= vpntunnel="xxxxxx" vpnuser=federica.biz remotegw=x.x.x.x Can someone help me?Thank you
When will there be an ARM64 Windows 11 version of the FortiClient VPN client be available?I'm technical consultant working for many customers with many different VPN solutions. I'm using Windows under a Parallels Desktop VM to access those systems on a Macbook pro.Now I switched to a new Macbook Pro with Apple M1 cpu which has an ARM64 architecture. So I'm now on Windows 11 ARM version. Cisco is the only VPN client (and those on virtual desktops) which is working in this constellation. I tried the 32 and 64 bit versions of the current windows FortiClients, none is working.I think there has to be a new ARM Windows version with a new tap-module to solve the problem.Has anyone a clue? Best regardsFrank
Hello. I want to let "normal" users with the role "Standard User" to add secrets as their favorites. As you can see in the screenshot the option at a normal user is greyed out with that role. Admin users can add secrets to their favorites. Can somebody help in which right is neccessary to add secrets as favorite? FortiPAM is running on version 1.5.0.
Hi, I try to register with Evaluation VM license fortigate VM, but I can't do it via https and ssh. Below are logs and my findings. Can you help me? Ping to FortiGate-VM64-KVM # execute ping guard.fortinet.netPING guard.fortinet.net (12.34.97.71): 56 data bytes64 bytes from 12.34.97.71: icmp_seq=0 ttl=52 time=107.7 ms64 bytes from 12.34.97.71: icmp_seq=1 ttl=52 time=112.1 ms^C--- guard.fortinet.net ping statistics ---2 packets transmitted, 2 packets received, 0% packet lossround-trip min/avg/max = 107.7/109.9/112.1 msFortiGate-VM64-KVM # execute ping service.fortiguard.netPING guard.fortinet.net (12.34.97.71): 56 data bytes64 bytes from 12.34.97.71: icmp_seq=0 ttl=52 time=107.6 ms64 bytes from 12.34.97.71: icmp_seq=1 ttl=52 time=107.6 ms--- guard.fortinet.net ping statistics ---2 packets transmitted, 2 packets received, 0% packet lossround-trip min/avg/max = 107.6/107.6/107.6 msFortiGate-VM64-KVM # execute ping update.fortiguard.netPING fds1.fortinet.com (173.243.138.71): 56
Hello. I'm having a trouble setting up OSPF over IPSec in the network of my company. We actually have created VPN tunnels between each branch office. This tunnels are in a simple configuration with static routes working well. We want to configure OSPF over this tunnels for, in a future, establish a dynamic full mesh topology. I thought it was just like configuring any device for OSPF, however I was wrong. I need to know what Networks in the OSPF web based manager means. Let me explained. I thought I should establish there the networks i want to broadcast OSPF files by, so it would be the public network IP. I did this but it didn't work. Then, I put the IP intern network and neither work. I've already configure Interfaces (the tunnel interfaces) and established to redistribute connected networks and static ones. I'm getting crazy. If you know something, everything can help. Thanks a lot.
I am practicing land attack block in an offline network with Fortigate 60D. If you "set block-land-attack enable" in "config system settings" and then LAND attack the device, won't it be logged? When I look at events or logs, I don't see the log saying it was blocked. Where should I look?Reference material:https://docs.fortinet.com/document/fortigate/6.0.0/handbook/533753/blocking-land-attacks-in-transparent-mode
Hi All, I need to know which Internet services/applications should be enabled/allowed through a Fortinet FW in order to allow Windows PCs to receive Windows/Office updates.
How can i get application signatures from api request? i want to save all app in varaible
This is the situation: We have a rule that allows a Dynamics 365 Business Central IP to access an on-premises SQL Server via an API. The rule functions properly and returns the expected output. However, the issue we are encountering is that the IPs for Dynamics 365 Business Central are dynamic. I created an external Fabric Connector to Azure, which showed up as running. Then, I created an address with the type set to Dynamic. The SDN Connector was Azure, and I set the ServiceTag = Dynamics365BusinessCentral. This setup is supposed to allow access to all dynamic IPs for Business Central. According to the Fortinet example, once the connector is completed, the addresses should populate automatically. However, I am not receiving any addresses. Business Central changes IPs weekly, and I do not want to update this manually—I am looking to automate the process. FortiGate 301e v7.4.7 build2731
Hi everyone,we are using FortiMail 7.6.2. Now we observe the following problem:If an e-mail contains an SAP order confirmation with interactive fields, FortiMail will not accept the e-mailIn our mailflow, there is a mail server of a service provider before the FortiMail, which accepts the e-mails and then forwards them to the FortiMail.If the service provider tries to forward such an e-mail to FortiMail, it receives the following meaningless error message:"delivery temporarily suspended: lost connection with “IP FortiMail” while sending end of data."In the mail event on the FortiMail you can only see that an attempt is made to forward the e-mail to the FortiMail every hour.Now we have also found the cause. The e-mails are only blocked if “PDF” is activated in the content profile under Content Disarm and Reconstruction.Has anyone had experience of this or found a solution?We don't really want to completely deactivate this check to avoid blockages. Maintaining each affected sender m
Hey members, I have been trying to upgrade my FortiNAC server from v7.4.0.0427 (GA) to 7.4.1.0451 but its failing.I cannot reach fnac-updates.fortinet.net but am am able to ping 8.8.8.8. FortiNAC
I try to enable SNMP on management interface but always failed, the SNMP server can't connect to the Fortinet. If i enable the SNMP on LAN interface the SNMP server can connect. Anyone know here who to configure the SNMP on Management Interface?
Hello, I am a new network engineer from Japan and would like to hear your thoughts on a problem I am facing. I am conducting communication tests with two FortiGate 100F devices in HA active/passive configuration. In addition, I have created four VDOMs and configured two Vclusters. ・Vcluster 1:root、VDOM1・Vcluster 2:VDOM2、VDOM3、VDOM4 (The composition). The priority settings are as follows: ・Active device: Vcluster 1 (priority 200), Vcluster 2 (priority 100) ・Passive device: Vcluster 1 (priority 100), Vcluster 2 (priority 200) (Example: Active device settings). config system haset group-id 1set group-name "FW-HA"set mode a-pset password ENC xxxxxxxxxset hbdev "ha1" 50 "ha2" 50set session-pickup enableset ha-mgmt-status enableconfig ha-mgmt-interfacesedit 1set interface "VLAN10"nextendset vcluster-status enableconfigvclusteredit 1 Override Settings Disabled Priority set 200 monitor "x1" "x2" set vdom "VDOM1" "root" next edit 2 set override disabled set prio
Hello I am having problems connecting to the FortiGuard servers on a FortiGate 40f firmware v7.0.13 build0566 (Mature) (HA Cluster). I am also receiving the message "FortiGate time is out of sync.", I use an NTP server 200.160.0.8. Images belowFrom FortiGate, I can ping the servers service.fortiguard.net, update.fortiguard.net, guard.fortinet.net. I get a response time of approximately 150ms. And I can also ping the IP 200.160.0.8 with approximately 18ms of response time. The output of the "diagnose debug rating" command is shown below: I also tried changing from https to udp with port 8888 with the commands below and I was also unsuccessful.config system fortiguard set fortiguard-anycast disable set protocol udp set port 8888 set sdns-server-ip 208.91.112.220 <-- IMPORTANT TO ADD THIS OR ANY OTHER FDN SERVER TO PREVENT DOWNTIME! endI have two internet links and I can ping the Fortiguard servers from both links. Both internet links are PPPOE. I tried to change th
where application control and web filtering are working fine on the LAN, but when trying to access YouTube or Facebook on your mobile device, the filtering is not being applied.
Hi, I have been given a task to activate the SSL Certificate inspection (not full) on the inbound traffic (on published servers lets say) so I tried to search for almost one week but couldn't get anything on the inbound traffic SSL inspection I have some questions if you can help me with that I would really appreciate it :1-What is the difference between Full inspection and SSL Certificate inspection and which one would be best practice? as am trying to test out some stuff on the published test server.2-What is the best practice for SSL Certificate and just to give you more information we user VIP as I found the some information it says that the traffic would be decrypted when coming to the firewall and traffic would be inspected then rencrypted the question here is which CA do I use in the certificate option ? 3-anything related links sources would be really appreciated for more info on the inbound SSL Certificate inspection as I tried to search found little info I know am d
So I've created a ticket with Fortinet, and I don't think the tech understood what I was asking so I'll try to explain my question here to see if anyone else has this same problem. I've got one Fortigate that was setup for my company's IPSEC VPN tunnel, and we have roughly 170 Fortitoken Mobile licenses that have been input using multiple license packs as we've built up to 170 over time (several packs of 20 licenses, and one pack of 50). For the sake of this example, let's say that I have the following. Pack 1 - 20Pack 2 - 20Pack 3 - 50Pack 4 - 20Pack 5 - 20Pack 6 - 20 Well we've run into a problem with our internet pipe where we have reached the maximum number of sessions allowed on the circuit, and we need to offload some of the users to a different firewall/internet pipe. Easy enough right? When I contacted Fortinet, they wanted to know which license file I wanted to transfer, but my question for them was that I wanted to know which token serial
Hi, I have recently setup SAML auth with Azure AD but cant get it to work via Forticlient. Users can login to the webportal and auth using SSO successfully, its just Forticlient that fails. When users try to connect via Forticlient they are directed to the correct Microsoft Login URL and can successfully auth with their Azure creds(including MFA) but after accepting the MFA prompt Forticlient stops at 48% and shows "Credential or SSLVPN configuration is wrong (-7200)". Checking the SSL-VPN Monitor in the Forti shows the user as being connected but only with "Web Connections" instead of "Tunnel Connections" It almost like when authenticating Forticlient cant find the user in a User Group so assigned it to the Web-access portal Running Forticlient 7.0 and firmware 7.0.1 on the Forti There is a post on Reddit about the SLL-VPN certificate key length having to be 2048 but we are using a certificate with a key length of 4096. CONFIG
I am trying to install FortiEDR 6.2 Core/JumpBox, but the installation is asking for an ISO provided by Fortinet. I followed the steps in the official documentation, but I couldn’t find how to obtain the required ISO.Does anyone know where I can get this ISO? Any help would be appreciated.
How do i force an update of the IPS db? I did a quick check and got this error message. Databases: Virus, IPS, Application Control, etc. versions and dates are listed. Critically, the IPS and Proxy-IPS databases are from 2015.IMMEDIATELY UPDATE THE IPS AND PROXY-IPS DATABASES. This is the top priority due to the significant security vulnerability. Check other database versions as well.
Dear Guys, I need your suggestions related to the weird issue on a Fortigate Firewall which is related to an SMBv2 Application. As the Fortigate FW, Client and the Server lie in a single network and also I would say in a single subnet. Fortigate is running in a NAT-mode, also I have created a Virtual Wire Pair with the two interfaces whereas port15 is connected to a to Client and port 16 which is connected to a L3 Switch(MPLS Provider) where the Application Server resides. Its a sort of a Car Application, that check the employees and revert the daily results of the working hours. However, with Fortiagte once I have login the application and trying to access through the Client it doesn't show anything only reverts with a blank page. I have been stuck in this issue for 2 weeks. Even though I have been in contact with FortiTAC Support but they said Fortigate is working fine and there is a problem with the Application seems to be something on it after seeing the Packet Capture. Whene
FortiAnalyzer-100C: What are the user limits for the device? Is there support documentation?
Good day everyone, I've been trying to use the official Chrome Extension for searching from here https://chromewebstore.google.com/detail/fortinet-google-search/nhemkpkfgilmlepjncbgojlojaekhibm?pli=1 and no matter what I click it shows just 1 page of the search results. So wanted to ask - is it something on my side or it is by design this way?Thank you
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.