Mark a Best Answer
Fortinet Community
Recently active
Gentlemen, I'm adding a third-party camera to my equipment, I've already tried many different settings, but the error appears: Failed: Invalid value: Get object (MediaProfileCollection)Has anyone gone through this?7.2.2
Hello,Is anyone using FortiClient as a replacement for 3rd party AV software?Considering replacing what is currently being used but curious to hear what others are doing.Our entire network stack is Fortinet hence the thought to integrate it into the Security Fabric.Thanks
What are you using to monitor and automate FortiADC?I've read in some post that the Ansible module is lacking and there's no support for open telemetry, just SNMP – I'm not sure how to get the OOID descriptions and I could not find much information with people using prometheus or datadog with it.For FortiGate there was a prometheus exporter but it seems the developers got tired of supporting it without Fortinet help on documentation.
I managed to get my hands on another fortigate, hoping this would be unclaimed. This time it's a 200F. I can't reset the password though. I have followed any and all guides I could find. I have tried just holding the pin down for 30 seconds, it just reboots and didn't go default.I have tried to press the pin down when the status light comes on, but when it does it is already started and ready to login.I followed this:https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-To-Reset-To-Factory-Default-Configuration/ta-p/198660None of the way presented here works. Maintainer account does not work, or is not active. I have also tried to break it during start up. I found a guide saying I could press any key when it starts, and I've tried: Press any key to display configuration menu... .. [C]: Configure TFTP parameters. [R]: Review TFTP parameters. [T]: Initiate TFTP firmware transfer. [F]: Format boot device. [B]: Boot with backup firmware and
Hi we are new to fortigate's and need a little help/advice. We are currently adjusting the security level of our firewalls to a higher level. i.e we setup up the firewall rules first, next we implemented the IPS-sensor on a interface policy. After this we added the web-filter profile to the same policy. so far so good, but when we added the AV-profile also to this interface policy a important application stopped working. We checked the security logs but there are not active blocks/messages regarding what is being blocked. We made a second interface profile and only added the AV-profile and enabled it ... the applicationn is no longer being blocked but we are thinking that second profile is not being used (see config information under)config firewall interface-policyedit 1set uuid xxxxxxxxset logtraffic allset interface "port1"set srcaddr "all"set dstaddr "all"set service "ALL"set ips-sensor-status enableset ips-sensor "xxxxx all_default"set webfilter-profile-status enableset webfilter-
Hello,I have two FG 500E in HA configuration.I just did a sw upgrade on them which seems to have been completed successfully.The previus version was 7.4.2 and the current is 7.4.5 build 2702.Now I cannot access most of websites because I get the error: PR_CONNECT_RESET_ERROR.The network is working and by excluding the fortigate from the path I can regain the access to the websites.Many thanks for any help.
I keep seeing these random errors in the logs from numerous ap's but I have yet to find any good information as to what they mean or if I should worry. Seems like I will see a bunch all at once then everything settles down for a whileLog Description: Physical AP errorLog ID: 0104043613Reason: 80211 WLAN DEL error or 80211 WLAN ADD error They are FAP221-E . Firmware FP221E-v6.0-build0044Forigate 300E: Firmware 6.0.2 build0163
Hello Anyone and Experts, Could you please help me and advise me anything about integration between FortiAuthenticator and RHEL Server integraton for MFA to AD Users?Actually I follow below article for linux integration but it does not working.https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Integrating-Linux-login-with-FortiAuthenticator/ta-p/190276 FortiAuthenticator version: 6.6.2RHEL OS version: 9.4 Thanks,Leo
Does FortiGate support renewal will extend Hardware warranty? Is there any document saying this ?
Hi Team, There are around 300 tunnels are configured between fortigate & Juniper & it was working fine in version 7.4.4 but when we did upgradation to 7.4.6, some of the tunnels went down. We have checked with everything at the Fortigate but no any useful finding. And surprisingly, The same tunnels came up after doing the reconfiguration of tunnels at the juniper side. Kindly suggest here if you face this kind of issue anywhere.
I am deploying Extreme Cloud IQ and Appliance in a few of my restaurants. I need a captive portal to retain client information so custom fields for numbers and email addresses. The solution should integrate seamlessly with our existing infrastructure. Could anyone provide information on suitable options?
Hello everyone, Looking for a solution to this after a week of searching and trying. I wanted to setup a FG 100F v7.0.15 to be a vlan switch. I removed all the ports from the switch except port1 as it will not allow me to remove the last port of course. Problem... after setting up all the vlan switch vlans and adding the ports I want to the vlans, I create the trunk. The trunk will not hand out the IP address from native vlan 1 or 0 on this product. To test my work before adding to the network, I take the PC and tag the NIC with the corresponding VLAN and I get the correct IPs per VLAN. If I remove all tags on the NIC leavin the NIC on 0 (Untagged) I get nothing when I am expecting the native VLAN 1 IP addressing. What gives here?
hi,i'll be creating multiple (a lot) SNAT policy in a multi-VDOM FGT which is an "F" series (1000 plus model)my question, do i enable/allow log "all sessions" or just "security events"?can my current platform (1000 plus F model) can handle such log?i just want to prevent any high CPU/memory due to lots of NAT processing/cache.
Unable to create a span session under a vlan switch in fortios 7.2.8
Buen dÃaEstoy teniendo problemas al sacar un reporte en FortiAnalyzerTengo agregado un equipo FortiAuthenticator, revisando en los logs de event, veo los registros correctamente.En log type selecciono Event (es la única opción que tengo)El problemas esta que cuando ejecuto el query en datasets SELECT * FROM $event. Valido el query y no me manda error pero al ejecutarlo para ver los registros no me manda ninguno a pesar de que tengo registros en Log View -> Event.Hago el mismo proceso en otra ADOM con un Fortigate y aquà si me trae registros. Tendrás alguna solución o recomendación respecto a esto.
Good afternoonI am configured to deploy the operating system through the server, but when I start PXE, the client computer does not see the server, how can I configure it in Fortigate so that the computer sees the server via PXE???
Hi everyone. I've received a Fortigate 60F for my company. My current setup is: ISP - Core Router - Swtich - PC'sI want to use the Fortigate between the Core Router and the Switch: Core Router - Fortigate - Switch - PC'sThe unit will be used for: Antivirus, Antispam, Web Filter, SSL inspection. It will not be used for Routing, NAT, DHCP, VPN.At the beginning I was thinking to use it in Transparent Mode but this mode will disable many features that I need and the fact that I will not be able to use IP's allowing/denying policies but only ports is not what I want. Then I read about the "Virtual Wire Pair" that as I understood acts like the Transparent mode but has more options, will this mode allow to filter IP's too not only ports? Or maybe in the default NAT mode I can achieve want I want by just configuring it properly ? Will need some support configuring Fortigate for my needs as I'm no familiar with FortiOS. Thank you in advance.
Hello We have a customer that is using the FortiClient VPN only client. We need to deploy the client if possible with config of a VPN tunnel. Is this possible and supported? We were able to create such packages before with the help of the "FortiClientConfigurator.exe". Right now we are trying to create a package for the newest version 7.4.2.1737, this uninstalls an old 6.x version before and installs the new version but we have some issues deploying the config. Thank you for your feedback!Samir
2x fortigates2x fortiswitchesmany Forti AP'sForticlient EMS So finally figured out the internet drop outs are when forticlient is installed on the endpointstook it off and put it back on a couple and its 100% the reason. So now I just dont know which part is causing the issue.We only have VPN, Telemety, Update and Web Filter enabled. I have been in and removed Web filter but still the exact same problem Any ideas what this might be please?I cant remove it as it's our VPN connection which everyone uses, Thank you!
Have Forti AP's connected though FortiswitchesGuest WIFI works fineWork WIFI using RADIUS auth on NTP server - very intermittent. One minute its connected - next minutes - no internetthe domain never drops - only the internet connection dropsLots of DNS errors on the logs. DNS-NO-RESPONSE, DNS-NO-DOMAINInternal DNS on our domain controllers set - dont use the forti ones.Just dont understand what's causing the constant drops - then it just randomly reconnects.very unstable.Forti Support just told me to upgrade the AP's and it's made no difference.
Hi everyone, after upgrading my FortiGate 91G from FortiOS 7.0.16 to 7.2.10, the SSL VPN interface (ssl.root) disappeared from Network > Interfaces in the GUI. However:•The SSL VPN works normally and users are able to connect.•From CLI, the ssl.root interface is visible and the status is su:get system interface | grep ssl Output:name: ssl.root ip: 0.0.0.0 0.0.0.0 status: up type: tunnel The SSL VPN configuration seems active and correct. But if I go online the SSL VPN INTERFACE is not visible. You give me feeds
Good afternoonI can’t configure option 67 DHCP in the additional DHCP parametersplease help
Hello everybody: I want to enable two-factor authentication but only for local users who use the forticlient to connect VPN (fortigate 60F).I want to use email, I already have the email-server configured.The option does not appear, so I have to configure the email-server.This is my configuration:show system email-serverconfig system email-serverset server "mail.emailexample.com.ar"set port 26set security smtpsendAccording to the documentation:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Email-Two-Factor-Authentication-on-FortiGate/ta-p/194890There are two steps to complete this configuration:Configure the SMTP server.config system email-serverset reply-to {Sender_email_address}set server {SMTP_server_FQDN/IP}set port {SMTP_server_port_number}set authenticate {enable | disable}set username {username}set password {password_string}set security {none | starttls | smtps}end Create a user(s) with email two-factor enabled.config user localedit {username}set type passwordset
Hello, I want to ask you for advice. I am currently managing a FortiGate device where I am running a VPN setup. Within this VPN, I have a requirement to authenticate users against two separate Azure tenants. Both tenants are configured with FortiGate SSL VPN applications. I have tested the connection, and I observed that when users are in different tenants, the authentication always attempts to validate against a single SAML provider (Users can be authenticated through one tenant, but users from the second tenant are experiencing issues. The system attempts to authenticate them through the first tenant, where they do not have access). I am looking for a solution that allows the system to attempt authentication in the second tenant if the initial SAML authentication fails. I would appreciate any advice.Jan
Hello,we are pushing FortiClient instead of cisco anyconnect, is there a way where I can see ONLY the mobile devices (iOS / Android) connected to the VPN? I can see all users in SSL-VPN widget in the dashboard but I can't filter that to mobile devices only. Please Help!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.