Mark a Best Answer
Fortinet Community
Recently active
Hello,It is my first post here and I'm not experienced to much with Fortinet.What I would like to do is move the server from Site 1 to Site 2 and keep the ip address for the users from Site 1. Sites are connected via ipsec vpn and I try to avoid changing database connection details on all clients.I mean... If I ping 10.0.0.101 from Site 1 then I get reply from 192.168.1.101.Is it possible to achieve it with virtual server function inside these to networks?
Hey, Guys,I don’t know if you can help me with this problem, but I have tried many types of configurations network and of interfaces, therefore, the problem still happening. On Windows I’m abel to Connect and use services of this VPN, but on Ubuntu, after some atualizations of system, when I try to connect the FortiClient shows the “VPN Connect” but the bytes received are iqual 0 and I can’t access the services and VMs. I already try restart network confugurations and reinstall FortiClient, but still not working. Thanks for your attention
Hello all,is there any Documentation or Best-Practice on how to set-up a Wifi SSID with AD-Authentication via Windows NPS Server from scratch? At the moment our company uses MAC Filter based via WPA2-Personal, but i want to change it into Authentication through AD via Radius Server. Best would be WPA3 Enterprise i guess. I set up the NPS Server, applied the Network policy and Connection Request Policies, set up the AD groups, added them into the Network policy, created Radius Client on the Forti (and NPS Server ofc), connection between Forti and Radius is successfull and also my user credentials are working, but when i set up the SSID and add it to my Network Interface, the Client says connection is not possible.I mainly used this technical tip: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-FortiGate-and-Microsoft-NPS-Radius/ta-p/213024and also thishttps://docs.fortinet.com/document/fortiap/7.4.4/fortiwifi-and-fortiap-configuration-guide/961597/configu
Hello, I have strange situation related to my configuration of SSL VPN and LDAP users on my FG100F unit.Currently all people in my agencies using their LDAP accounts to connect VPN and work remotely. Last week one person reported to me that it is possible to change expired password using Forticlient. It is normal because I have configuration which allows to users to change their Windows (LDAP) password. Unfortunately this user changed password for exactly the same as he had before. In my GPO I have password history for last 10 and compliance policy on high level (at least 10 characters etc.)But for now I see that it is possible to change it though Forticlient Does anyone know how to force FortiGate to use AD policy during password change ? BR Konrad
Hello,I recently purchased a few APs and have already set them up and installed them. However, I haven't registered them yet.How can I activate them?Thanks!
Hello, We use the FortiGate device in our customer. We are using version 7.0.17. We cannot access https://sci-hub.se/. We also cannot access if we do not perform a full-ssl inspection. We do not apply any inspection in the rule written at the top of the policies. However, we cannot access the relevant site. Can you offer me solutions in this situation? Best Regards,
Scenario:wan ip: 1.1.1.1 (assuming 1.1.1.1 is public IP)i have 1.1.1.2 as another public ip (same subnet of wan) that is whitelisted on the remote gateway of my client ipsec vpn.how can i use 1.1.1.2 as outgoing ip address going to ipsec tunnel instead of wan ip 1.1.1.1 since on ipsec vpn config you can only select wan interface so far i have tried both no good:- set 1.1.1.2 as secondary ip of wan interface - create ip pool of 1.1.1.2 and use it on policy ipsec > lan, lan > ipsec
Hi, Our FG200 firewall cluster auto updated last night, and now we have several win11 failing with the following error : Credential or ssl vpn configuration is wrong (-7200) Checking "Use external browser as user-agent for saml user authentication" solved the problem. Any ideas why this might have happened and if there's an easy fix? We don't know how many clients are affected yet and it would be much better if we can change something on the firewall side to resolve the problem, instead of having to change settings on all win11 clients.
As the title says, I would like to ask a question.Can fortigate vm free trial manage and authorize fortiAP & fortiswitch?Does fortigate vm free trial provide this function? If it does, the performance will be relatively poor, and the number of managed APs may not be large?
I have two FortiGates configured in HA (FW1 and FW2). After upgrading the firmware to v7.6.2 build 3462 (Feature) and rebooting, I am unable to access the UI via HTTPS on (FW2), although I can access (FW1) after rebooting again.
The firewall is running version 7.2.10.I have a set of rules which has web filters, IPS and DNS filters enabled. The web filter is set to warning for unrated websites. I have set several static URL filters to exempt certain URLs from web filtering, but it is apparently still being blocked by web filtering. How do I ensure the static URL filters work for exempting URLs from web filtering?
When you create or edit an ADOM this setting give you a choice of Select all or Unselect all. What does this setting do? All the documentation I've been able to find just says to choose one, never says what one does compared to the other. My ultimate goal is to have Fortimanage organized so clients with a single FG are all in in ADOM, and any client with multiple FGs have there own ADOM, and in both cases I don't want Fortimanage to push out anything based on any group/ADOM, no policies, nothing. Just a way to manage the FGs independently. Thanks
Hi FGT adminsThere are some config elements we usually check in order to see if our FGT config is compromised, like check if any suspicious admin account, suspicious VPN account, suspicious suspicious rule, ... etc.But is there any complete official procedure or to check it?
Hi, We have a Fortigate which act as router/firewall to protect/split our different networks. It is also used as the Internet Gateway.Our VPN clients are connected through Cisco AnyConnect Platform, getting RFC1918 IP. These IP are NATed (other RFC1918) in output from VPN plateform for mandatory reasons. NATed address are known from Fortigate and VPN client can reach servers hosted by Fortigate by this way. However, VPN clients have to go to Internet too. So their NATed address is reNATed with a public address to go on Internet. VPN client (10.0.0.1) => NATed on 192.168.1.1 by VPN plateform => Fortigate => NAted on public address by Fortigate It works for almost cases except for video/audio on particular visio services... VPN client must have a 10.0.0.X address and MUST be NATed to go to Fortigate Networks. What other solution could be used ? Is this "double NAT" correct ? Maybe some parameters to set for keep audio/video (UDP ?) working ? R
helloI have FortiGate40F and already I have DDNS from x.dyndns.orghow I can configure this DDNS from FortiGate (from GUI only server from fortiddns.com )for example when I write x.dyndns.org with specific port from browser forwarding to server inside my Network Best Regards
I have the below config, and seem to have an issue where the fortigate isn't sharing the direct connected routes, between BGP peers.FortigateInterfacesaggregateinterf: IP 172.19.0.6 255.255.255.248. No Vlan.MGMT: IP 192.168.183.58 255.255.255.192, VLAN 200, Parent: aggregateinterfCCTV: IP 192.168.183.190 255.255.255.192, VLAN 250, Parent: aggregateinterf.SwitchVRF WANVRF LANVRF MGMTVRF CCTVSVI: WAN, IP 172.19.0.2/29, VRF WAN, VLAN 101.SVI: CCTV, IP 192.168.183.130/26, VRF CCTV, VLAN 250SVI MGMT, IP 192.168.183.2/26, VRF MGMT, VLAN 200SVI: LAN1, IP 192.168.168.1/24, VRF LAN, VLAN 300SVI: LAN2, IP 192.168.169.1/24, VRF LAN, VLAN 301 On the switch, I leak the routes between LAN and WAN.I have BGP peering from the switch as below.VRF WAN to aggregateinterf, 172.19.0.6/29VRF MGMT to MGMT vlan, 192.168.183.58/26 Now BGP is established and I can see the fortigate as the default route.The issue I am having is, the fortigate is not advertising each interfaces connected route to the ot
Hi. Can I check if FortiProxy license expire, will the current configured web filter and antivirus profile still function as normal? Will firmware upgrade still be successful? What about explicit proxy settings configured, will it still work?
Dear support, TrendMicro Worry-Free Business Security Services (WFBS-SVC) provides the different URLs that can be used as reference for troubleshooting purposes (e.g. allow listing from firewall or proxy server): https://success.trendmicro.com/en-US/solution/KA-0006176In FortiGate we created a rule, allowing as destination a new address: trendmicro.com (fqdn) but we noticed that it is resolving only to 1 IP. TrendMicro use more than 1 IP. Also we tried using the FortiGate Internet services but without any luck. Can you support me ? Thank You
Need to create IPVPN tunnel from a branch to multiple other branches...All these branches have Fortigate FWs and already have IPVPN tunconfigure as spoke to another Hub.
I did an upgrade on my firewall and now I cannot login. Also did a reset and cannot connect to the default IP. Anyone experienced this ?
Hello, I am running into issues after updating to 7.4.2 to address FG-IR-23-278. Specifically IPSEC tunnel. The SSL works as expected, but not IPSEC. We use DUO for MFA, but it does not even getting to the point just stays at connecting... and then fails. Any thoughts? Thank you in advance!Best, Brandon
I'm currently facing some challenges while trying to configure my FortiGate for a Site-to-Site VPN connection. Despite following the provided documentation, I seem to be encountering message scheduler https://www.gbgenie.com/gb-whatsapp/ Status time limit settings, Contact Toast difficulties in establishing a secure connection. Has anyone else encountered a similar issue or successfully set up a Site-to-Site VPN with FortiGate? Any guidance or insights you can offer would be greatly appreciated.
I have a new implementation of FortiSASE and trying to integrate with EntraID for SSO. We have followed all the steps as documented here including API permissions : https://docs.fortinet.com/document/fortisase/latest/agent-based-vpn-autoconnect-using-entra-id-sso/547823/configuring-entra-id-options-for-agent-based-vpn-autoconnect SSO still doesn't work and every time, I lock the policy Source to EntraID group (My account is a member of this group), and i try to connect to agent based VPN, it gives me the following error. AADSTS50105: Your administrator has configured the application FortiSASE ('677888668-56ff-4675-7561-ddee90078') to block users unless they are specifically granted ('assigned') access to the application. The signed in user 'abcd@ybg.com' is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application. Does anyone knows
So I have a few laptops in our organization that this has happened to now, I originally thought it was the most windows update that did it as both users advised that issue started occurring after a windows update. But after experimenting with one of the laptops I have wiped it multiple times now (as issue kept reappearing) my tests I started installing things one by one and rebooting. I started with our 7.2.5 installer and had no issue, but when I updated to 7.2.7 is when issue resurfaced. I then created a 7.2.7 installer wiped the laptop and first thing I did after joining our domain was install forticlient 7.2.7 and it issue immediately happened. When the issue occurs the login screen flashes every few seconds and resets to the initial screen, it is painstaking to just reboot it into maintenance mode to use the recovery drive. It has happened on 2 different model of laptops (Surface Laptop 6 and Asus Expert Book) I have a bunch of laptops that are just fi
I am trying to setup my iPad and Phone on Fortisase and then connect to the VPN. Registering them on Fortisase has worked and I added the SSL cert. But when I try to connect to the VPN, type in the user and pass (which are correct because that is how I connect on my laptop) it fails. It says Internal Error. I am using the app 7.4.3.0.161 thats available in the App Store. All help appreciated.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.