Mark a Best Answer
Fortinet Community
Recently active
I'm looking at the SSID configuration and I was wondering about Broadcast suppression - 1.what are the thresholds ?2.I undertand what ARP poison means (I am a CCIE after all), I understand ARP proxy.yet I don't understand the following - ARP replies - does it block ARP reply which is in broadcast ? after all ARP reply is unicast.ARPs for known clients ? does it block ARP reply from a known client ? does it block traffic intra SSID ? DHCP downlink ? does my 40F can still work as DHCP server ?DHCP unicast ? what does feature mean ?DHCP uplink ? does it mean DHCP Snooping ? does it mean that the client can't request for DHCP ? can anyone provide me recommendation and explanations ?
unable
Hello allI wonder if the Test pages for Web Filtering work as expected?i.e. https://fortiguard.fortinet.com/wftest/14.html does not get blocked although i blocked the category in my web filter. First i thought it might be an issue in my filter settings, however a friend of mine (who administer another firewall) reports the same. Does the page above get filtered by your filters? Best regards
I'm working on setting up an IPSEC VPN tunnel between a remote cellular router (Digi TX64) and the FortiGate 300E at our headquarters. I've got the tunnel up and stable, but can't seem to get traffic to flow properly. If I run a ping from a device behind the Digi to a device behind the FortiGate, I can run packet sniffer on the FortiGate and see the ping packets coming into the FortiGate from the VPN interface, but I never see them leave the FortiGate to go on to the actual host. Once I get the formula for this sorted out, I get to duplicate it about 180 times for routers across our bus fleet. All of the bus routers use the same 192.168.x.0/24 internal subnet, so I need to NAT the traffic as it is passing through the FortiGate into our main network, and then reverse that as it passes back through the FortiGate to return to the bus. I also need to ensure that NAT is always one-to-one such that traffic from a specific 192.168.x.0 address will
So I currently have a shop running aged gen 1 ubiquiti with an updated controller os running on Linux.I'm not having the greatest experience and looking to go Fortinet full stack.2x Fortigates3x fortiswitch FPOE full poe. And looking at either 100 or 200 series.What is everyone's opinion?The current setup: 2x Gen 1 48 poe 500w 2x gen 1 24 poe 250 w 2x gebt 1 16 poe 150w Soniwall fw.Here's why I'd like to upgrade.Full poe for voip expansionFull poe for switch consolidation. They added too many switches since ubiquiti can't handle full poe usage.Full poe for cameras and badgingMore expensive product cause it's a in house install so more money to gear and no project overhead.Fortilink. IMO fortilink is what unifi pretends to be. I know it's local but I can get in local. So I don't mind loosing a silly app that isn't very functional on the mobile side.
We are using a cluster of two 120G since February running the special-built 7.0 fortios releases with various platform specific annoyances (non-critical bugs).Any hint when this platform gets added to the general release pool?
Je crois que par inadvertance, j’ai effacé l’OS de mon Fortigate, il y’a par contre les infos d’un serveur TFTP mais je n’ai pas accès à ce serveur. Que faire s’il vous plaît
We have a home user who is getting disconnect from the VPN every 30 seconds. She has confirmed she is using the correct password. We don't think it is local network as the same issue occurs on mobile hotspot. Issue has only just started in the last 24 hours. FortiGate Client 7.2.1.0779 The VPN log is attached ( I have started out some sensative bits like my company name and user name)fctver=7.2.1.0779 fgtserial=FCT8001468094356 emsserial=N/A os="Microsoft Windows 11 , 64-bit (build 26100)" user="********" msg="Traffic log" sessionid=1380262705 srcname=sslvpn srcip=172.17.0.100 srcport=0 direction=outbound dstip=london-********.co dstport=443 proto=6 rcvdbyte=12895686158 sentbyte=12888050432 utmaction=passthrough utmevent=vpn threat=disconnect userinitiated=0 browsetime=02/18/2025 11:37:26 AM info sslvpn date=2025-02-18 time=11:37:25 logver=1 id=96600 type=securityevent subtype=sslvpn eventtype=status level=info uid=2E74E029E55740
Good morning everyone,It has been a while indeed. This is a follow up to a resolved post below: Post: Forticlient EMS removable media accessDate:14/5/2024----------------------------------------------------------------------------------------------- Since I configured this feature in EMS, it has been working perfectly, blocking usb devices while only allowing certain devices, especially Keyboard and mouse. However, my manager attached a USB dongle/device to a computer apart of target group/profile, and it is blocked by the USB policy. He instructed to disable the "Removable Media Access" feature on LAN until this ethernet-usb can be allowed on computers. I really don't want to keep this off for too long. Don't know why that instruction, but hey, following orders, at least my name won't be called for any issues. Can you show me to allow this device in Endpoint Profiles -> Malware Protection -> "profilepcs" -> Removable Media Access? Kindly see image below/at
Hi there,I guess I'm doing something wrong - I hope you can help me.My topology is very simple - 40F managing FortiSwitch POE that has 7 FortiAP connected to it in Local Switching mode.there are 3 floors, 2x831F in first floor, 2x831F in second floor, 1x831F and 2x221E on third floor.the 831F is for each classroom, with 30 students, each has a laptop, and a phone.I have 2 SSIDs - STAFF and STUDENTS.yet when I look at the GUI for interfering SSID - despite the fact that the channel selection is auto, and all are controlled via the same 40F - the 831F sees the other 2 831F as interfering SSID.but that makes no sense - they should each use it's own channel, with auto power, and auto channel selection.how can they interfere each other ? they should support each other don't they ? which CLI commands should I provide you ?
Hello,I would like to implement VDOM In azure infrastructure. As I discovered when you implementing VDOM you must to assign interfaces to the VDOMs, but in case of Azure you have just 2 interfaces and I don't know how I can assign 2 interfaces for example to 3 VDOMs?
Hi, I have a problem after the firmware was upgraded from 7.2.10 to 7.2.11. I'm having general GUI connection issues through HTTPS and sometimes the CLI gives connection lost as wella s the GUI itself losing conenction on firefox even after clearing the cache. There are no noticeable issues on edge browser. does anyone know what happend? why did this new firmware screw up connection to fortigate in general? ciao,Antonio
Hi,A pen test on our outside IP shows us that port 2000 (Cisco Skinny Clients (IP Phones)) and 5060 (Session Initiation Protocol).We don't need those ports. And our security office wand to close these ports.We are running on software version: v5.4.5The configuration change we did to close port 5060:conf globalconfig system session-helperdelete 13endAnd for port 2000 we used the following:conf vdom(vdom) # edit Firewall# config voip profile(profile) # edit default(default) # config sccp(sccp) # set status disable(sccp) # end But unfortunately this did not close the ports.Does anyone has a suggestion to close these 2 ports. I hope someone can help me. Thanks in advance.Greetings Palermo
Today I wanted to use application to connect to the server. I get the following message:"Sorry could not start connection "s" Error Revoked by android REBOOT!" .The problem has been happening since today because yesterday everything was working normally even though I didn't change anything. It is worth adding that I managed to connect the desktop to the server using this small data. I tested the problem on Android 10 and 13 and the message was the same.
Hi, today we tried to get information about our interface bandwith with iperf and Fortigates. We would like to get information about a FG location in South America. Our main office are in Europe and we use FG100Fs and 7.2.X. All our offices have at least 2 x 1000/1000mb access but in South America we can only do speedtest on browsers where we get like 800/800 at the most. Firts, we could not run iperf within the VPN from FG Europe <> FG South America. We set up a iperf server on windows on our side but doing diag traffictest run -c x.x.x.x we could not connect. We checked Windows FW, AV and policies and there was no way. As iperf-int we tried all interfaces (internal, WAN and the VPN interface). After that we tried with a linux in our network and we created a VIP with 5201 and trying from our FG with WAN as interfaces we got like maximum 12mb trying at least 10 times. Doing the same from our FG locationes in EU we got like 300-700 mbs. We would like to k
We have some Fortigate 92D with FortiOS 6.2.12When we are trying to manual update of ISDB (ffdb file) there is error code -85 and message about "Updating FFDB is disabled"How can I fix this issue?FortiGate
Hello everyone! I have 2 Fortiweb devices in active-passive ha cluster. Now I can connect via HTTPS to the mgmt interface active device of the HA cluster, there is no access to the passive device, while using the cli I have access to the mgmt interface of the passive device fortiweb too. Can I use the web UI on a passive cluster device, such as on fortigate devices? Thanks.
helloI have fortiGate40FI need to disable save logs in cloud after that I need to save all logs to external USB automatically Best Regards
Hi allI need to connect second internet redundant connection into fortigate. I am using only one fortigate. Is it possible to use one fortigate for redundancy ?
Hello everyone, I am currently working on integrating FortiAI with FortiAnalyzer, and I would like to know from which version of FortiAnalyzer this integration is officially supported.- What is the minimum FortiAnalyzer version required to recognize and store logs from FortiAI ?- Are there any specific configuration steps or limitations I should be aware of ?- Where can I find the official documentation regarding this integration ?Any insights or shared experiences would be greatly appreciated. Thanks in advance for your help!
I've got a few lab forti's that are getting behind on updates. I don't care about hardware support on them, I've got spares and I don't need to spend much for the home network lab. What's the best way to get access to firmware these days?
My forticlient ssl connection fails at 10% but successfully connected through mobile network. It was working before but suddenly it stopped working. I tried to reinstalled but did not worked. Looking for some solution or suggestions.Thanks
We currently purchased some FortiSwitch 124F-FPOE switches for a client and are running into some odd issues getting the DHCP Helper feature to work properly. DHCP Server exists at a central office with a bunch of branches connected to it via MPLS. So a hub and spoke topology, where all traffic from the branch sites is funneled back to the main office. For whatever reason when we are using a FortiSwitch at one of these branch locations, the DHCP Helper function doesn't work properly on VLANs. The native vlan on the internal interface will forward the DHCP traffic, but the other DHCP Helper on VLAN10 will not forward DHCP traffic correctly.I have confirmed routing is working properly because I can statically assign a device on VLAN10 and ping the DHCP server with no issue. There is nothing that would block this traffic.Currently have a case open with TAC and they aren't able to resolve the issue either, wondering if anyone else has run into this issue? I've tried run
Hello there, can somone please explain to me what this FortiClient VPN icon display means ? I could establish a succesfull connection and i pressed disconnect. After 10 min when i tried to enter again i had this icon displaying and could not establish connection I have the Forticlient 7.2.8 version because it was the only version that i could establish a succesfull connection
Hello! I am currently experiencing a problem with dialup ipsec vpn on a fgt-90G.. i use certificate auth and the problem is that sometimes, the windows client connects, but no traffic passes through the tunnel... in logs i have ike retransmits like it shows below.. The thing is.. it sometimes works with no modifications to the configuration.. 2025-02-12 15:02:16.961772 ike V=root:0:Dialup_0:131: sent IKE msg (retransmit): x.x.x.x:4500->y.y.y.y:64916, len=1728, vrf=0, id=8e28e757f91c9b5b/5efcee79161f925b:00000001, oif=392025-02-12 15:02:18.669458 ike V=root:0:Dialup_0: link is idle 39 x.x.x.x->y.y.y.y:64916 dpd=1 seqno=2 rr=02025-02-12 15:02:18.669490 ike V=root:0:Dialup_0:131: send IKEv2 DPD probe, seqno 22025-02-12 15:02:18.669512 ike V=root:0:Dialup_0:1235: sending NOTIFY msg2025-02-12 15:02:18.669522 ike V=root:0:Dialup_0:131:1235: send informational2025-02-12 15:02:18.669540 ike 0:Dialup_0:131: enc 0F0E0D0C0B0A0908070605040302010F2025-02-12 15:02:18.669598 ike 0:Dia
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.