Mark a Best Answer
Fortinet Community
Recently active
Hello, a FortiAnalyzer Cloud7.4.3 b5573 does not show a FortiGate 7.4.3 b2573 although the device is connected. I checked the serial number of the cloud instance and it matches with that one connected to the Fortigate.On the Fortigate I can switch in Log -> Forward Traffic to the Fortianalyzer and it presents all events. in the FortiAnalyzer Cloud account it says Quota is at 73%, but there are 0 devices shown.But in the local events I see the most recent events which came from the Fortigate. Also in Log View -> Log Browse I can display the older logs from yesterday on back to archived logs from months ago.In FortiView in Fortianalyzer Cloud it says Invalid params: No valid fabric member found. But in CLI it says:FAZVM64-VIO-CLOUD # diag log deviceDevice Name Device ID Used Space(logs / quarantine / content / IPS) Allocated Space Used%FCTEMS882400XXXX FCTEMS882400XXXX 0.0KB( 0.0KB/ 0.0KB/ 0.0KB/ 0.0KB) unlimited n/aFG100FTK2103XXX FG100FTK2103XXX 3.2GB( 3.2GB/ 0.0KB/ 0.0
Does anyone have information on the End of Life (EoL) date for FortiWeb 1000E? Any official sources or insights would be greatly appreciated. Thanks!
Hi, We tried installing v7.4.2.1737 on a few devices and they do not connect. Please advise.
I recently added a new disk to my FortiAnalyzer VM and successfully extended the storage. However, in ADOM, the additional disk space is not reflected in the total disk size—it still shows the previous total instead of the new extended capacity.Has anyone else experienced this issue? Is there a specific step required for ADOM to recognize and update the total disk space?Any help would be appreciated!Thanks.
Hello everyone,I am sending the logs from our EMS server directly to our FAZ as the syslog server option.I wanted to know if the logs sent from the EMS to a FortyAnalyzer are unencrypted or are they encrypted ?From the EMS server GUI the commands are limited, is there a command from the CLI to possibly enable encryption of the logs sent to the FAZ ?If so, is there anything else to configure on the FAZ side ? FortiAnalyzer #Forti EMS
Hi, We initially thought this was a Webtitan issue, however, when a user is connected to Forticlient VPN, websites that are blocked on Webtitan policies are being allowed to filter through and get accessed. If the user disconnects from VPN, and tries accessing those sites again, they then get blocked from Webtitan. Has anyone come across this issue before or can provide further details on why this may be happening? We think it may be a configuration issue with our Forticlient setup. Our VPN is a IP SEC VPN. We have tried several devices (Windows 10 PCs and Windows 11 OS laptops) and the same happens. This has happened for several different users on different Webtitan policies. I can provide further details if needed.
Hi everyone,We are currently using FortiWeb version 7.6.1, and we've noticed multiple requests coming from a specific source IP address in the traffic logs. All these requests are returning a 404 status code. We have configured DoS protection, imposed limits on HTTP access, and set up a custom rule in the advanced protection settings to restrict these requests. However, it seems that these measures are not effective. Could anyone provide guidance on how we can implement a rate-limiting rule to block requests from this IP address after 10 occurrences of a 404 response, and then enforce a block for 1 minute?Thank you for your assistance!
Hello guys,I'm kind of at my wits ends here.I have two FortiAP 431Gs on 7.4.5 managed via FortiLAN cloud. Both are connected to their own Fortigate 40F running 7.2.10. (So two sites, 1 AP each)The clients randomly drop throughout the day. Sometimes they will go a day or so without drops, then the clients will start to drop at random intervals sometimes every 5 minutes, sometimes every few hours. Looking at the logs, I do not see any error messages, just client wtp disconnect messages. CPU/Memory looks to be within acceptable bounds on both the AP and the Fortigate too.What is interesting is we have 27 other sites with the same settings and no reported issues - only difference is at these sites the AP is managed via the Fortigates...The only thing I can think of if it has something to do with FortiEdge Cloud. if it matters, the sites with the APs are in the southeastern united states but for some reason they were deployed to FortiLAN cloud in Canada.but I also hav
Dear Team,In my system, I am using an app service. This app has 2 NAT ports to the outside, port 4432 (used to encrypt HTTPS links) and port 802 (used to get HTTP app data). But the main protocol used is L7/TCP for the app api to work, it cannot use Profile HTTPS or HTTP. Is there a way for me to use L7/TCP and still configure content routing for port 802 and 4432?
MacOs Sequoia has changed to location of some of the security permission sets and the system extensions security profiles have changed. After installing 7.4.0.1645, the prompts to allow permissions takes a user to the permissions area where the defined permission set is no longer available to allow. You cannot continue beyond the FortiClient app prompt to change the security settings and the permissions cannot be given since the extension is not available to give permission to. Any word on a Sequoia compatible release?
Hello, I've come accross a problem, where I need to edit an interface through the CLI.The interface is a VLAN under FortiLinks, and is called "default".When I try to edit using the "edit in CLI" button, or con sys int through CLI, I get: FortigateName (interface) # edit "default"The input 'default' can't be interface name.node_check_object fail! for name default Is there a way to bypass this so I'm able to edit cli-only settings ?Thanks,FG101F - FortiOS 7.4.7
hello guysi have one forest and inside it have two domain controller DC1& DC2i have installed FSSO collector Agent on DC1 and already monitoring DC2in FG configuration already Added DC1 as primarymy question is can i install FSSO collector agent in DC2 and monitor DC1 too and add it as a secondary in FG configuration or it will not work
Good afternoon! I ask for help in explaining how to transfer a VLAN from one Fortigate to another.Network diagram:fortigate 1:network 172.16.50.2Cisco vlan 50-60dhcp is linked to ip addresses192.168.51.254/24192.168.52.254/24192.168.53.254/24192.168.54.254/24fortigate 2network 192.168.102.254/0vcenter 192.168.102.10has a task so that servers on vcenter can receive and have ip addresses with 1 fortigate.Site-to-site is currently configurednetwork 192.168.102.254/24 sees networks with 1 fortigateand vice versa.Unfortunately, my knowledge in this matter is scant and I do not understand how to make sure that I can specify the required vlans with 1 fortigate on vcenter.I will be grateful for any help, as well as for the direction that you can read
I have an AT&T fiber circuit where they handoff to me using a /30, but giving me an IP range in a using a /28. So for example Handoff IP is 1.2.3.8/255.255.255.252 Handoff Gateway 1.2.3.7 Usable IP Range 1.2.3.9-1.2.3.23 Since AT&T did not install their own managed router, I opted to use a Fortigate 80E to handle the NAT. 80E Wan1 is IP'd to 1.2.3.8/255.255.255.252 Static route 0.0.0.0/0 gateway 1.2.3.780E Lan is IP'd to 1.2.3.9/255.255.255.240 On the internal side of the network, I have a 100F that has it's wan1 IP to 1.2.3.11/255.255.255.240 sdwan gateway 1.2.3.9 All of this was working fine, untill I could no longer establish IPSec tunnels using port 500. FortiTac says it's an AT&T problem, AT&T says it's a firewall problem. So my question is, is there a way to eliminate the 80E as the management router for the AT&T circuit and bring the handoff strait to the 100F and still be able to us
Hi everyone,I'm facing an issue that I need help resolving. I'm trying to configure a FortiWiFi 40F to distribute the IPv6 ::/56 prefix provided by my Starlink High Performance connection. I believe you might know how to set this upI’ve checked some resources(https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/37673/ipv6-prefix-delegation), but they haven’t helped me successfully propagate IPv6 on the FortiWiFi 40F. I’ll attach the configuration script for your reference. I really appreciate any assistance you can provide. Best regards Octavio FortiWiFi-40F-3G4G (interface) # edit wanFortiWiFi-40F-3G4G (wan) # config ipv6FortiWiFi-40F-3G4G (ipv6) # showconfig ipv6set ip6-mode dhcpset ip6-allowaccess pingset dhcp6-prefix-delegation enableconfig dhcp6-iapd-listedit 1set prefix-hint ::/56nextendendFortiWiFi-40F-3G4G (ipv6) # getip6-mode : dhcpnd-mode : basicip6-address : ::/0ip6-allowaccess : pingicmp6-send-redirect : enablera-send
My L2TP client ip address is 10.10.100.2-10.10.100.50, can we assign ip address for each users? So if the client reconnected the client will have same ip address.
Hello,Today I have a server that is not part of my domain, but is in my IP Range, I need it to resolve an address https://plm.group.com/Windchill for server 192.168.20.2 to work https how do I do it inside the DNS server / DNS Database?
Hello, I have a specific website and I would like to access it through remote machines connected through IPSec VPN. The website only allows a connection from my WAN without fortigate. Can you help me access it, please?
Greetings, OUR ON-PREMISE ANALYZER, THE OS HAS BEEN CRASHED SO WE HAVE CREATED ANOTHER (NEW) VM SERVER AND INSTALLED THE FORTI ANALYZER AND BACKUP RESTORE HAS BEEN DONE. NOW, WE NEED HELP FOR THE DATA RESTORE. KINDLY GUIDE US. THANKS.
I had an issue with the sdwan, wan1 always state dead and the traffic isnt balance, more like 80 wan2 : 20 wan1 (i set 50:50 volume). I tried to research related the issue and find the wan1 overload. Is there any configuration to reset the volume or there might be an other issue? Note : i did not upgrade the firmware from v7.0.16 to v7.0.17 and my alternative solution so far is make static to wan1 priority and set policy object to wan2 Im begineer and try to gain more knowledge
Hi all,I am in the process of migrating from a Sophos XG210 firewall to a FortiGate 60F firewall, and I need some help with understanding the corresponding settings for WAN Link Manager.In the Sophos XG210, the WAN Link Manager allows configuration of IPv4 gateways, which provides a failover mechanism to shift between available gateways when certain conditions (like a failed ping to a specified IP) are met.According to the Sophos documentation, this configuration is part of managing WAN connections and ensuring availability through automatic failover to backup gateways.When researching the equivalent function on the FortiGate 60F, I came across SD-WAN configurations that seem to provide similar features for WAN failover. Could anyone who has experience with this kind of migration confirm if SD-WAN on FortiGate is indeed the correct solution for this?Any help or insights would be greatly appreciated! Thanks in advance for your time!
Hello! I have downloaded the free Forticlient VPN installer for Windows but after the message "the installer is about to start" nothing else appears and i can't install it. I have already had previous versions installed. Can someone help me? Thanks!!
Hey everyone,I recently attempted to set up Dial-Up VPN authentication using TOTPRadius in combination with an LDAP server and TOTP (Time-Based One-Time Password). TOTPRadius acts as a Proxy-RADIUS server and integrates LDAP authentication with TOTP for two-factor authentication. The setup process was based on the information provided by Token2's guide, which primarily explains how to configure TOTPRadius for admin login but does not explicitly mention VPN authentication. The Test Authentication worked, but when in combination with VPN it doesn't. The Problem:When trying to authenticate a Dial-Up VPN client using FortiGate and TOTPRadius, the authentication fails with the following error message from the TOTPRadius Server shown in Wireshark: Initial login not allowed; Empty password provided for user <blank-user>; Terminating process with Reject message This suggests that the FortiGate did not transmit the user’s password when performing VPN RADIUS authenticat
Hello, It's possible to make internet service group, example i want create Microsoft group and will contains all Microsoft predefined internet service?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.