Mark a Best Answer
Fortinet Community
Recently active
hello everybody, I defined a ZTNA Group that includes two ZTNA Tags: I know that a firewall policy can work with ZTNA Tags. But is it the same for a local-in-policy?Looking at the documentation: config firewall {local-in-policy | local-in-policy6} edit <policy_number> set intf <interface> set srcaddr <source_address> [source_address] ... set dstaddr <destination_address> [destination_address] ... set action {accept | deny} set service <service_name> [service_name] ... set schedule <schedule_name> set comments <string> next end It generally talks about a destination address. But is the local-in-policy capable of understanding a ZTNA group?I didn't find anything indicative about this. I'm working on a Fortigate 60F v7.2.11.Thank you
Hi. I have a Cisco switch configured with gateway IP at 10.24.111.65. The switch is connected to the fortigate through a trunk with VLAN 101 tagged. Im trying to do vlan-routing from my VLAN1 which is configured with gateway in the fortigate to VLAN101 with the Cisco Switch as gateway. I have created VLAN101 in the fortigate without address.Firewall policies from-to VLAN1-VLAN101.Static route Destination 10.24.111.64/255.255.255.192, Gateway 10.24.111.65 and Interface VLAN101 I cannot ping the gateway or any devices on vlan 101 from vlan 1. (Reply from 192.168.80.254: Destination host unreachable.) The devices on VLAN101 are showing up in the fortigate users & devices under VLAN101. What am I doing wrong?The cisco and all devices connected to that is supplied by a third-party supplier and I cannot do any configuration on that network.
Fortigate 90G FirmVer7.4.5Default internal is VLAN ID 0.I tried to change this VLAN ID 1,but errore poped up something like "cannont use VLAN ID 1..." I want to use VLAN ID 1 ,because I want to fortigate deliver VLAN ID 1,100,200 by trunk-port to cisco L2switch. How can i change VLAN ID 1 of fortigate? or it is not nessesary to define VLAN ID 1?By the way, what means internal vlan id 0 is?
Today we received a security audit assessment from a 3rd party security company. They indicated they can login successfully to our border FortiGate firewall using jsconsole from a trusted management interface. The trusted management interface is connected to the Out-of-band (OOB) Management network and is restricted to specific internal users including the 3rd party security company performing the audit. Can anyone speak to this access, good, bad, indifferent?Can jsconsole be used to make changes to the firewall?Is there a way to block jsconsole access?Thank you
Hello, I hope you are all doing well, I tried installing the FortiEDR Collector on Debian 11 and Ubuntu Server based on the steps in the official documentation, but the installation fails with the following error message: E: Unsupported file ./FortiEDRCollectorInstaller_OS_Version.deb given on commandline Or in case of Debian 12: Unsupported Linux flavor. debian Do you have any idea on what may be causing this problem?
Hi,I have 40F as Firewall and Controller, Connected to FortiSwitch, and has several FortiAP's connected to it.I have 831F APs and 231F APs.for some reason I see that there are 3 devices that are connected to the 831 which has much bigger distance than the 231F.Despite the fact that the 231F have no clients connected to it at all.This lead that the signal strength of these clients is "Fair" and not better.yet - if any of them would connect to the 231, due to the distance (1-2 meters away from it) - it should be much better.I assumed that the 231F doesn't support 802.11AX, yet one of the devices is using 802.11AC. how can I tell the reason ? also can I "transfer" a device from the 831 to the 221 manually via the controller?
I currently have 2 x fortigates configured in a VRRP group. There are 2 x VLANs on both Fortigates and both Fortigates are VRRP master for one VLAN and backup for the subsequent VLAN. e.g. FW1 is master for VLAN 100 and FW2 is master for VLAN 200. FW1 is backup for VLAN 200 and FW2 is backup for VLAN 100. I have configured split DHCP scopes on both fortigates so that if one goes down or connectivity is interupted, the other will serve DHCP addresses to clients. Is there any way to set a delay in DHCP response on the FG to the secondary (VRRP backup) DHCP server so it will only offer an address if the primary VRRP firewall doesnt beat the backup unit? If not - how would I go about having this added as a feature request? I went for VRRP over HA for capacity and granular policy control on the backup VLAN in a fail-over scenario. Session sync is not at all important in the current environment. The alernate solution is to move DHCP server to Windows servers.
Ran into this issue today and figured I would post the solution, since I couldn't find it. Situation is a VPN hub/concentrator running 5.2.8 with multiple IPSec VPN peers configured as dynamic/dialup peers. When testing the new firewalls one at a time before shipping out, each one worked fine. But after users received them at their site, none worked. They all kept bouncing up and down. Tunnels would establish, and then with 2-3 seconds go back down again, over and over. The solution was to disable add-route under the Phase 1 settings for each VPN peer: config vpn ipsec phase1-interface edit "DVPN-PEER-1" set add-route disable next end I didn't capture the log message, but what was seen was a message indicating that route 0.0.0.0/0 was being passed from one VPN to the other. Since Phase 2 selectors are set to all zeroes, and add-route is enabled by default for a dynamic pe
Hi, In my lab I have a 200E on 5.4.4. I'm using ssl deep inspection for 443 traffic. I'm testing with the Fortigate SSL cert added to the trusted root cert authorities store on computer accounts for windows 10. Normal https traffic is working fine tested on IE11. My issue is when using RDP connections through rd gateway servers. Specifically external Windows Server 2012 rd gateway servers wont connect rdp sessions from windows devices behind the Fortigate in my lab. Interestingly SBS 2011 rd gateway servers connect successfully, actually. I tried both proxy and flow based modes. Same result. Does anyone have similar issues or know how to resolve?
Hi, I find that IPV6 SD-WAN rules are unable to add IPV6 FQDN objects.Was this by-design? Or a bug?Device: fortigate 60eOS: 7.4.7 config firewall address6 edit "speed.cloudflare.com" set uuid 3e275afe-e74f-51ef-ba51-85ac2c2767bd set type fqdn set fqdn "speed.cloudflare.com" next end
For instance, this is just one rabbit hole if you want to dive into this issue: https://sites.google.com/classrooms.management/view/home For Reference: FW-7.02-1706
Good morning, I have a question regarding SSL/ssh inspection, on some machines that are used for development I had to exclude the following domains since they could not access the pages they needed:sourceforge.netdevelopers.facebook.comdl.google.comrepo.maven.apache.orgupload.video.google.comgitlab.comwww.jetbrains.comInformation Technology Categorywe already have the certificate installed in the browsers but in this case how to do it, they use php storm, android studio to program. Those machines use Debian and Ubuntu.I don't think it's safe to leave so many pages excluded. What would be your recommendations in this regard?Thanks
I have a FortiGate 601E, and I need to determine whether it supports IP Reputation. If it does, could you guide me on how to check and configure it?
Dear alli have already advpn on some my networkexample HUB A have 3 spoke, spoke A, spoke B, and spoke Cbut there are some additional network example spoke D and spoke E that need connect to Spoke A as hub can spoke A become HUB to spoke D and spoke E ?
Hello guys, I'm new here and I'd like some help with BGP and public range configuration. It's the first time I configure both. Info :I have a new setup with one ISP with two connections (Two routers), a primary (10Gig) and a secondary (4Gig).- Both are connected to a Fortigate 1000D.- A p2p public IP to both routers with BGP configuration.- The p2p IPs are non-routed IPs.- A public range /27.- Only the default route is shared by the ISP. I would like to know what's the best way to configure the public range to avoid limitation? Just to try the connectivity, I have tested this right now => Set the Public range with loopback interface. It works, but only the first IP is available of course. Also, I realized that I can't use the loopback in local out routing for the DNS/Fortiguard. I also tried to set a loopback with a /32 and did the same with the BGP network command, but even if it's shared to the neighbor, I lose internet connectivity. Maybe it's normal with
Hello, After changing password, I can't login.It always say Authentication failureThanks in advance
I'm testing Fortigate-VM-Evaluation adn EMS Client Trial(Server),Fortigate-VM can't accept certificate of EMS Client.Fortgate-VM:OS Firm 7.2.10EMS:7.0.7build0398Is there any possible mistake to setup for EMS and Fortigate、or perhaps, Evaluation cannot be used.By the way,when I tried phisical-Fortigate-100F with EMS、it worked.Physical-Fortigate-100F could accept certification of EMS.Please help!!
I want to WAN2-port to Dedicated as Ethernet Trunk.Is this possible?Even WAN2-port role is changed to LAN-role,there is no "Dedicated as Ethernet Trunk".I have to choose port1~port6 using by "Dedicated as Ethernet Trunk" ?
Transfer a backup from fortigate 50e to 60e
How to access to local webserver by domain name via ssl vpn ?
Does the Fortigate 70f come with ICAP support? I want to double check that before I purchase it. There's no mention of ICAP on the data sheet (https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/fortigate-70f-series.pdf) but this feature matrix it *does* have ICAP support: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/ee1ebc62-b64d-11ef-9411-ae1fcf29f169/SWMTX-761-202412-R1.pdf Thanks!
How can I transfer a FortiAnalyzer-VM license that is on one VM (on a physical machine) to another VM (on another physical machine)?FortiAnalyzer
Hello,I'm trying to connect with iPhone on a tunnel SSLVPN (with MS SSO configured) and the FortiClient VPN app on device says:"The network connection was lost."The same SSLVPN tunnel works fine from an Android device.How can I resolve ?Regards,Leandro
Am I right in thinking that setting set username-sensitivity enable for a local LDAP user just removes the set username-sensitivity disable line from the user's config? set username-sensitivity enable doesn't persist in the config when I enter it, and I want to be sure I have this right. I assume entering set username-sensitivity enable is the same as entering unset username-sensitivity ?
We have a bunch of branch office fortinets in the field (don't know the model as the MSP rebrands them) running version 6.4 . Each gateway is using wan1 and wan2 in an active/standby mode. is there a way via snmp to see which wan path is currently active? basically we want to find out immediately when the primary goes down (typically fiber or cable) and it fails over to the secondary (cell). Many thanks. Jeff
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.