Mark a Best Answer
Fortinet Community
Recently active
Hi FNAC adminsFortiNAC-F 7.2.9.Do you know a way to show/set device model configuration in CLI or via Linux shell (enter-shell).
Can we put the url to download the persisten agent on captive portal than the agent downloaded automatically?
now i want to identify the printers with its specific mac addresses in Fortinac and if there is another mac address unless i identify put it in quarantine vlan.how can i achieve that?
Hello all,we have an Exchange Hybrid setup with all our mailboxes on-prem. We need to let graph send emails via Exchange Online but we would need to relay these emails via our Fortimail appliance. So the Exchange Online environment does not send these itself without going through the Fortimail first. We found this in the cookbook:How to integrate FortiMail into Microsoft 365 | FortiMail Appliance and VM 7.4.0 | Fortinet Document LibraryAnd this technical guideline:Technical Tip: Office365 Secure Relay via FortiMail to avoid unauthorized email relay | CommunityAnd it seems like we can’t let graph talk directly to our on-prem Exchange servers:https://learn.microsoft.com/en-us/graph/hybrid-rest-support So we wondered how does the Technical Tip from fortinet make sure that we are not risking the relaying of unwanted emails. The authenticated part in the technical guideline does not apply here, no? Because our user mailboxes are all on-prem? And regarding the cookbook: our concern is that w
Hi all, I'm rather new to FortiMail and Fortinet products. Trying to configure same wildcard cert (e.g. *.domain.com) for both Exchange and FortiMail, using an internal Windows CA. The topology of email is like: exch.domain.com > fml.domain.com > outside While HTTPS connection is cool, FortiMail keeps complaining "unsupported certificate purpose" when it receives email from the internal Exchange server (FML acts as a server in this case in terms of TLS connection). But when outside sends email into domain.com, FortiMail happily forwards it to Exchange server (FML acts as a client in this case) How do I start troubleshoot this case? If I were to use Secure TLS Profile to enforce, outbound mails would be rejected. Thanks in advance.
Hi everyone,We are facing an issue where FortiGate email notifications are not being received by Outlook.com email accounts (Outlook, Hotmail, Live).Our SMTP configuration is working correctly because all email notifications, including SSL VPN OTP emails and other system notifications, are successfully delivered to our company email accounts.However, when the recipient is an Outlook.com email address, the emails are never received, including the Junk/Spam folder.Has anyone experienced this issue? Is there any known compatibility issue, Microsoft filtering policy, or SMTP configuration that could cause Outlook.com to reject or silently drop emails sent by the FortiGate?Any guidance or troubleshooting suggestions would be greatly appreciated.FortiGate Model: 1101EFortiOS Version: v7.4.11 build2878 (Mature)
Can we hide the captive portal address bar when the endpoint connect to isolation network on fortinac? I dont want user knowing the url of captive portal.
Hello FortiGate Community,Does FortiGate Natively Support mTLS/SPIFFE?If SPIFFE has to be integrated with FortiGate, what is the recommended approach? if you have any integration guides, please provide.I couldn't find any public information regarding this integration.Thank you in advance.
Na
I’m trying to setup LACP between Fortigate HA Active-Active cluster and another device (switch or another fortigate). On Fortigate HA, only one link to the primary is active and passing traffic. There is documentation for HA Active-Passive to prevent sending traffic to the slave(“set lacp-ha-secondary enable” ). Is there any m-lag configuration option on Fortigate HA ?. Thanks,
Hi,I wanted to update a Fortigate 50G from v7.6.6 to 7.6.7 via GUI but the button is grayed out. I read some articles that it could be about scheduled fabric updates. But I am unable to cancel it. Why does that happen? Why is a simple update so complicated now? FG is licensed and registrered.
we have FortiGate 91G firmware version is 7.4.12, SSL-VPN is not in GUI and also in feature visibility since it supports SSL-VPN how can be active to see in GUI?
Dear community, I need you support on the following itemsI have been asked to configure link health monitoring for our networks, now I have already setup the Performance SLA using ICMP Ping to check if the link is up and/or down. this will check if the link is up alright, now if the link goes down then using the SD-WAN rules the connection should swing the other ISP link and avoid any distruptions that might happen or it should not require manual switch.Now first question is here that what do you suggesst be the minimum link status to avoid any kind of routing issues later Now the second issue is that when configure SD-WAN rules which interface selection strategy should I use because when I read through the docs they mentioned to use the Manual but it does not allow for selecting any SLA rules you have configured, now out of the Best Quality and Lowest cost which one should I use?Can you please advise on this as well. I am looking forward to hearing from you. Best Regards,Shah.
Forti voice is 7.4.1 Is there a way to mass or change the 4 digit caller ID when doing local calls to other 4 digit extensions?i.e. I have 2 front Desk Phones both have Primary Extension (Main Phone and Aux Phone) 1234 and then have the Departments line 4444 has a SLA.When they call from these phones to just a 4 digit internal extension Caller ID shows ‘Desk Phone 1234’, I would like to hide the 1234 and just have Desk Phone show up, since everyone knows to just call 4444 locally to get to the front desk. Having 1234 show up can be confusing. I cant make the 2 desk phones just 4444 because placing calls on hold doesn't show up on AUX phones or any other phones that might also have that SLA mapped. We also plan to always have call forwarding enabled on 1234 to 4444, but I still would like to completely hide the number if possible.
Dear Security Team,We respectfully request that you review our domain and remove it from your blacklist if appropriate.We have completed a comprehensive security audit of our website and have fully resolved all previously identified security issues. All malware, malicious files, and any potentially harmful content have been completely removed.In addition, our website has been scanned by multiple trusted security services, all of which confirm that the site is clean and free of malware, phishing, and other malicious activity. Google Safe Browsing also reports our domain as safe and does not detect any security threats.We kindly ask you to re-evaluate our domain based on its current clean status and update its reputation accordingly.Thank you for your time, consideration, and assistance. We appreciate your review and look forward to your response.Best regards,Website Administratorhttps://dorottyanadorfi.com/ https://lantosfestes.com/ https://dirdurr.eu/ https://balanceyourlife.hu/ ht
I have a bridged AP that is tied to the DATA interface that cannot get to the Internet. The DATA interface works for the ports on the switch with no problem.
Does Fortitoken MFA support the server that running on Windows server 2012?
Now i have Fortinac with version 7.6.5 Fortinac-os and i have agent is 9.4.0.93 i need to know if this is most suitable version for agent or not and if i plan to upgrade it what should i do if i made in the scan policy check latest persistent agent and i also edit the registery key of LoginDialogDisabled
I use persistent agent to checking antivirus on the client before the client can connect to the network.My question is what parameter will be checking by PA? Is antivirus realtime protection is on/off, is antivirus batabase signature updated or not, or something else?
Hello dears,I hope you are all doing well.I am facing an issue with FortiClient VPN in our organization. Every time an employee tries to open FortiClient, they are prompted to enter administrator credentials.Has anyone encountered this issue before or knows how to resolve it?
Hello,I am connect to mobile hotspot rogers and my internet speed is very very good no doubt. I did every thinh minimize the wifi MTU in laptop. disable ipv6 and other stuff but still after 98% it restarted.Need urgent help in that please. Thank you,
good morningThe requirement is to create two physical ports for the firewall: one dedicated to the entire internal network, from which all data flows, and the other one dedicated solely to the Fortigate firewall's settings, updates, databases, and communications with its servers and online services.How can I properly isolate these two ports to prevent any data leakage from the first port to the second? Can I get a detailed, practical guide to the process?
Hello everyone,I'm experiencing an intermittent issue with an IPsec Remote Access VPN.The VPN tunnel establishes successfully (IKE and IPsec SAs are up), and the client authenticates successfully. However, in some cases:TX (sent) packets increase normally. RX (received) packets remain at 0 bytes / 0 packets. No internal resources are reachable.One interesting observation is that the issue depends on the ISP. If I switch to another Internet provider, the VPN works immediately.A few months ago, I had a similar issue that was resolved by setting the MTU to 1350, but this workaround no longer solves the problem.I have reproduced the same behavior with:FortiGate 7.4.x FortiGate 8.0.0This makes me suspect an MTU, fragmentation, or ISP-related issue, but I'm not sure where to investigate next.Has anyone encountered a similar behavior?
Setting up new Fortigate and prefer to start from scratch as old gate was breached several times most recently during the SSO vulnerability and changes were made. Instructions that I could find recommended deregistering and wiping configuration on the old gate and resetting and programming on the new gate or transferring the relevant configuration to the new gate. Is it possible to leave everything as is on the new gate, wiping switch and ap (resetting) and then attach to the new gate and setting up from scratch or will the fact that it is still set up on the old gate interfere with the process? Would just prefer that I have the option to put them back on the old gate if I run into difficulties with the new set up. Clearly not a network engineer! Rolling back to 7.4.12 on new gate because of glitchiness on 7.6.7 and switch is on 7.6.6 and ap is on 7.6.5 - should I drop back firmware on switch and ap when I transfer them?
Forticloud Support gave me this as a solution: Well, this did NOT work. Could anyone here provide a solution/fix for this?Can this be ignored?Will it have impact on performance?How can one reduce the amount back to max 110?How can i prevent further growth? N.B. I am seeing weird variations of a work email address, with different characters added in the email address itself thus creating multiple copies. For example: jbrown@work.edu.ca is the official email address. Now i am seeing in the FM cloud active user mailbox list j-brown@work.edu.ca, jbrown123@work.edu.ca , j.brown@work.edu.ca and it goes on and on for others. This is unacceptable.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.