Mark a Best Answer
Fortinet Community
Recently active
Is there a manager who has experienced that symptom?
I am successfully receiving dynamic firewall tags on my gate from NAC.I would now like to setup FSSO Firewall User Tags. The FSSO communication on port 8001 is established (NAC port 1 has allow fsso) However, I am not getting any users/groups listed. NAC is successfully pulling groups from my AD. I think I must be missing a config in NAC.Any ideas ?
Hello, In a Fortinet SD-WAN setup with an active-active dual-hub architecture with iBGP in the overlay, are there any best practices or guidelines concerning inter-hub communication? This comunication is made in the same overlay that Spoke Hub communication. Best Regards,
We have upgraded to v7.2.8 to 7.4.5 but we faced challenges such as. Unable to boot device.Not able to access GUI.Need to reboot device to get Arp (get system arp)Can anyone faced this kind of issues or not recommendations are welcome
Hi,We are experiencing issues with FortiClient. Some of our staff are connected, but they cannot access the remote local IP addresses, which prevents them from connecting to the RDP servers.I had a call with a FortiGate technician yesterday, and he advised that there is no configuration issue with FortiGate; it is configured correctly. The problem seems to be with FortiClient, which is not passing traffic from the local computer.I've noticed that this issue occurs mainly with staff using Windows 11. It does not happen consistently—some staff members can connect to the RDP servers, but then suddenly lose access. After a few minutes, the connection may start working again.I will appreciate if anyone can advise on this.
I am trying to debug some ssl-vpn connection stuff. If I run "diag debug application sslvpn -1" it generates a lot of debug lines. Downloading the output and filtering through it to find what I need is not fun. Is there a way to filter this by the source IP of the remote VPN client? Or by some sort of VPN session ID? Or something so that I can focus on troubleshooting a single user without having to wade through all the other connection data?
Does fortinet consider start providingh VPN only MSI format installers? so we can push the vpn clients thru GPO or other RMM tools? and if there is one for, if you could create one that is OFFICIAL, i would like to get hands on it. FortiClientVPNSetup I am looking for the latest the greatest version.
Hello,I'm working on the use of an AD group to allow VPN Access. Is it possible to manage Fortitoken Mobile by the mean ?
On January 19th, we started to receive SOC alerts for failed logins to a FortiWiFi 60E running 7.4.3 (Feature). Normally we don't push out Feature version firmware so why it is installed is another story unrelated to the current issue. I do not have a date on when this Firmware was loaded so I am unsure if this has been an issue since loading 7.4.3 or recent issue. We did have SSLVPN enabled for 443 up until January 1st at which point it was reassigned to port 4444 and disabled in favor of Remote Access IPSec. We found that there is a Local In policy for HTTPS listening on ANY interface rather than just the LAN interface where HTTPS is enabled on the interface. We cannot remove this listing. The FortiWiFi is without subscription and stuck on 7.4.3 using Automatic Upgrade. The downside is that Automatic Upgrade is failing to download the image for the next mature image available. I really loathe 7.4 introduction of blocking manual upgrades when there have been a number of critical
Hi FGT/EMS adminsIn FOS 7.2.10 I was able to add multi TCP Forwarding entries in my ZTNA server, while in FOS 7.4.7 I can add only one.Why this has changed? Did I miss something?
Hi There,I hope it is possible.My company uses Office 365, therefor we use the office 365 Active directory solution.in case it is possible - I was wondering how do I integrate between my 40F, running the latest firmware with the Active directory - in order to login to the 40F.I want to use my AD user instead of local user. I prefer not to install LDAP server etc. since we don't have hardware for it.
Fortinac is configured to send firewall tags to my gate. Communication is working fine. For wired switchports in Role Based Access mode, the tags are being properly sent when the Network Access Policy is matched. However, I can't seem to get it working for wifi. Although the correct NAC policy is hit, logical network is assigned, and VLAN is changed, I still get:Looking up LogicalNetworkConfiguration for LogicalNetwork prod-wifiUsing SSID Name:root:corp_wifi, id: 439Returning LogicalNetworkConfiguration: AccessConfiguration- Task ID:[null]- Network:[prod-wifi]- Access Value:[VLAN_230]- Access Action:[2]- Alias:[false]- Send Groups To Firewall:[false]- RadiusAttributeGroupId:[1]- Version:[9]- Tags: []- Firewall Groups: [] One thing I noticed is there really isn't a config for applying RBAC to a Wifi SSID. Could this be the issue ?
Hi expert, Over the few hours I am trying to ping tunnel interface ip address from HQ to BR, unable to ping even after enabling ping at interface leve. please guide me what to do next. please rerfer the snapshot.C *> 1.1.1.1/32 is directly connected, PrimaryVPN1S *> 1.1.1.2/32 [5/0] via PrimaryVPN1 tunnel 10.10.30.2, [1/0]C *> 2.2.2.1/32 is directly connected, SecondaryVPN2S *> 2.2.2.2/32 [5/0] via SecondaryVPN2 tunnel 10.10.40.2, [1/0]S *> 1.1.1.0/30 [5/0] via B2HO_VPN1 tunnel 10.10.10.2, [1/0]C *> 1.1.1.2/32 is directly connected, B2HO_VPN1S *> 2.2.2.1/32 [5/0] via B2HO_VPN2 tunnel 10.10.20.2, [1/0]C *> 2.2.2.2/32 is directly connected, B2HO_VPN2 Note policy is already created all and all over tunnle interfaces.
Hi.As in topic. We have few computer in which when trying to connect to our VPN using SAML login w external browser the browser itself won't open. We tried reinstaling the forticlient with older versions, nevest version, adding and changing default browsers but nothing is working. FortiClient ver. 7.4.0.1658, Windows 11 24H2. Anyone have any idea what we can do to help except new system instalation?
Hi, I have a Fortigate 60F and need to create an IPSEC tunnel to a non-Fortigate device. My problem though is that there is an existing router in my way. I'm unable to remove the router and I can't get into the settings of it. It's needed for the ISP's mesh wi-fi setup I am told. 1. Can i place the Fortigate on the internel network and have it negotiate the tunnel? I don't think it would get the traffic.2. Put the Fortigate at the edge in transparent mode and establish the tunnel? It doesn't have any L3 addressing so not sure that's possible.3. Double NAT? yikes
HiI cleaned all the website filesI installed "Really Simple Security" and "Wordfence Security"I scanned the website from the cPanel with imunify 360Pleas check an remove the website mnblaw.co.il from your black list Thank youAvihay
Hi. Can anyone share how to upgrade ADOM from FMG using offline mode? Thanks.
Hello support,Is anyone else experiencing issues with Forticlient VPN on MacOS 15.3. Before the update on version 15.1 everything was just fine. Thank in advance.
With WPA2 you just use a psk and with standard SAE you do also. There is another option to use a private key which i tried, however the end machine does not ask for private key. What are the pros/cons of generating a private key which also lists a password(s)?P.s. on a new AP now not intergrated Wi-Fi.Thank you
A customer currently has Kaspersky Antivirus installed on their endpoints and is considering deploying FortiEDR. They would like to know:Can FortiEDR coexist with Kaspersky on the same endpoints?Is there an Active-Passive kind of mechanism available that allows them to keep both Kaspersky AV and FortiEDR running without conflicts?Can they also have Microsoft Defender alongside Kaspersky and FortiEDR?Any insights on best practices, potential conflicts, or required configurations would be appreciated. Will there be any performance impact?
Hello members, I have scenario where customer wants to use 7.4 and still be able to utilize SDWAN templates for 3 hub sites. I know that on 7.6 there is an option for Multi hub but can anyone provide any pointers using 7.4 version? TIAHitFortiManager FortiGate
Hello, we recently updated our FG100F to 7.2.10 from latest 6 OS and we find something in the Dashboard > Network > IPSec strange. In the remote Forticlient VPN configuration we decline the network 10.10.10.10-10.10.10.200 so the Forticlient adapter should give our remote users IPs from this network. Now in this widget I find it strange that as Peer ID information I get from all users 192.168.1.X. This 192.168.1.0/24 network is the WAN where all Remote Clients connect to, but I dont understand why I see these IPs. Checking on the logs I see the Local IP 192.168.1.254 (whis is the IP of the WAN Inteface) and User 192.168.1.X. Than in the event I see the correct information, assigned IP 10.10.10.X, his remote public IP X.X.X.X What do you think? Thanks
i am doing license renewal for fortiproxy using fortimanager as fortiguard server in an air-gapped environment.after uploading the entitlement file into fortimanager, i could not see the new expiry date when executing the below command:diagnose fmupdate fds-dump subscan anyone advise if there is any issue with the entitlement file?
Hi. I need to renew license for FortiProxy in offline mode using FortiManager as the FortiGuard server. On FortiManager, I have to manually upload the Entitlement file using SCP. The command executed is as below. execute fmupdate scp import license EntitlementExport 10.22.33.44 folder1 user1 password1 However, it is giving error message as below. Start getting file from SCP Host...SCP session read error: 5(Input/Output error)SCP failedUpdate failedCommand fail. Return code -902 Can anyone tell me how to resolve this error?
Hi, EDIT:I alreay find the solution, just set the set name using "msg", and it is working as expected.---------------------------------------------------------------------------------------------------------------------------------I am new to fortigate, I just got a fortigate 60e(192.168.98.99) with os version 7.4.7, and a debian device(192.168.98.178) directly conneted 60e.I setup a link monitor on 60e in order to monitor if the debian device is online or not.Till now, link monitor is working as expected: # diagnose sys link-monitor status Link Monitor: n1, Status: alive, Server num(1), cfg_version=0 HA state: local(alive), shared(alive) Flags=0x1 init, Create time: Sun Jan 26 16:39:12 2025 Source interface: internal5 (12) VRF: 0 Interval: 2000 ms Service-detect: disable Diffservcode: 000000 Class-ID: 0 Transport-Group: 0 Class-ID: 0 Peer: 192.168.98.178(192.168.98.178) Source IP(192.168.98.99) Route: 192.168.98.99->192.168.98.178/32, gwy(192.168.98.9
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.