Mark a Best Answer
Fortinet Community
Recently active
Do we have any free tools or community scripts for running a firewall health check? best practice analyzer?Looking for something besides the built-in security rating or Forti Analyzer that might be useful to check out? Thanks
Our user need to access one portal for procurement.some times users will encounter issue accessing the URL. error message is ERR_CONNECTION_CLOSED.we have whitelist the URL so that users wun get blockedwhat else we can do to ensure users don't get this error_connection_closed error ? what our users noticed is if they launch another new session using different browser there will be no issue but will get the same error if launch using same browser.
Fortinet in console get error Fortigate Cloud Not managed at Fabric Connectors. Users don´t navigate through Fortinet. Any idea please? It´s urgently regards
Hello, I have made a deny policy on the Fortigate 7.4.7 and assigned some FQDNs as source on LAN to WAN communication. However, I realized it doesn't work. When I tried the policy with the IP addresses, it worked as it should. Then, I executed below command where "ABC.Domain.com" is our internal network host's FQDN. exe ping ABC.Domain.com Result: Unable to resolve hostname. We are using the Fortigate DNS servers as below: #show system dns config system dns set primary 96.45.45.45 set secondary 96.45.46.46 set protocol dot set server-hostname "globalsdns.fortinet.net" set dns-cache-limit 300 end Also: # show system dns-server config system dns-server edit "lan" set mode forward-only set dnsfilter-profile "default" next end FYI, I'm able to ping the hostnames in my endpoints but not in comman
Dear team, I am experiencing issue while connecting ssl vpn, VPN connection is successfully established but it seems to be remote machine which I am trying to take RDP, getting freez. I am not able to understand where is problem, it may issue with windows machine. I have come here to know anybody facing this type of issue. please let me know. Windows latest security patch may be issue. while taking RDP of remote windows machine. Thanks
In the GCP environment I set up the VM where I installed the ova file downloaded directly from the Support Fortinet site (see below for example) After installation I tried logging in with the default credentials both in SSH and from the GUI but I get this error when logging in Thank everyone in advance!#FortiPortal #GCP
Dear Team, I am looking for workaround as this incident took place when latest windows security patch updated in my windows 11. Issue - Windows latest security patch update causing problem while taking RDP through SSL vpn in fortigate, after successfully established ssl VPN connection through Forti client application. When I try to take RDP of Remote machine. RDP connection gets freeze. For your information there is much latency from VPN machine to Remote machine. I am looking for solution, may be someone has solution. Thanks,
hi Community, We have a website that goes through our fortiweb with HTTP authentication with AD enable. Is there a possibilities to exclude this authentication rule based on IP Address? thanks
Hello everyone, since Fortigate Firmware Version 7.6.0 (and above) the "Enable IPsec Interface Mode"-Option is missing when creating a new costum VPN Tunnel. On Firmware Version 7.4.7 everything is fine. The checkbox is displayed and can be unchecked.When creating a new policy i can switch the Action to "IPsec" an choose the VPN tunnel: After upgrading the same Fortigate 40F to Version 7.6.0 the "Enable IPsec Interface Mode" is disappeared:Without unchecking this option i can't choose the VPN tunnel in a new policy I already tried to deactivate the "policy-based IPsec VPN" Feature and active it again. It did not work. I also updated the Firmware to 7.6.1 and 7.6.2. On both versions the same problem. Is this a bug or kinda a feature? Best regards from Germany,Florian
Hello, We have a fortigate 80F. There is a Firewall Policy, which has WebFilter enabled for traffic from LAN to Internet. The problem is that we are trying to access a sftp with IP. I see in the logs that the IP is categorized as Unrated. I created a new Web Rating override and in the URL I've added the IP we are trying to access (The override is to use a different category to allow the access). Obviously the URL field is for URLs, so the IP is still been treated as unrated. To overcome this issue I have created a new Policy rule so the traffic for this specific IP is not using the WebFilter UTM.Is there any way (except making the Unrated category allowed) to overcome this issue?
Hi guys, I have a problem with FortiEMS. I configured everything: group, domain, certificate, deployment, installer... but the client keeps staying on “unmanaged”. What's wrong? instead, if I send the “invitation” the device registers correctly. Please, can you help me? Thanks in advance
We have created bookmarks on web mode for SSL-VPN on 7.4.5v.There multiple bookmarks which are not opening after entering the credentials on Web mode. But that bookmarks are internally accessible & able to login after connecting to FortiClient.
I am currently using both SSL and remote IPsec VPNs. The issue is the negligible logs on fortigate.When a user gets disconnected all i see is "status change" in logs, is there anyway to get more info? did the connection drop use to packet loss? user disconnected? etc if not through Fortigate how are people monitoring this in their infra? is there any setup using 3rd party softwares to be able to monitor why and how VPN was disconnected?
Hey friends,We're in a situation where we need to offload the process of token resets from employees getting new phones to another team (support desk) that we're not comfortable giving administrative access to the FAC. The process requires human intervention for security and access reasons, we can't allow self-service options. I'm wondering if anyone's figured out a way to simplify this function through the API or other means. We're hoping for simple, one click type action for re-issuing a fortitoken by a junior admin, after visual confirmation with the end-user. Has anyone faced this challenge before, or maybe most places have a fully fledge secops team that can handle the load?
Hi AllI have issue one of our Firewalls, All the devices that connected to Firewall cant get an IP address i check the DHCP Server is working and change the port to LAN 2 or LAN3 nothing change with me. Even if i give any device a Static IP its can't access to internet and i got No Internet. The firewall don't have a lot configuration we just do a VPN Tunnel and no VLANs its a Flat Netwrok. #Fortigate
How can I connect a VPN via a FortiGate 50E with a FritzBox via the FortiClient VPN program
I want to build a HA with FortiClient and my current EMS has 150 client licenses but do i need to buy another 150 for the implementation of a HA or will the client use the same license when switching to the second EMS?
hi everyonei have configureded ssl fortigate vpn with ldap authentification (windows 2008 server)i have this error in vpn events : sslvpn_login_unknown_useri have configured the ldap server, and add domain user in the fortigate i don't know where is the problem i use fortigate100d with forti os v5.6.2
Hello Community, Why I don't have ddns settings in fortigate interface, although I can configure ddns via CLI. Is it because of a license issue?
Dear FortiNAC ExpertsWe have FortiNAC 7.6 - 802.1X Radius is configured with Cisco Switches and authentication is through LDAP-WinBind MSCHAPv2 , PC machines are windows 11, Now we are facing issue with new users / password change of the user or if user login to other PC in same domain, FortiNAC throw error credential failed when we change password in AD or new user logins.In this setup i think user does not have access to LDAP before logging into machine. it does not allow to enter credentials etc how to fix this issueThanks in advanceFortiNAC @ebilcari
We are having a bizarre problem since updating to 6.2.1 (we updated due to a memory leak issue in 6.2.0). Certain sites are giving us a ERR_SSL_PROTOCOL_ERROR only in Google Chrome. I have tried all the usual troubleshooting for this error, but the only thing that fixes it is restarting the fortigate. Two sites (facebook.com and login.renweb.com) both use TLS 1.3, but we can get to facebook without a problem and we cannot get to the other site. After rebooting the device, it works for several days and then starts behaving poorly again. Other browsers work fine, including Internet Explorer, Edge (not Chromium based) and Firefox. I have attempted to disable SSL certificate inspection, but that does not seem to affect the problem one way or another. I also tried putting the fortigate back on its factory certificate. My next step will be to revert to 6.0 branch, where I did not experience this issue, but I figured I would post first to see if anyone had similar exp
Our domain has been added to fortiGuard's antispam blacklist.Contact information for www.fortiguard.com is disabled.I would like to make a request to correct the false positive detection of anti-spam,but if anyone knows where to contact me, please follow me.
I was thinking about learning on how to configure Fortinate Firewalls and I was thinking about buying a small home firewall to play with. The purpose is to learn syntax and whatever I need to know. My question is do the small home firewalls use the same UI as the enterprise editions? My line of thinking is that if I learn it on a small piece of equipment, it'll carry over to the enterprise editions.Your thoughts or suggestions?
When we scan our website's IP address on www.virustotoal.com it shows that it is marked Malware by Forticlient. All the other vendors show it Clean. I am not able to find any place on Fortinet or FortiGaurd to check the IP address directly, neither a way to start a process of de-listing our IP address. The only relevant link I found on the website was https://www.fortiguard.com/updates/irdb , but it seems to be not working. Any help regarding this will be highly appreciated.
We have a external vendor who request us to setup IPSec tunnel with their Cisco router.the requirement is us to do NAT with the following static NAT address mapping table. True IP (Our LAN) NAT IP10.200.xx.xx 10.229.xx.xx any issues if we use the following to setup the IPsec tunnel ?IKEv1Phase 1 (at life time 24 hours) :Authentication: SHA-256Encryption: AES-256Key Exchange operation security: DH-group-16 (4096 bit)Phase 2 (at life time 1 hour):AH-Authentication: NoneESP-authentication: SHA-256ESP-encryption: AES-256PSF: DH-group-16 (4096 bit)
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.