Mark a Best Answer
Fortinet Community
Recently active
Hello.After updating our Fortigate devices (40F, 600E) to 7.0.17 we've got a window to choose a personal cert.The windows comes up up, befor I can enter my credentials. Where is this to change back (we don't use this feature), or where can I add a valid cert? Thanks in advance for your answers. RegardsDirk Emmermacher
Alert messages are not received because the recipient address cannot be registered
hi,i have a licensed forticonverter and converted a cisco ASA config.the ASA config had only basic LAN, WAN, no NAT, and "inbound" ACL (internet > WAN) applied on the WAN/outside.my question:1.do i need an FW policy for the "outbound" traffic (LAN > WAN)? is this for "ALL" traffic outbound?2.do i need to have a "reverse" FW policy for each "inbound" ACL/FW policy? config firewall security-policyedit 1set srcintf "port 1" <<< WAN/outsideset dstintf "any"set srcaddr "all"set enforce-default-app-port disableset dstaddr "all"set service "echo-reply"set schedule "always"set logtraffic disableset status enableset action acceptset comments "access-list acl_outside extended permit icmp any any echo-reply"nextedit 2set srcintf "port 1" <<< WAN/outsideset dstintf "any"set srcaddr "all"set enforce-default-app-port disableset dstaddr "all"set service "time-exceeded"set schedule "always"set logtraffic disableset status enableset action acce
hi,i configured a new FGT VDOM and was trying to configure DNS.does all VDOM rely on the configured "global" DNS settings?or can each VDOM have its own DNS setting? fgt (vdom-a) # config system ddhcp Configure DHCP.dhcp6 Configure DHCPv6.dns-database Configure DNS databases.dns-server Configure DNS servers.dns64 Configure DNS64.fgt (vdom-a) # config system dns-server <Enter>fgt (vdom-a) # config system dns-serverfgt (vdom-a) # set command parse error before 'set' fgt (vdom-a) (dns-server) # edit Add/edit a table value.delete Delete a table value.purge Clear all table values.rename Rename a table entry.get Get dynamic and system information.show Show configuration.end End and save last config.
I need to know about IPSec VPN for a FortiClient VPN tunnel. Are there any limitations to using a single WAN interface? I have already created an IPSec VPN tunnel for FortiClient, and it works perfectly. However, I created another tunnel for the same WAN interface, but the new one is not connecting with FortiClient VPN. Please help me resolve this issue. version - fortigate 1500D 7.2.9
Hi there, I'm trying to generate an ACME cert on my FortiGate, just as I've done on my EMS server, but it always fails with a "Timeout during connect (likely firewall problem)" error: Port 80 is wide open to the world and you can see the traffic coming in when running a diag sniffer. From me running a curl against http://vpn.<mydomain>.com: I'm at a loss. Does anyone have any ideas or suggestions? Thanks!
FAQ followed and it has worked like this for years:https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-use-FortiClient-SSL-VPN-from-the-CLI/ta-p/192581I use this for the automatic VPN tunnel setup for the backup clients outside at home.For 2 months now, the parameter -i -m -q has no longer worked, which says "do not display a certificate message", i.e. the message always appears and no tunnel is automatically set up, i have v7.23.Tried:Then I downloaded the latest version 7.42 Fortitools and adjusted the command and then the parameter -u "enter user data according to text file" doesn't work anymore and no tunnel connects, but when i type in the credentials manually it works and no certificate warning comes - but automatically is needed.It almost seems as if Fortinet has tightened security here "no stored access accepted" and in the old version "certificate must not be ignored" disabled?I need an automatic VPN tunnel setup because of the weekly backup from the target clie
Trying to import license manually for offline device getting error license activation failed.
I have one blocked when the MAC of the machine is not registered in my DHCP reservation it does not browse, would there be any warning when anyone tries to put a machine on my network to warn that it is trying to get IP?
I have read every article on the internet on this topic and worked with Fortinet TAC for 2 days. All of the articles say you can secure the public IP of the Fortigate by putting the public IP in the Host IP section for the common name in the CSR. Done this, does not work. Once the wildcard is rekeyed for the subdomain it shows the top level domain in the cert and that it is applied on the IP login but the browser still says not secure. I have tried this with the SAN as the DNS name for the site, and it secures the DNS name for the site but not the IP. Has anyone successfully done this and how, and why would Fortinet documentation say this can be done if it can't (this is what TAC says and would not escalate)?
Dear Community,We are currently experiencing intermittent disconnections for remote users connecting via SSL VPN on a FortiGate 80E running firmware version 7.4.6 Build 2726 (Mature). The FortiClient versions in use are 7.0.14.0585 and 7.4.2.1737, and the operating system is Windows 11 version 24H2 23100.3037.Upon initial investigation, it appears that the disconnections tend to occur shortly after a download process begins. However, we have also observed random drops, even when the connection is idle, suggesting that the issue may not be related to download activity alone. It is also important to note that some users are not encountering this issue, indicating that the problem might be isolated to specific configurations or environments.Has anyone encountered a similar issue with this firmware, FortiClient versions, and Windows 11? What could be the potential causes of these random disconnections? Are there any recommended configurations, best practices, or troubleshooting steps to he
Hi FWB adminsAny idea on how can protect web server from auto clicker with FortiWeb?
We have multiple users experiencing issues with random SSL VPN disconnects. We've tried various versions of the FortiClient from 7.2.x and 7.4.x. No changes regardless of version we try. All computers are the same Lenovo hardware and are running Windows 11 23H2. The commonality between users is that all of them have Comcast modems. If a user has his/her own modem and router, no reported issues. We've tried various uninstalling/reinstalling, reimaging the PCs, nothing works. Found users with similar issues in the Comcast forums:https://forums.xfinity.com/conversations/your-home-network/same-issue-vpn-disconnects-from-wifi-on-work-computer/65e9fbc045834d314f456a24?page=2. I am fairly certain this is an ISP modem issue. However, I am wondering if there is anything we can do to resolve this issue. Setting change, etc. Thanks for the help.
Hello. I noticed a pattern in the Fortigate file filter (both for proxy-based mode and flow-based mode). Files larger than 10 MB are not inspected by the file filter. SSL inspection is enabled in the deep inspection mode. Traffic is processed by the device according to explicit proxy policies. Also in the file filter event logs, there are events of files less than 10 MB in size that were inspected. Has anyone experienced this behavior? Is this normal file filter operation on Fortigate devices? In the “print tablesize” output, I could not find any indicators that explicitly set this limitation.
Hello,I am looking for a way to do a factory reset of a Fortigate from a Fortimanager.I haven't found anything in the documentation about this.Am I missing something or is it really not done?Thanks in advance for your feedback.Regards,
Dears , I have read in some Fortinet presentation about Fortivoice that the Fortivoice has an embedded basic SBC. At the same time, Fortinet didn't mention anything about it in all FortiVoice documents. My question Does this feature really exist in the Fortivoice or not? If yes, where can I read in detail about it? BR,
Hi, In fortisase portal we are able to enable scheduled vulnerability scanning. We are checking for the option to enable the auto patching for the vulnerability.We checked fortisase admin guide and not seeing any option of auto patching.Will fortisase do the auto patching like Forticlient EMS ?Please guide.. Regards,Ganesh Karale
Hi all, I'm planning to do SDWAN with my current setup, but I've to admit that my setup might not be optimal. Currently the setup is, LAN --- HQ FG --(Single WAN)-- LB (3 WANs) -- Internet -- (Single WAN) -- Branch FG.My plan, was to build 3 IPsec VPN tunnels, and implement SDWAN over it. So the best performance tunnel will be selected automatically. I tried a few methods but I failed,1. Secondary IP with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.2. Loopback interface with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.3. Peer ID, Local ID.4. Network-overlag, network-id. I'd like to seek for help on how can I achieve my plan with SDWAN. Appreciate any help, and thanks in advance!
We recently started using Fortigate 200E 7.2.4 build 1396 as our external network interface. IPSEC VPN was enabled on WAN1 for company employees to access the internal network. Two key issues arose: Most users worked fine, but some users' VPNs were not stable and would always disconnect automatically.In addition, some users with Home Internet could connect to the VPN, but they could not use the ODBC driver configured by Microsoft Access to access our database when connected to the VPN, and would always receive various ODBC errors.But the strange thing is that when they switched to mobile hotspot, it worked fine.I would like to know if anyone knows what the general cause of this situation is? How can I check these issues and fix them?
I was following a tutorial on how to integrate Entra ID SSO with FortiWeb and there's a segment that says"<FORTIWEB_NAME> is a name identifier that will be used later when supplying configuration to FortiWeb. Contact FortiWeb Web Application Firewall support team (mailto:support@fortinet.com) to get the real URL values. You can also refer to the patterns shown in the Basic SAML Configuration section." I was wondering how to get the value for "<FORTIWEB_NAME>".I'm new to navigating the FortiNet support system/forums/etc. so I don't know if this has been answered already or if I need to reach out elsewhere to get an answer for this, but I would appreciate any help with this matter.
Hello, Has anyone had problems with Fortiuathenticator 2000E when upgrading an HA cluster from version 6.3.1, build0682 to version 6.3.4 build0694?
I have an SSID for staff working fine.The second we connect to the Foriclient Telemetry the internet keeps droppingI have a constant ping running without a blip - connect to Forticlient and then i get lots of failures.Need Forticlient for VPNtried turning off all the different components but still the same What is causing this? Fortigates, Fortiswitches and Forti APs
Hi,I'm looking to add radius authentication for administrators on the FAC in our deployment, currently we're using simple local users.I would like the Radius request to be sent to a remote radius server, from the FAC. The FortiAuthenticator is running version v6.6.2, build1669 (GA).I can't find any cookbooks or guides on how to enable radius for administrators using a remote radius servers. Is anyone able to provide me with either a guide, or some assistance ?Thanks in advance!
I have recently set up Fortigate Evaluation VM 7.0.14 to test IPS in GNS3. Have created IPS profile with specific signature to Block. But it doesn't seem to be blocking. I would like to know, does the evaluation VM supports IPS with the signatures available in the pre-built IPS DB.
We are planning to transfer a FortiGate 40F firewall to another company and need to change the account associated with its serial number. This change is required so that the new owner can purchase and activate the necessary licenses.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.