Mark a Best Answer
Fortinet Community
Recently active
Hello everybody, I'm using a macOS with 7.2.5 of Forticlient.I had a deployment error with my device. Looking at the logs, i found this error: Downloading data from xxx:10443/Installers/default/FortiClient for Invitation/FortiClient_7.2.8.dmgURL using bad/illegal format or missing URL Obviously the error was caused by the spaces between the words: FortiClient for Invitation On the EMS, I updated the URL, removing the spaces. At this, point, I want that my client, for the next update, automatically downloads the file from the new url. How can i say to my client:retrieve the new url and download the installer from thereIs there some command to push this new url to my client?Thank you! 
Hello, I have Fortimanger and FortiAnalyzer both with many ADOMs.- In FortiManager is there way to search on the CLI for a particular IP that may be in ANY of the ADOMs ?- in FortiAnalyser is there a way on the CLI or otherwise to search the logs of ALL ADOMS at once ? Thanks for any help.
Is there a way to automatically map AD Groups to Workgroups for use in Policies ?I saw this article that seems to support it in 6.2. Seems the functionality is missing in 7.4.1 https://docs.fortinet.com/document/forticlient/6.2.0/new-features/280319/automatic-group-assignment#:~:text=group%20assignment%20rule:-,You%20can%20use%20AD%20groups%20to%20categorize%20users%20into%20different,local%20domain.
Is there a way to search through multiple / all FortiAnalyzer ADOMs?
After the latest Viber update. Signature Application Control ID 26178/ 12/19/2024 29.924 -fortiguard stopped blocking the Viber application.The logs show that the requests are simply sent over HTTPS.We tried to include deep-inspection.Please take note and fix this issue.
Trying to figure out the best way to handle setting up VPN tunnels for about 200 mass transit buses. Each bus has a Digi TX64 cellular router installed, and they are all configured to use the same internal subnet for the equipment on board the bus. We're needing to enable communication between a couple of devices on each bus and on-prem servers located at our headquarters (perimeter is a Fortigate 300E). Since all of the buses are configured to use the same 192.168.x.x subnet on their internal network, obviously we're going to need to NAT that traffic somewhere along the way. Would like to minimize the configuration needed on each individual bus though. The on-prem servers we need to hit are on a 10.x.x.x network, so that traffic shouldn't need to be NATed. Oh, and we can't have static IPs on our cellular connections (long story), so will have to use Dynamic DNS for that end of the tunnel. I've been studying the docs I can find online, a
Hello, I'm blocking app control Proxy category but I need to whitelist access to proxy-safebrowsing.googleapis.com. It falls under Proxy.HTTP application and gets blocked. I would like to do it via custom signature. But I can't seem to match the traffic using my custom signature. I've read the signature creating guide and followed it but no luck. It still recognized as Proxy.HTTP. config application custom edit "Google.Safebrowsing.Proxy" set signature "F-SBID( --attack_id 9876; --name \"Google.Safebrowsing.Proxy\"; --service HTTP; --protocol tcp; -- app_cat 6; --pattern \"safebrowsing.googleapis.com\"; --weight 40;)" set category 6nextend config application list edit "AppControl" set extended-log enable set other-application-log enable set unknown-application-log enable set deep-app-inspection disable unset options config entries edit 4 set application 9876  
On the fortigate 100D, I configured an IPsec Site to Client VPN. How do I make the remote device connected to the VPN continue to access the internet? In this scenario it is Windows 11.
I have an HA Firewall in a Active and Passive system. When the system fails over the outbound WAN changes and I need to establish a vpn to the same destination. What is the best solution for this?I see the cookbook suggestion is SDwan VPN.https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/389913/dual-vpn-tunnel-wizardJust seeing if anyone else has done something like this
Hi, I'm trying to do a FortiAP implementation where there is a hotspot ssid with Captive Portal authentication. The requested design is that Cisco ISE should provide the Hotspot portal for clients.Did someone implement this design? Could it work?I find some documentation where there is a config example for that but it didn't work for me.My config is based on that, but it didn't work for me:config wireless-controller vap edit wifi-cap set ssid "fortinet-guest" set security captive-portal set external-web "https://<ISE_Portal>:8443/portal/g?p=jN9z47goOJg75HpaXxV8WZPQgd" set radius-mac-auth enable set radius-mac-auth-server "ISE" set radius-mac-auth-usergroups "AuthorizedGuest" set local-bridging enable set portal-type external-macauth set schedule "always" next Or the config from FortiGate side is only that, and we should look at ISE side? Thank you!
FortiMail 3000FFirmware version: 7.4.2 Two problems occurred when registering approximately 5,000 new aliases via CLI to FortiMail, which already has 100 aliases registered.1. When mail is received by newly registered aliases and existing aliases, mail is not delivered to members (user unknown is displayed even though the user is already registered).2. Adding/deleting a member in the GUI is not reflected in the alias where the above problem occurs (the member is deleted in the GUI, but the member still receives mail via the alias).The first problem stopped after I forced failover from primary to secondary in HA configuration,However, problem 2 continues to occur.Are these known issues?Is there a limit to the number of aliases that can be registered or the maximum number of members that can be registered in one alias? Is there any way to recover problem 2 ?
Hello, ADVPN DYNAMIC tunnel (spoke to spoke) is not getting established, getting below logs : ike 0:SPOKE1_0:426016: route configuration mismatch with SPOKE1 ike 0:SPOKE1_0:1658729:SPOKE1:426016: failed to add dynamc IPsec SA due to route clashike Failed to add selectors
Hi, We are looking to update our fortinet client build to the latest version, we have over 160 devices using the free Forticlient VPN software, after testing we have ran into a issue trying to deploy the latest build via our patch solution in which it is bricking the Fortinet Application completely and no longer loads with the below error, has anyone seen this? This can be resolved by uninstalling and reinstalling the latest version, however we need to find a workaround as there are over 160 devices with it installed. Thanks
Hello, I want to create an alarm in fortianalyzer for the next logs: Delete system.adminAdd system.adminEdit system.admin Can anyone told me how is the way to create this alarm? Regards.
Hello everyoneI am learning about Fortianalyzer, my knowledge is not much, so I come to ask for your help, I also have no knowledge about databases. My question is, how can I create a query or query in the database to give me all the columns or fields contained in the database of my FAZ.Apreciate it
Hello,I want to create a new operating system to include it in the OS checklist in the VPN SSL web portal configuration on FortiManager. I see that the current list includes Windows and macOS. My question is, how can I create a new OS entry for Linux Ubuntu 22.04, for example? How does FortiGate determine the version of the OS? Thank you.
Hello everyone, We have an OnPrem Exchange Server, it works via Fortigate as well. We only installed Fortigate about 6 weeks ago. Now we have the problem that access via OWA is not working properly. The OWA access and the page itself are fine, you can log in, see the email and click on it. However, the preview of the email is not displayed. But you can send a new email. Internally, i.e. via localhost\owa, it works without any problems. We are a bit confused, but suspect that Fortigate is the problem, as it worked before and also works via local. We have basically set up a virtual server in Fortigate and then a firewall policy. Does anyone have experience with Fortigate and a local Exchange Server? Emails via Outlook work perfectly, but these problems only occur with OWA. Do you need more informations? Thank you in advance for your time.
Hello Fortinet Community,I activated device control in #EDR to control the use of mass storage devices. The last days I created several exceptions for usb sticks with in the gui. Now we plan a bigger roll out of usb sticks. I want to prepare the exception in advance before handing out the sticksI used the API several times to handle collectors and their groups. This was no problem. The description of the API has a function call "create-or-edit-exception". The Exception data is mentioned as JSON in the body. There is no example for it in the dosumentation. I retrieved an exeption with "list-exceptions". I passed this JSON output to the create-or-edit function an get an error.So I´ve got the following questions:Can I create an exception for an usb mass storage device which has never generated an event?When there first has to be an event, can I used the event to create or add the device to an exception?Is there an example existing?My goal is to generate a script on an Linux machine in ord
Hi team,I am configuring FortiADC and have configured 1 VIP for 10 realservers (Layer 7). Then I have configured content routing for each realserver and it works. However when I configure 'redirect http to https' it does not work.Please guide me to configure Redirect using Content Rewriting feature.Thanks.
Hi teamAfter upgrading the FAZ to 7.2.9, I have experienced out D and some of our E series can not connect to FAZ due to SSL error. I have check this forum and have gone through them but still no good,Our VMs are fine, but it looks like its only the hardware ones. I have contacted support and they have gone though all the forums as well but can not get it to work. The software versions are all compatible Is there something I should also check and test? Thanks
I have a fortigate 60E with Fortios 7.4.7. I have FortiClientEMS 7.2.8. What I'm trying to find out is if I can block endpoints that don't have FortiClient installed from connecting via the WiFi. Are there any cookbook recommendations for this?
Hi, we recently changed from 300D cluster to 200F cluster. Now we see no logs, no information at all in FortiCloud. In the GUI Dashboard I see Status activated, connected to my account, storage used 0KB and no files uploaded. In System Feature Visibility I dont see anything deactivated which could have impact, Fortigate Cloud Sandbox is activated. In Security Fabric > Fabric Connectors and Logging Settings I see Fortigate Cloud activated and connected to send logs every 5 minutes to Fortigate Cloud. In Log Settings > Local Logs memory is activated since we also want to have the information there. We dont really see something missing? Thanks!
TopologySpoke ---ipsec--- SDWAN HUB ---ipsec--- DC (non Fortigate)Site A(Spoke) and Site B(Spoke) follow the same topology.However on Site A, when I do a ping sweep to a resource on DC I see a 3-4% packet loss, when I do a ping sweep from Site A to SDWAN Hub there is no packet loss. There are no packet loss monitored on the performance SLAs as well. I mirror the same test for Site B and other sites and dont have this issue and they are all using the same template configurations. Tried to play with NPU, MTU, MSS as per several guides but did not resolve the issue. env: 7.2.8
Hello, In the firewall logs, different app names appear while DNS is expected to be seen as application in internet-directed DNS traffic, what is the reason for this? Can you give information about the subject? Best Regards,İsmail Ürek
Does Fortinet provide a general overview of EOL dates for all FortiOS releases like this?ReleaseReleasedEnd of Engineering SupportEnd of Support7.49 months ago(11 May 2023)Ends in 2 years(11 May 2026)Ends in 3 years and 8 months(11 Nov 2027)7.21 year and 10 months ago(31 Mar 2022)Ends in 1 year(31 Mar 2025)Ends in 2 years and 7 months(30 Sep 2026)7.02 years and 11 months ago(30 Mar 2021)Ends in 1 month and 6 days(30 Mar 2024)Ends in 1 year and 7 months(30 Sep 2025)6.43 years and 10 months ago(31 Mar 2020)Ended 10 months ago(31 Mar 2023)Ends in 7 months(30 Sep 2024)6.24 years and 11 months ago(28 Mar 2019)Ended 1 year and 11 months ago(28 Mar 2022)Ended 4 months and 4 weeks ago(28 Sep 2023)6.05 years and 11 months ago(29 Mar 2018)Ended 2 years and 11 months ago(29 Mar 2021)Ended 1 year and 4 months ago(29 Sep 2022)
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.