Mark a Best Answer
Fortinet Community
Recently active
hello everybody am facing strange issue where I can't ping from our new site lets name it HQ-2 I have configured firewall policy and everything we have an ipsec tunnel between main site HQ and new site HQ-2 I have vlan for MGMNT other device in same vlan they can reach the AD via the ip sec tunnel such as switches but still my firewall can't ping when I run the command Diagnose sniffer packet to see whats going on it seems the firewall is trying to ping the AD via the dmz interface which has the ip 10.10.10.1 nothing is connected to this interface I have tried to use policy route but still the same issue any advice what could be the issue here ? thanks in advance
Hello!I need to set up FortiEDR notifications for when a collector/device gets put in isolation automatically via the playbook. All of the system/security event notifications are setup and work properly, but how do I get the isolation notifications sent to the distribution lists? Thank you!S0ck-Pupp3t
Hello,I'm currently configuring a second client IPSec VPN. The new uses IKEv2, on the same WAN interface/IPaddress. I saw help pages about the PeerID and LocalID, but my tries aren't okay. I have an phase1 error. I put a PeerID on the Authentication frame, and I reported it on the LocalID in the Forticlient configuration as I understand. Is it okay ? What about the LocalID on the Fortigate ? The existing Client VPN has this configuration :Is this configuration a problem ?
Good day Fortipeeps! I just wanted to ask if anyone has any idea how to calculate the total average or maximum CPU utilization. For example, the total average over 24 hours. I’m a bit confused about per-core CPU utilization. it is considered alarming if one of the core have high utilization?I would appreciate your insights Thank you!
 showing the error above, have not blocked the firewall/ traffic from between servers, please help to check it. thanks. FortiClient
Hey, I have device profiling rules one is for APs and the others are for Cameras and Printers with the Vendor OUI. When I plugged in an AP on Switch FortiNAC tagging it to AP_Role but the others does not work although it appears in the Hosts. Same configs for both of them. What could be the problem? It can detect AP but can't detect the others.
Hello everyone, I've configured the antispam profile action on FortiMail to use personal quarantine. However, the end user receives a notification about a quarantined email several hours later—sometimes even a full day later. I've checked the NTP synchronization, which appears to be fine, and the latency between the mail server and FortiMail is normal. My current FortiMail version is 7.4.2, and I plan to update to 7.6.0 to see if it resolves the issue. Does anyone have a better suggestion or know if there's a way to adjust this delay on FortiMail? Best regards,
Hi everyone, The ZNTA on my FortiClient EMS working well with SAML verification user and invitation codes. However, we got problem on connecting using the FQDN.- With unchecked "Enforce User Verification", the FortiClient using FQDN connect to EMS successfully without any SAML login (insecure as we adopt off-net workstation).- With checked "Enforce User Verification", the FortiClient using FQDN doesn't connect to EMS. The error message is about the connection require invitation code. if you made FQDN connection with user verification successfully, please kindly advise what is wrong or missing in my configuration setup. Thanks so much.
Hello everyone,I’m currently facing an issue with the FG3501F Firewall. If anyone has encountered something similar, could you share the technical reason behind it? Here’s the scenario:We have two interfaces on the Fortigate firewall connected to the Server Farm—Port1 and Port8. The goal is to route internet traffic via a static route and intranet traffic via Policy-Based Routing (PBR). We’ve configured PBR for the /16 subnets toward Port1 for intranet traffic, while adding a static route for the same subnets towards Port8 for internet traffic. However, the firewall is not prioritizing the PBR, and *all traffic is routing through the static route instead*. Any insights?
Heyho, just ran into this: On my FortiManager in an adom I added an IPSec VPN provisioning template in device manager. This has a phase1 and also a phase2. I had no problems with phase1. But I do have a big problem with phase2:I need to enter the selectors (dst-subnet and src-subnet) and I do enter the correct ones. However it doesn't matter wether i input them in the form subnet/suffix or subnet,suffix. When I click apply it says its invalid.If I create the phase2 without templete and the same subnets it works fine.Any clues?
I am setting a new Firewall Cluster, when I import the firewall policy (show firewall policy/show) from the previous Firewall into the new Firewall (excluding UUID details) I can see the new policy on the new Firewall "show firewall policy" but I cannot see the policy in the GUI...! If I create a policy rule in the GUI I see the policy in "show firewall security-policy" but not in the "show firewall policy" ouput I am really struggling to see why? There are no advanced features in the policy just source/dest/port/accept.Is there something I need to turn off? This should be just a simple import, there are too many existing rules to import manually.
Hello. We have a Fortigate where we have configured exporting syslog messages to an external syslog server, the problem we have is that we are getting alot of syslog messages most of them informational and Notification severity. Is there a way we can filter what messages to send to the syslog server? for example, only to get messages of Warning severity or above.
Hi FGT adminsCan FortiOS be compromised? I mean like any other OS by an attacker or a malware.Have there been any known cases?Is there any method to check if my FortiOS is compromised?Does FortiOS checks itself for possible compromise?Note: here I'm talking about FortiOS itself, not about FortiGate configuration.
We can install any version of FortiClient VPN on brand new Macbook (15.3 Sequoia).Problem lies in the new MAC security layer in the OS. Creating a connection then clicking on Connect produces an error: "To connect to the VPN with FortiClient, open Security & Privacy Settings and allow the system software from FortiTray".Problem is that option is NO longer available is the new Mac OS versions.Called Apple to confirm this is a issue, and they report the section of the security applet has been removed and will not come back. See screenshot. Will there be a newer build to accommodate for this new Security Change is MAC OS?The version shown here is the latest 7.4.2.1717Thanks!Brett FlaggIntegraONE
We're looking to monitor FortiGate DHCP information using SNMP from a remote appliance for historical and alerting purposes. We used the published KB to create an additional poller for the listed OID but the problem we're facing is we can't figure out how to corelate the utilization to a specific interface. Being able to simply trigger off pool exhaustion is handy, but the historical data and even the alerts and semi-useless if we don't know which network or pool it corresponds to. Is anyone out there today familiar with this? Ref:SNMP traps and query for monitoring DHCP pool | FortiGate / FortiOS 6.4.0 | Fortinet Document LibraryMonitor DHCP via SNMP - Fortinet Community
Anybody else seeing a pattern with 50E dying? I had these deployed for about two years. I've had two starting to have packet loss and one that's not forwarding even though port is up. I saw a thread on reddit and this is starting to become a growing concern. I was able to have the client replace two of them but I'm afraid we're going to start seeing more problems with the 50E. Anybody know if we can RMA these still without support? The client is going to lose confidence in Fortinet. This rate of failure is unacceptable. Update 2022-02-03:Had another two breaking down. 1 is showing slow speeds. The other one isn't passing traffic even though port is up. 6th 50E broken now. Update 2022-04-26:2 more units bad.
Hi team I have a scenario where some end user machines are being blocked from accessing DNS yet the services in the policy are set to all services. This is affecting some machines while others are working fine #FGT
We are looking to integrate our ConnectWise Manage (CM) ticketing system with our FortiVoice Call Center IVR, but I cannot find documentation for this. I see that multiple FortiProducts offer a connector of sorts for CM, like FortiSOAR, but I don't know if FortiVoice can do this natively, or if FortiSOAR can connect to FortiVoice to do this.Ideally, a customer would be able to create a new service ticket in our CM system while on the Call Center IVR or have the ability to pull up their service ticket from CM.Anyone have any ideas?
How would one go about showing the upgrade history going back at least 18 months on a 1500D?
I am just wondering if someone is aware the order of security profile processing in FortiSASE? What i am trying to understand is if URL filtering gets processed before the CASB App profile? Or does the App profile gets processed first?Is there a order in terms of how this is processed. I am aware in terms of how security policy is processed but not too sure around the security profile order.
Could someone guide me on the correct process to extend the FortiPAM VM hard disk size and allocate the extra space to the system? Are there any specific commands or steps required within FortiPAM to recognize and use the new disk space after increasing virtual disk size in ESXiAny help would be appreciated.
Ive been working on this guide to configure DHCP over IPSEC without problems .https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/189440/ipsec-vpn-with-external-dhcp-serviceThe problem is when the remote user disconnected , the device sends a dhcp release to the dhcp server and the lease goes off.This is the main reason im migrating sslvpn to dhcp over ipsec if to remains ips of device for 2 weeks at least base on the mac address.This is what i saw when users disconnected.DHCP 342 DHCP Release - Transaction ID 0x34073082
Hi!I think I'm confortable with Azure networking, I'm ok with networking in general. Yet I never used SDWAN feature on Fortigate.I'm looking into the option to put a single Fortigate VM into Azure in a hub&spoke model and use SDWAN feature. I don't really see a need for Azure virtual WAN as per the size of the limited deployment, and the cost of Az vWAN can't be justified. I would appreciate some guidance please.1/ Is it possible to have Express Route and Internet as the underlay networks? Any limitation?2/ Is it possible to have Express Route reachable on internal/LAN side in such a SDWAN setup? Or does Fortigate SDWAN zone setup require a dedicated NIC for WAN port?3/ Any Fortinet document you would recommend please? Googling Fortigate SDWAN and Azure always returns content related to vWAN deployement model.Thanks!
Hello,I would like to know if it is possible to change the AND in the fields to OR because I would like my action to be triggered only if one of the parameters I define is triggered.Thank you in advance.
I have lant to migrate all of virtual machine to new server in different location, and we need to keep same ip address.The vlan handled by core switch and the core switch connected to the fortinet, in new location i also have same devices and both location have internet connection.Since the migration will done partially, this need both location should have same ip address, same vlan and can communicate each other.So can we use VPN in fortinet to transfer Vlan ? In my mind if we can transfer vlan over VPN then the new location will have same vlan and each host on new location can communicate with devices in of location.IF migration is done for all virtual machine then i can shutdown vlan interface on old location and make new interface vlan on core switch in new location.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.