Mark a Best Answer
Fortinet Community
Recently active
I know fortiedr is from the ensilo acquisition. Anyone have any recent experiences with FortiEDR ? and maybe some opinions on how it compares to other ones in the market ? We have fortigate routers and switches, but not sure we definitely need to have that "single panel" convenience, though it sounds nice. Obviously nothing catches everything, and we would prefer better lateral spread prevention, than protection of said endpoint (as in we could sacrifice a known corrupted endpoint, which maybe the fortisandbox might help with as well). that and we would only allow VPN connections if the client was running forticlient with protection, rather than letting any endpoint connect. It might be difficult to determine on login, whether the endpoint had EDR running outside of the fortinet security fabric mechanisms..So we are considering Windows Defender ATP (endpoint), s1, fortiedr right now. There just isnt much information on fortiedr out there. S1 kind of requires MSP, and we're looking to k
Hi Team, After upgrading to FortiOS 7.4.4, the set reply-to has been hardcoded. Does this impact the sender email address reflected in the relay and sms server? Currently, there is error of same sender and receiver email for the sms based 2FA authentication as reflected in the relay logs. Is there a way to change the sender email on the FortiGate side? I have looked into these KBs already:Updated default email notification server 7.4.4 | FortiGate / FortiOS 7.4.0 | Fortinet Document LibraryConfiguring SMS Two-Factor Authentication... - Fortinet Community Thank you!
안녕하세요, 로그인 할 때 98 % 후,다음과 같은 문제가 발생합니다.기존 커뮤니티 게시판에 나와 있는대로 설정해 놓았는데, 전부는 아닙니다. 다른 해결책이 있습니까?
In a FGCP cluster trying to get session sync traffic over the dedicated interface with the set session-sync-dev command. But the corresponding diagnose output seems to indicate it doesn't work. fgt1 (root) # diagnose sys ha session-sync-devHA sessync ports: 1dmz probe: HA probe, Standalone connected, peer_mac = 00:00:00:00:00:00HB pkts: rx=0, tx=508298SES pkts: rx=0, tx=0 Seems to indicate HB packets are send, but none received. Also the status remains probe for HA.The cluster is connect with a direct cable, no switch in between or such.Tried with other interfaces also, wan1, internal4, ... Anyone has this working and different command (diagnose sys ha session-sync-dev) output? What are your counters and status?
I want to configure FortiLink over a point-to-point layer-2 network for connection to FortiGate Firewall and Cisco BB (Backbone). I need to connect FortiSwitch via Cisco BB. I'request support on how I can perform this configuration.The environment have: Fortigate > Cisco BB > FortiSwitch
I have a Fortiswitch standalone mode - no Fortigate - I am trying to set up MS NPS for radius authentication. I have all set up in the NPS.On the Fortiswitch for a new administrator I cannot choose remote as an option - greyed out.Is what I am doing possible - if so how do I get rem
Hello All Please be informed that we had a customer, and he purchases FortiGate firewall 81F and 3 Forti Switches 124F He was asking to connect all Forti switches directly to FortiGate with Forti Link mode to make sure that he avoids the single point of failure and if any switch become down that doesn't affect to both switches Please advise if there is any recommendation will be appreciated
Hello everyone, I would like to understand how FortiMail calculates email sizes, particularly when encryption is involved or more. The issue I’m facing is that the size varies inconsistently. I understand that factors like attachments influence the final size, but at times and very often, this instability causes emails to exceed the configured size limit, impacting their transmission. I want to avoid having to adjust the email size limit manually each time. Are there any solutions I might have overlooked? ? Best regards
Hi Everyone, Does anyone know how to navigate or check previous version of fortinet?I need the date/timeI've already check the link below but can't navigate it where can i find the datehttps://community.fortinet.com/t5/Customer-Service/Technical-Tip-Check-firmware-upgrade-date/ta-p/329149 Note:The firmware is automatically update thats why i need the logs of previouse version and date and time.
hello , here jai two wan the first is set up for ipsec the second is to go to internet I have a problem with the webfilter when I put a web filter in a policy via wan 1 PPPOE the webfilter its work but when I put it on the wan 2 ip manual the webfilter blocks everything
Greetings.I faced the following situation.In FAZ Storage Info, a message appeared that the logs for ADOM Syslog exceed the possible time limit, i.e. Analytics (Actual/Config Days) - 62/62. I would like to remove this warning. But there is enough space.I went to this ADOM: Syslog, went to Log View > Log Browse and found that there are logs for 2022, which should not be the case. I wanted to delete them. But when I select the logs from the VDOM - Syslog, the Delete button does not become active.I would be grateful if you could tell me how to solve the problem.Best Regards
Hi guys, I am configuring a Guest SSID in Bridge mode on fortigate (FortiAP) with external captive portal authentication on aruba clearpass. The redirection to the captive portal works correctly. Authentication works on some devices and some browsers, credentials are sent in https Post and requests are processed correctly by Aruba clearpass.However, on some devices, authentication does not work and credentials are not sent to Clearpass. Has anyone encountered this problem? Best regards
I already have SSL-VPN running with SAML enabled and it works fine..I'm starting to setup IPSEC-VPN and it's configured to work with a local group and local account, just to get it running.If I want to start using Azure SAML with IPSec-VPN, can I use the same samluser/saml remote group I have for SSL-VPN or do I need to setup a new one for IPSEC-vpn in parallel, including the Azure side of it.should the ipsec-vpn also be setup on a loopback interface ? (my ssl isn't, currently) are the steps the same ?
FortiGate 7.4.4-1 in GNS3 unable to ping GNS3 VM, unable to ping windows 11 host machine, unable to ping gateway. FortiGate IP address: 192.168.0.33/24GNS3 VM IP address: 192.168.0.52/24Windows IP address: 192.168.0.125/24Default Gateway: 192.168.0.1/24 C:\Users\<username>ping 192.168.0.33Pinging 192.168.0.33 with 32 bytes of data:Reply from 192.168.0.125: Destination host unreachable.Reply from 192.168.0.125: Destination host unreachable.Reply from 192.168.0.125: Destination host unreachable.Reply from 192.168.0.125: Destination host unreachable.Ping statistics for 192.168.0.33:Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Warning: Got ICMP 3 (Destination Unreachable)FortiGate-7.4.4 (IP address: 192.168.0.33\24) running in GNS3 (2.2.47 version).GNS3 VM (2.2.47 version with IP address: 192.168.0.52\24) running on Oracle VM Virtual Machine.Windows 11 with IP-address: 192.168.0.125 with Default Gateway: 192.168.0.1 Able to ping GNS3 VM IP-addr
anyone with experience on the diagnose debug for sessionsync (FGSP)? i tried the -1 on 7.2.8 and think I once saw the sync packets on the output, but at the moment I don't see anything when the system is working normally and session sync is working. when i run a resync all command with diagnose test application sessionsync 9 I do get some output, but not during normal operations. another debug level perhaps? i did try a few, but couldn't get any other output to show.
I am looking to get SNMP traffic to flow across an IPsec tunnel. I know I have to change the source ip in the CLI for this to work properly. My question is, I have been instructed to use a source IP from a local phase 2 selector. This is a route based tunnel so phase 2 is 0.0.0.0/0 on both sides. There is a static route for 0.0.0.0/0 to go out the WAN1 port for the IPsec tunnel. Would I be using the WAN1 interface ip for the source-ip in the CLI, or how would I go about making this change? Thank you.
Hello,i have a fortigate 901G and connected to old isp modem with vlan subinterface and do static route to the next hop ip,WAN port led blinking Green and Static Orange, So :i created also loopback interface on foritgate and configure it with public ip and ping from this ip to 8.8.8.8 the ping is not compeleted with 100% many times give me loss with 20% and 40% and 80%a tried to change port speed to 100Full Duplex from 1000 auto nego. and it is still lossing the packets ping and user not able to connect to internet or ping - So is there is any recommendations from you to solve this problem .
I know the differences between using flow based vs proxy based.I recently switched all our profiles and rules over to flow based to see if this was causing slowness in the response times users were seeing. It ended up being a DNS server issue after I took packet captures and saw the DNS queries were getting server failures half the time.Generally just curious if people are using flow based out there or proxy based in your environments!
Hello everybody,I've a simple IPsec tunnel on my Fortigate 60F (v7.2.10): Is it possible to reserve a particular address to a specific client based on the MAC address. Let's suppose I want to reserve 10.212.134.221 for the client whose MAC address is xyz. Is it possible? My attempt was:I connect from the xyz PC, then I go to Settings -> DHCP Monitor -> Select the client ad reserve the address. Unfortunately, during the IPsec connection, the client is not shown inside the monitor.Is there any way to do what I want?Thank you!
Hi All, I am writing to inquire about a challenge I've encountered while implementing Fortinet Single Sign-On (FSSO) on my FortiProxy in a lab environment.Current SetupI have successfully integrated the FSSO Collector Agent in DC Agent mode with my Active Directory (AD) and Domain Controller (DC) servers.However, when attempting to define a user object of FSSO type under the User Definition submenu, only AD Groups are generated. I am unable to select specific AD Users.QuestionsDoes the FSSO configuration on FortiProxy differ from that on FortiGate? On FortiGate, I can define FSSO users by selecting specific AD Users under User Definition. This does not appear to be the case with FortiProxy.If defining FSSO users by specific AD User is not possible on FortiProxy, how can I implement FSSO in FortiProxy policies? I have several proxy policies that require source addresses to be defined by specific AD Users. I would appreciate any insights or guidance you can provide to resolve t
Hello all... New to Fortinet and wanted to run some script syntax by the community. Need to implement some global settings on our Fgates via a FortManager script. Some of our gates are multi-vdom. So far I have this, below - have not tried it yet - just to see if I have it right before tripping over the syntax. Thanks in advance! This would be for the multi vdom devices - lconfig global config system global set admin-console-timeout 300 set pre-login-banner enable set post-login-banner enable set admin-ssh-grace-time 60 set admin-lockout-duration 300 set admintimeout 5 set admin-lockout-threshold 3 next config system auto-install set auto-install-config disable set auto-install-image disable nextend
I have two Sites (Site A) using Fortiddns, and Site B using Daillup . There is VPN tunnel between them and it's working fine. I want to make DNAT for my server and it's behind Site B. I don't have public IP Addresd .it's not working in this scenario?
Is there a way to create a SSID for GUEST in meraki cloud and integrated to FNAC-F FortiNAC FortiNAC
Hi All,I'm looking for advise on configuring a backup internet connection using vDSL.I have a Draytek 167 which I plan to set to bridge mode and perform the PPPoE authentication on the FortiGate.I have a single /32 public ip address. Any thoughts on this?The ISP is Andrews and Arnold.
Hi,I have 40F, connected to FortiSwitch 108F.I'm managing the 108F, and the FortiAPs connected to it via the controller that exist in the 40F.I've configured the SSIDs to bridge mode, and I want the use the same VLAN for LAN and SSID.at the moment I've configured under the Fortilink interface, which port a is associated to it an interface VLAN (VLAN 10). I want VLAN 10 to work over the fortilink and also via port 1when I connect a second switch (non forti) to port 1 - the port goes up and down (I guess LACP is to blame). I have the following configuration :the interface vlan -config system interfaceedit "STAFF"set vdom "root"set ip 192.168.10.254 255.255.255.0set allowaccess ping https ssh httpset device-identification enableset role lanset snmp-index 20set ip-managed-by-fortiipam disableset switch-controller-igmp-snooping enableset switch-controller-dhcp-snooping enableset color 13set interface "fortilink"set vlanid 10next and then the ssid configurationconfig wir
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.