Mark a Best Answer
Fortinet Community
Recently active
hello guys i have problem with this api request start = 0 limit=1 all_policies=[] while true: url = f"{base_url}/api/v2/cmdb/firewall/policy?vdom={vdom}&start={start}&rows={limit}" response = requests.get(url, headers=headers, verify=False) if response.status_code == 200: policies = response.json().get("results", []) all_policies.append(policies) if not policies: break # No more policies to fetch start+=limit​ when i print all_policies in every loop, the first log show every request, that means the start in the URL does not work correctlyhow can i take logs block by block?the first request get log number 1 to 1000the second request get log number 1001 to 2000and so on
Hi, Can I configure site to site vpn between 2 sites, one of them is dynamic IP address. Thanks,
I want to change the API request period in terms of time. I want it to be from now until a month ago. I want to specify the policy ID and also not take all the logs in one request. I want it to take the first 10,000 logs and then take from 10,000 to 20,000 and so on.How can I do that??
Hello, I have come across an issue when using multiple captive portals on a FortiGate on separate interface (SSID's). I have a GUEST and BYOD portal, both using remote authentication for each. The goal is to avoid certificate errors completely, so I have an FQDN which matches a wildcard certificate, and a local DNS record for the internal interface IP mapped to each respective FQDN, with each interface configured in recursive mode (all works). The issue lies with the redirect once authenticated. The only way I can get the redirect to work after successful authentication is to configure the portal-add under user firewall auth-portal pointing to the a single fqdn: configure firewall auth-portal set portal-add guest.fqdn.comend This is a global command and cannot be duplicated as far as I'm aware, so either GUEST will work or BYOD, not both at the same time. I believe it is possible to configure the portal-addr on the interface where captive portal
Hello experts, Am trying to find a way to block download exe files over whatsapp using fortigate f70, i have applied the file policy along with ssl deep inspection, also applied application control polciy to block file upload and file downlod from whatsapp as per below document : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Block-WhatsApp-file-uploads-action-by-using/ta-p/219694 After that we have tested, all files have been blocked over whatsapp, however we only require to block exe files over whatsapp, how we can achive that?
ask how to activate this feature after I create an account with Forti Token?
Good day, my name is gafar. I have a case in my office, which is to setup SD-WAN between two Fortigate site office and Head Office (HO). we use two links, one is a local radio link via connection provider (L2) and another one is through IPsec Tunnel via internet (Starlink). Can someone point me a guide for this? because i already tried the guide below, but it doesnt seems to fit the purpose, since one of the links are just a LAN. Technical-Tip-Configure-IPsec-VPN-with-SD-WAN Also, kinda confused with the local and remote address in ipsec sdwan, should we create all the IP subnet in the routing table as a remote address in ipsec configuration? below i attach the simple topology. Thanks before. Gafar.
We have requirements to block all the requests except Google Firebase , what is the best practise to achieve that ?BTW we have got on some links below that related to google cloud service and is there any other links that related to firebase service. firebasedynamiclinks.googleapis.com
I would like to know if the fortigate 200F supports the mirror port, and what this option is called
Hello, I'm trying to add a new worker to a shard. The test is successfull but if i try to deploy it i get following error: ClickHouse provision error: ClickHouse DDL Failure: One of the entries is already present in ClickHouse-Keeper registry. This could happen if a previous instance with the same is not cleaned up from the ClickHouse Keeper registry.To delete the offending entry, follow Step 8 in Deleting from ClickHouse Cluster section in user guide: https://help.fortinet.com/fsiem/7-0-0/Online-Help/HTML5_Help/clickhouse_config.htm#Advanced. There is no step 8 in this user guide. How can i fix this? Kind regards
Hey guys, we have received below mail from Forticloud. Dear Customer,We are reaching out to inform you about an important update regarding FortiGates provisioned to FortiGate Cloud without active subscriptions.To ensure robust security posture of your devices, starting Feb 28, 2025 FortiGate devices without an active FortiGate Cloud subscription will be required to upgrade to the latest firmware patch within 7 days of patch GA release.This change ensures enhanced security, reliability, and compliance with the latest features and updates provided by FortiGate Cloud. FortiGate Cloud will provide notification and prompts for upgrade when new patches are available on the web portal and the option to configure the upgrade time/day window of choice within 7-day schedule for convenience. Please note that cloud access and log upload to FortiGate Cloud can be restricted if not upgraded for devices without subscription. We are not using FortiGate Cloud, but we do send logs from o
Hi everyone,I'm relatively new to networking and eager to learn.I would appreciate your input regarding a technical solution. Specifically, in the following architecture, I aim to facilitate communication between zones using two firewalls configured in High Availability (HA) active-passive mode. The challenge lies in achieving complete redundancy without employing intermediate switches between servers and firewalls. In the scenario where, for instance, FG1 is the active firewall and the connection between SRV1 and FG1 drops for a specific reason, I'm unsure how to achieve full redundancy without using intermediate switches. In such cases, the only solution seems to be manually forcing an HA failover. I'm thinking about using HA active-active, but I haven't used FortiGate devices in this mode before, and I'm uncertain if it's the optimal solution. I understand that having a pair of switches between servers and firewalls is preferable, but due to space and cost constraints
Has anyone ever managed to connect a Fortigate with SSO/SAML using Keycloak? For Login Administrators.I have already spent many days with it and failed in all directions. UCS is used as the Keycloak backend (LDAP)
I noticed that in Policy & Objects there is at CLI Configurations > Objects > router some router objects like prefix-list and route-map. This seems to achieve something when first wanting to use a prefix-list or route-map for example in the Device BGP configuration. But later changes in the Policy & Objects on that configuration don't seem to have an effect. Did anyone work with this successfully? How did you make this work?
Hi all, I am trying to establish a ZTNA replacement of our VPN for all AD-joined devices.The first problem I have encountered is that workstations cannot resolve the domain controllers - our internal DNS server is accessible on TCP 53, but it tries UDP 53 to the DHCP provided DNS server of my remote users. So my users are unable to change their passwords, force local password changes and etc. Does anyone succeeded in establishing ZTNA for AD environment?
Hi,I am using Fortigate 200D Firmware v5.4.1,build1064 (GA)Recently, there is the message when I log in "Conserve mode activated due to high memory usage" Memory Usage 85%Could you help me fix this issue?Thank you.
Hello community. Can anybody make me understand two things as I mentioned in subject, how packet flow happens If first time remote users (SSL VPN user using forticlient) connect to organization networks. I have search a lot but couldn't find packet flow. Your support will be more applicable. Thanks.
Hello, In a situation with sd-wan with a static route for a zone and via iBGP I receive the same prefix for another zone, even changing the administrative distance of the static route to the same as iBGP, the static prevails. Anything other than administrative distance to consider? Thanks
Good day! I hope you are all doing well, I just want to ask what are the possible solutions when we input 2 FQDN (one is malicious and 1 is legitimate) it resolved same IP addresses. the FQDN that tagged as malicious are blocked via deny policy. However the our client are having a problem accessing the legit FQDN because of the same IP. the legit website are from Cloudflare. does cloudflare assigned same ip address to FQDNs? Thank you!
Hello. I want to setup a dial up ipsec vpn tunnel from FortiClient to FortiGate. The tunnel is working with transport mode "udp" and port "500". When I change the transport mode in phase1-settings to "tcp" or "auto" and than use "tcp" in FortiClient, the FortiClient is running in an timeout. I have tested with local and sso users. Both same beahviour. I also tested different tcp ike-ports in "conf system settings". Any ideas? FortiGate: 7.4.7FortiClient: 7.4.2
Hello, I have 2 sites with 2 Fortigates that have both their WANs behind a NAT device. So basically at both sides I have a NAT router attached to the WAN that has a private ip. Both connections have a public static ip. Is it possible to create an IPsec VPN between the two Fortigates? Many topics have been discussed but I cound not find a specific answer to that. From the routers is of course possible to forward any port to the WAN interface (NAT-T UDP 4500 or IPsec UDP 500 for example should be forwarded, from my understanding). But will that be enough?
We have some Ubuntu hosts that need access to a site for updates, and on a "Permit Outbound Web Traffic" rules that includes both 443/tcp and 80/tcp, and there are blocks because of UTM. Specifically, the "Threat Type" is "N/A -Static URL Filter." I put an exclusion in (the FortiManager, running 7.2.8) for the FortiGate (also running 7.2.8) within the Security Profiles > Web Filter for wildcard *.ubuntu.com*, but the block persisted. I then put one in for "connectivity-check.ubuntu.com," which is the first site the hosts try to reach. The blocks continued on. I created a rule to exclude that subnet from the Web Filter, and it works. I'm at a loss as to why the firewall is behaving this way, and I also can't figure out what "N/A - Static URL Filter" really means in context with the Web Filter. I need to fix this rule, so any help in resolving this would be greatly appreciated.
how can i filter the api request i want to filter the size of logs{base_url}/api/v2/log/disk/traffic/local?vdom={vdom}&filter=policyid=={policy_id} and _metadata.timestamp>={start_time_ms} and _metadata.timestamp<={end_time_ms}&start={start}&limit={limit}i want to take just the first 1000 logs but the request show all logs
I have a scenario where there are two different Fortilink interfaces on a FortiGate. I need to extend a particular VLAN from the gate to both Fortilink-managed switches. Unfortunately this requires me to require a VLAN sub-interface on each Fortilink interface. One has an IP address configured and the other is just 0.0.0.0/0. I assumed, maybe incorrectly, that this would just do 802.1q and pass layer-2 between interfaces but I also know this is a firewall and that sort of behavior may not work. Can anyone confirm if this is supported? If not, is the only solution to re-architect this and reconfigure for only a single Fortilink?
Good day good people, I hope you are all doing well, I just want to ask if anyone has an idea on how to backtrack the reason for high resource utilization. For example, high CPU and memory utilization were observed during the morning, and we just noticed it in the evening. Does anyone know how to backtrack the issue without TAC intervention? what are the commands needed on to solve this issue Fortigate 7.2.10
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.