Mark a Best Answer
Fortinet Community
Recently active
Hi All, Is anyone aware if it's possible to enable the mac-move feature on fortinet managed switches. Fortinet Firewall firmware is on 7.4.6. Thanks
Hello, Given the upcoming deactivation of SSL VPN in the next version of Fortinet, I would like to switch to IPSEC for user connections. However, I have seen on several forums that IPSEC does not work with the "FortiClient VPN" client but does work with the "Full Client." Indeed, the connection does not establish on FortiClient VPN.Is there any way to make it work on this client? If so, how? And if not, are special licenses required for the Full Client?
Hi Expert, I need your support as I have configred Ipsec over SDWAN configuration between HQ to branch office.phase 1 & phase 2 tunnels are showing up but performance SLA is showing down. I have put so many effort but no luck succeded. that's the reason I came here for help. Until perfomance SLA comes up I will not able to set traffic from HQ to Branch. Head_Office_Firewall #Head_Office_Firewall # get router info routing-table details 192.168.2.0Routing table for VRF=0Routing entry for 192.168.2.0/24Known via "static", distance 220, metric 0, best* directly connected, NullRouting entry for 192.168.2.0/24Known via "static", distance 1, metric 0via H2B1_VPN1 tunnel 10.10.30.2 inactivevia H2B1_VPN2 tunnel 10.10.40.2 inactiveHead_Office_Firewall #Head_Office_Firewall (members) # showconfig membersedit 1set interface "port1"set gateway 10.10.10.1nextedit 2set interface "port2"set gateway 10.10.20.1nextedit 3set interface "H2B1_VPN1"set zone "VPN_ZONE"set source 192.168.1
Hello,I have two accounts tied to this email: one I made for posting on the forum, and one partener made by the company later on. If I register a Fortigate to this email account, can I select then "where will it go"? It needs to be seen by the others.
Hello Everyone. Home user here, been thinking about replacing my old linksys router with a fortigate firewall. Nothing crazy, probably just the 40F. Was looking at the support options, can anyone tell me if you're able to download firmware updates for your firewall with out having to pay for a yearly support contract?Thanks!
Hi all, I encounter an issue when trying to register to EMS from my local FortiClient. The version I have now is 7.0.2 for FortiOS. I am trying to troubleshoot this however am clueless where to start for the debugging....
Hello, I have a question, I have a Fortigate 100F, but I don't know if this fortigate support the CGNAT, and if the fortigate suppor it , i don't know what is the configuration I need to apply. Can anyone help me with this question? Regards.
Hello! We just upgraded our FGT80F firewalls from 7.4.3 to 7.4.7 and LDAP no longer works on the secondary units, it only works on the primary units when trying to log on. We have to use the emergency local account if we want to log in the secondary unit. We have two active passive clusters, and we have the same issue on both clusters, the secondary can only be accessed with the local account. My teammate found this article, maybe we are hitting this : https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-local-out-traffic-blocked-by-HA-debug-flow/ta-p/198747 But in all cases, I think we should be able to log in using LDAP in the secondary if we need to. Any ideas to troubleshoot this? At first sight, we get "local-out traffic, blocked by HA" when trying to do Packet Trace. Hoping everything is clear, if there's anything, please ask! Thanks!Konnan
HiI have setup webfilter to block some categories but when a user wants to visit a website which is not in those categories , the browser shows this site is blocked because it is in local blocklist which is empty.
Hello,We are experiencing the following issue in our company: we have a FortiGate 60F with a GRE over IPsec tunnel configured between a Cisco router and the FortiGate firewall.When we checked PRTG, we noticed that the tunnel went down on February 27. Upon investigation, we found that both phases are configured identically, and the configurations are the same on both ends. However, the Interconnect does not establish a connection, and ping does not work.Could you please help us understand what might be causing this issue? Ping is enabled on the interface, and everything was working correctly before. We have not made any changes on the FortiGate, and as I was informed, there were no changes on the Cisco router either.Additionally, we switched the tunnel from Tunnel Mode to Transport Mode, but the issue persists.I would appreciate any recommendations or troubleshooting steps. Thank you very much for your feedback!FortiGate #VPN #Ipsec
Hi We have a 200F FortiGate with 7.6.1 firmware. I have set up ssl inspection, web filter, ips and antivirus about 2 years ago and all of them were working fine till last week. I noticed that there is no fortinet issuer in any website I open and because of that all websites are permitted and no application blocking is occurred. I have used Fortinet_CA_SSL certificate (default) via group policy for users and that was working. please help me to solve this issue
We are experiencing the following issue with our FortiGate 30E. We have a network with the address 10.48.5.1/24, which is configured on the firewall interface. Unfortunately, after adding SNMP, the sensors are not working properly. For example, the ping works without interruptions, but other sensors, such as traffic on different interfaces or memory and CPU usage, sometimes lose connection and sometimes do not.A similar issue does not occur with a Cisco switch that is added to PRTG with the IP address 10.48.5.22—it provides all information instantly without problems.Could you advise what might be causing this issue? How can I resolve it? The monitoring system often encounters problems, with some sensors turning off and on randomly, leading to a large number of alerts.The PRTG machine has access via a VPN tunnel, and the VPN tunnel itself is working properly.FortiGate #SNMP #Monitoring #Configuration #30E
Hello, in order to plan the size of a new firewall, I would like to know the long-term throughput of my current firewall (in this case a 300E, 7.2.x). I know there is the command "get system performance status" which shows the current and average throuput, but this is limited to the last 30 minutes. Also the interface bandwidth widgets on the dashboard do not help, because it is a device with multiple VDOMs and multiple connected interfaces. Therefore I would have to accumulate many different values. My question is therefore, if there is any option, to monitor the long-term throughput on the device? This can also happen by SNMP. FortiAnalyzer and FortiManager are also available. The important information would be an average and the maximum total throughput, at least over one month. Thank you in advance - Regards
So I have the below setup.FortigateInterfacesaggregateinterf: IP 172.19.0.6 255.255.255.248. No Vlan.MGMT: IP 192.168.183.58 255.255.255.192, VLAN 200, Parent: aggregateinterfCCTV: IP 192.168.183.190 255.255.255.192, VLAN 250, Parent: aggregateinterf.SwitchVRF WANVRF LANVRF MGMTVRF CCTVSVI: WAN, IP 172.19.0.2/29, VRF WAN, VLAN 101.SVI: CCTV, IP 192.168.183.130/26, VRF CCTV, VLAN 250SVI MGMT, IP 192.168.183.2/26, VRF MGMT, VLAN 200SVI: LAN1, IP 192.168.168.1/24, VRF LAN, VLAN 300SVI: LAN2, IP 192.168.169.1/24, VRF LAN, VLAN 301 On the switch, I leak the routes between LAN and WAN.I have BGP peering from the switch as below.VRF WAN to aggregateinterf, 172.19.0.6/29VRF MGMT to MGMT vlan, 192.168.183.58/26 Now BGP is established and I can see the fortigate as the default route.The issue I am having is, the fortigate is not advertising each interfaces connected route to the other VRFs on the switch.in the outgoing routes, I would expect the belowneighour on aggregateinterf0.0.0.0/
Hello Team, I'm wokring on new product development and i'm pretty new to Fortinet SD WAN. At the moment i'm trying to understand the complete list of Fortimanager monitoring API's which needs to be queried in order to get the events related to SD WAN service. Can you please guide me/ share the complete monitoring API guide related to Fortimanager. Thanks & Regards,Prabhu
Hi All, I've built a lab with SD-WAN ADVPN set up over an MPLS network, with an Internet VRF and a Private VRF, all looks to be working fine, except for BGP multipath routing. I have a Server IP, learning the IP through BGP over both Hubs not a problem, with the preferred path entering the routing table, however, I thought with multipath routing it would install both routes in the routing table?As a result, my SLA to the server in SD-WAN is showing as down over 1 of the Hubs, so it can't flip over if packet lass or high latency occurs etc Any ideas please? Thanks in eager anticipation (topology, routing table and SLA attached if it helps)
Hello, we are changing in small offices from FG30E to FG40F and some 30G which we would like to try. First, I cant download newer FortiOS versions from the support portal, it seems that the 30G only has the 7.2.X version, cant be true, no? Also in the Web Gui I cant activate a AV profile. I can add a new one but than I cant choose it in the policy. Any experience and feebdack from this modell? Thanks!
HelloI am using a fortogate 100F device which I think has no license on it!!!Since Im not expert with fortigate devices i wanted to know if this images shows what i think ? I think there is no license installed on the device, either online or offline!!!I would appreciate any response  :folded_hands:
After updating Fortimanager to version 7.2.4, there is no synchronization in the Policy and Objects - User and Authentication - User Group - Firewall section. We create new users and groups on the domain controller, but they are not listed on Fortimanager. But all Fortigate devices synchronize and create new infrastructure objects.This is a problem with two domain controllers. One is connected via LDAPS, the second via LDAP. Maybe someone has encountered such a problem and knows how to solve it?or is this another bug=(
Hello Expert, I have fortigate 80F running version 6.4.I create a firewall policy and would like to to Clone Reverse the Policy.When I right click on the policy I not see the option to clone reverse. Is there some feature that has to be turn on before the option becomes visible.I humbly request some guidance . Thank youRegard Jomo
hi,i'm trying to configure a new FW policy and just wanted to know the difference between ICMP and Ping service.1.which is best practice to use/choose?2.if i need to clone/edit a custom ping or icmp service, i.e. echo reply, which service do i use/edit (icmp vs ping)?3.what is also the difference between the "traceroute" service vs the custom ping "time exceeded" (type:11,code:0).
hi,i'd like rename an existing VDOM but can't seem to do this either on the local FGT device or FMG.can this be done via CLI? if there is, what is the command?is there a feature visibility that i should enable for me to edit the VDOM name?
I have a Web Filter security profile already in place. Along with AV, DNS, APP, SSL filters as well. I am trying to add a site to URL filter for it to be blocked. I got this to work at one point by selecting Wildcard, Block, Enable. I had it written as *.website.com and it seemed to work hit or miss (seems like if you cleared your cache and retried it would give you the blocked splash page when trying to access the site). I am trying to block a website now and it will not block no mater what I do. Same for the old site that originally DID get blocked. I have the security profiles all set up as they should be and they haven't been touched. Why is this not working? 60F version 7.2.9
Hello. I would like to configure wan1 as the SD-WAN members on the case of new device.But, it is not appeared wan1 on interface for creating new SD-WAN member.It is appeared wan2 and dmz interfaces.How can I create SD-WAN members with wan1? Regards.
hi, I have two subnets :wifi 10.8.8.0/24internal 172.22.2.0/24 ( NAS,Printer) I have created policies to route from wifi->internal and internal ->wifi, I am able to ping the NAS and Printer from the wifi network but am unable to access the actual devices. in the policies in the source and destination i used the actual subnets and not the usual "all" for the policies, is this correct? I had also tried with all but didn't seem to work either so the issue must be something else... I am able to access the fortigate admin on the internal from the wifi subnet but that seems to be about all i am able to do.. any idea how to get the visibility of the devices? ciao,Antonio
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.