Mark a Best Answer
Fortinet Community
Recently active
Hello everyone,On one of my phones, when I use FortiClient to connect to the VPN, I receive the following error message, followed by an automatic disconnection after about 5 seconds:"Your device may not support more than 30 routes."Note that the FortiClient VPN works fine on my other phones.Thanks in advance for your help!
Hello everyone, I want the FML administrator(s) to receive a "notification" whenever an email is being quarantined, I thought about creating a notification profile, but I want a notification specific for quarantined emails. Does anyone have a better suggestion ? Thanks in advance Best regards,
I have a hub-spoke setup using BGP in a SDWAN setup. The SDWAN is due to having a fibre connection and a 4G for failover. So obviously I have both under each Zone.HUB -> Spoke1HUB -> Spoke2The hub has a Dialup IPsec tunnel for fibre connection and one for 4G connection to allow multiple connections from all the Spokes.Spoke1 has static IP IPsec VPN connection from its own fibre connection to the fibre connection of the HUB, and Dynamic DNS IPsec tunnel from its own 4G to the HUB's 4G connection. Spoke 2 has the same setup to connect to the HUB. I use BGP to advertise my internal networks of each of the 3 sites. Everything internally is working and the internal networks can talk to each other, including when failing over to 4G. My problem comes in with the FortiClient VPN. At each site I have a Dialup FortiClient VPN setup. When I connect to the remote VPN, I can access only the resources of the LAN at the site I am connected to. I can't talk to other IP ranges
When attempting to connect via FortiClient VPN (version 7.2.3.0929), the input modal for login credentials will appear after pressing the "Connect" button. However after an update 3 days ago, it is not appearing as it normally does. The issue occurs immediately after clicking the Connect button.Technical Details:- FortiClient VPN version: 7.2.3.0929- Operating System: [Windows 11, version 23H2]FortiClient
The internet archive is being flagged as "bittorrent" whenever the residents here try to read a book, stream a TV show, or ANYTHING. Case in point, this is antiques roadshow, this is free to use under public license, as it was released on PBS, but fortinet is blocking it: https://ia600508.us.archive.org/4/items/antiquesroadshowspecial/Antiques%20Roadshow%20Special%20Edition%20Discovering%20Americas%20Hidden%20Treasures.mp4 It is false flagged AS TORRENT, what gives?! Please, I am requesting that ia#.us.archive.org be removed from your weird torrent filter thing, it is a false flag. I know there's .torrent files there, however all p2p bit torrent files on the internet archive are generated BY the internet archive, and are heavily moderated. They are all 100% legal and do not require moderation from fortinet as well, because you're blocking NON-torrent files too. For many, the internet archive is an important resource for being able to read books, etc. Thank you. 
We just had to revert to Forticlient VPN (free) 7.2.8 for IPSec with SAML and we're running into an issue with the inline webbrowser staying logged into the wrong Entra account (we support multiple clients). I can't find a way to clear the cookies. I've used the button within the app, deleted everything I could find in the Appdata\local\forticlient dir. cleared cached for microsoft in Chrome and Edge and Internet Explorer. I can't get it to shake my Entra joined Windows credentials. Does anyone know how to get it so that I get prompted for Microsoft credentials at each login. This was working earlier today and now doesn't.
Hi,I am facing the task of migrating EMS from version 7.2.8 to 7.4.x. If I follow the migration documentation, will the SAML SSO settings also migrate or will I have to re-configure SAML SSO for this installation? RegardsAndrzej
Hi,I cannot find 100% answer to this question: Who manually creates there own installers, and manually pushes the FortiClient installer out or who leaves there FortiClient on the auto upgrade recently there has been a tonne of releases and still not managed to get on the latest version. Thanks, Harg-IT-Admin
I want to migrate my FortiEMS on prem to FortiEMS cloud, as other branches are already using the cloud version.Is there a way to migrate the configuration and the clients without a longer interuption to the cloud version without the BPS license or is it needed in that case?
I am using FortiClient Version 7.2.7 and whenever clients try to connect to the EMS withing the LAN they receive a "failed to verity server certificate" message.Connecting via a mobile hotspot works.Does anyone know why this is happening and how i can fix it?
Hi everyone,I have 4 Vdoms (Internet - local DC servers - Paretener - SSL VPN & IPsec), I have observed that one session is duplicated over every VDOM traffic that passes it. how I can terminate sessions from repeating through other vdoms?-Example:SSL users want to connect to the DC server and use the internet, the session will throw (SSL Vodm) then through ( DC srv vdom), and so on.... this causes multiple sessions consuming device resources. any idea to prevent the same sessions over multiple vdoms?Thanks for all,
Hi, I read the CVE article below and wonder if I need to upgrade FortiOS:Fortinet Security Advisory: FG-IR-24-535My FortiOS version is 7.0.16, and the HTTP/HTTPS administrative interface is enabled only on the LAN interface (disabled on the WAN interface).Do I need to upgrade FortiOS to protect against this vulnerability?
I am stuck in a situation where I am facing an issue with Google Meet video and voice within the enterprise network.I am using a 100F FortiGate firewall and have created a policy to block all unnecessary traffic from the public internet. Additionally, I have created a policy for Google Meet with no inspection. However, I am still facing the same issue.Can anyone help me with this? Is there any issue with NPU-offloading which is causing the issue in the google meet performance. 1. Implemented QoS for Google Meet, but it did not work.2. Implemented a no-inspection policy to bypass UTM features. #fortigate
So, I have an E61 firewall and it's got a nice SSL VPN on it for my 10 or so users who are in other countries. These users connect and we are using an LDAP integration for authentication. Today, I found out that people are trying to access the SSL VPN using real usernames from the org, and when they enter the wrong password three times, the user is locked out of Active Directory. For now, the SSL VPN is disabled. I need a solution for this. My first thought is to get some tokens and enable 2FA. Can some of you experts make some suggestions about how to best mitigate this? Thanks
I need to make it so that when a machine plugs a network cable into my network it can't get an IP via DHCP, but when I register the machine's MAC it can use my NETWORK, how could I do that?
Hey everyone,I'm curious about what public DNS servers you rely on in your infrastructure. Do you stick with the usual suspects like Google (8.8.8.8), Cloudflare (1.1.1.1), or OpenDNS? Or do you prefer alternatives like Quad9 for security-focused resolution, or local DNS servers or the ISP ones ?Would love to hear your recommendations and the reasoning behind your choices!
Hello, I have full read-write access for all features in my FortiPortal user profile, however I do not have edit options for the central SNAT rules.Can anyone advise how to activate this feature-set within FortiPortal ? - or even if it is possible ? Thank you.
Hi, May I know if possible FortiGate support two separate HA instances running with each other? If not, may I know the best ways to test it? Thanks in advance!
We decided to implement an SD-WAN solution for two branches and the head office. We plan to deploy one FortiGate firewall at each branch and a clustered firewall (HA pair) at the head office. We are facing a licensing issue when attempting to apply a FortiManager Cloud license for this solution due to the clustered device. Can we proceed with a FortiManager Cloud license for three devices for this solution, or do we require a license for ten devices?
Hi Team, I am was checking in CLI command in fortinet 100E the following below command. #Execute Sensor listand its showing me RPS -LOst what does it mean ?XXXXXXX # execute sensor list1 PSU OK2 RPS LOST3 FAN 1 CPU Fan1 Speed 8232 RPM4 FAN 2 CPU Fan2 Speed 8599 RPM5 TMP 1 External thermal sensor 38.38 C6 TMP 4 On-die thermal sensor 32.00 C
Hi,Due to recent vulnerabilities in radius, we would like to enable Message-Authenticator on our clearpass server.After enabling this option in clearpass, we get errors in clearpass that the radius packet received from FortiGate-1100E (v7.2.8 build1639 (Mature) is without Message-Authenticator as below.Is it possible to enable this? Source RADIUSLevel ERRORCategory AuthenticationAction UnknownDescriptionFailed to decode RADIUS packet - Received packet from x.x.x.x without Message-AuthenticatorTIA :)
Hi folks.I did not found an answer in the following request:FortiGate ver. 7.6 with managed FortiSwitches & FortiAp's.Created an SSID in tunnel mode, and i want to mirror this traffic to a port in the FortiSwitch for sniffing.Any idea?(creating software switch does not have the choice of selecting the SSID interface).Thanks
Can you use the the newer Biometric Yubikeys with FortiAuthenticator? They have a limited feature set when compared with the Yubikey 5. They do not support TOTP/HOTP which in some documentation I am seeing is a requirement. I don't know if that has been solved in future versions.
Hello,I have one question, so I'm posting it on the community. One document says that the UTM and UTP licenses are the same.Another document says that the UTP license is a higher version of the UTM. If anyone knows the difference between the UTP license and the UTM license, please explain. Thank you.
Hi Dears, We have two standalone Fortimail, configured in gateway mode. so there is no configuration sync between them.DKIM key generated on first one, and I want to export and import it on second one, to be synched and sign emails properly.I think it should be managed in the CLI, but I can't find the way.Thanks in advance
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.