Mark a Best Answer
Fortinet Community
Recently active
For the following error:facauth: ERROR: The AP of portal policy X does not contain client guestwifi.auth.local It is suggested to add "guestwifi.auth.local" to the Access Point configuration on the FAC, this however is still not working, The Fortigate has a cert configured (Testing Purposes) with a SAN of this name, I am using a Multi SAN certificate so its being used in the FAC and the Gate, I have also applied on the gate: config firewall auth-portalset portal-addr "guestwifi.auth.local" as per the instructions. The guest can register, get approved, gets added to the group and email sent to them with login, but then fails with the error described up, Am losing all faith in this solution, any help appreciated.
Is there a way to check a list of domains to see which Fortinet web filter category they are in and have this displayed without checking each domain individually https://speedtest.vet/ ?The background is the change from a squid proxy with a very long block list to a fortiproxy.I wouldn't like to take over all the domains and put them in a new category of their own, as most of them will probably be intercepted via the web filters.
Hi,I'm working on new Fnac 7.6 deployment.I need only visibility functions, in particular I need to associate user/host/ip address and see all in fortiview.It is necessary the persistent agent or I can retrieve the information in another manner ?Also I don't understand why in fortiview dashboard I can't see the ip address, only mac-address, but in adapter window I see the ip address resolved by mac-address.In inventory I set L2 polling and L3 polling on core switch.Thank you Vincenzzo
Hi.I have FortiMail 200F (v7.4.3)Fortimail is in Gateway Mode.I want to configure Fortimail so that incoming mail is scanned and forwarded to the mail client (MS Outlook / Thunderbird).How to configure Fortimail so that SPF, DKIM, DMARC is verified by mail provider, then incoming mail is checked for antivirus and phishing by FortiMail, and finally it is forwarded to mail client (MS Outlook, Thunderbird).Where to enter the MX record from the mail provider in Fortimail?Do I need to enter any records in the DNS configuration at the mail provider? If necessary, which ones?I am counting on your helpGreetings.
I am a new systems admin for my company and am tasked with the project of splitting a sister company from our network. The sister company has a fortigate directed to our network and need to make adjustments to take it off our network and allow it to work independently/ for their own network. Is there a previous post on the subject or can someone point me in the right direction for the steps involved in taking that fortigate off our network? Thank you.
Could you advise if there are any methods to diagnose the quality of an IPsec VPN? I've noticed that the speed between my two site-to-site IPsec connections is quite slow. However, when I switch to OpenVPN, the speed returns to normal Could there be any settings that might be affecting this? Thanks.
Good Day, I currently have an SDWAN that comprises of 6 different interfaces, I am trying to remove one of those interfaces for a different use, but I am unable to delete the interface from the SDWAN group. Would appreciate any help. Regards
when FGT is collecting tx/rx traffic for specific interface to draw graph, what is options used in this graph ? [i mean inside FG itself , collected logs not yet exported to FMG / or FAZ ]what is sampling rate for traffic , is it based on time , packets , etc ? [please provide reference]--then when its sent to FMG i see on fresh logs it can show up to 5 minutes distance , then if we explored old graph , distance is compressed to about 30 minutes [please provide reference]FortiGate FortiManager
I have a situation where I have 4 unique subnets.192.168.0.0/24192.168.1.0/24192.168.2.0/24192.168.3.0/24 Currently, there are no Vlans defined on the switch, so they are all in VLAN 1. A Cisco router is currently serving as a Gateway for this site and has the followinginterface GigabitEthernet0/0/0 ip address 192.168.0.1 255.255.255.0 ip address 192.168.1.1 255.255.255.0 secondary ip address 192.168.2.1 255.255.255.0 secondary ip address 192.168.3.1 255.255.255.0 secondary I would like to slip in a Fortigate Firewall to serve as the gateway device, but i need a way to service all of the subnets that are all residing in Vlan1 over a single ethernet cable. I have tried to give the port a parent IP address, similar to Cisco, with secondary ip addresses...but i cant ping from the network to the respective secondary ip address and vice-versa. The parent ip address works fine. any ideas? I have tried configuring the C
Hi, We want to use the "script feature" located in "login > configuration > scripts" to upload and run objects/rules instructions. When all goes well, script is "success", but when one command fails, part of hundred of lines, GUI returns only "script failure" without any log. Where could we find what has failed in the whole script ? Does this feature have any log ? Regards,
Hi,i created a wifi SSID just for test purposes because i wanted to create a proxy based policy with deep ssl inspection and DLP. The DLP is working only in part because I'm currently unable to get it to log let alone block outgoing e-mail files ( would I need E-mail filter for this to work?) containing the keyword, HTTPS post works fine! But the real issue with this Proxy based policy is that it's not allowing microsoft or apple services to pass.anyone has any idea how to solve this problem? ciao,Antonio
My 40f failed today after the system reset, the system did not reboot, the power light kept on, but the status and other lights did not come on either, what should I do? Can someone help me?
Hi! I'm looking to implement an automation in my FortiGate E100 in case on a specific port on my FortiSwitch 224E-POE a new MAC Address is detected. The only problem I'm facing is, how to detect this properly? I did some digging online and found out about sticky MAC addresses. I've enabled this for one specific port where always 1 specific device is connected to. I've setup the sticky MAC to persistently remember 1 address. I managed to get a FortiSwitch notification about the detection of a new device (other than known in the remembered sticky MAC address) in the FortiSwitch Systems logs, but I cannot manage to get a notificaiton about it. In the FortSwitch System Logs I did notice a new enterance, that looks like this:Interface MAC learning limit exceeded, MAC 84:XX:59:XX:e9:XX on port11 (Packet VID: 1). - FortiSwitch system So to just try out I made a Trigger in the Security Fabric Automations for notifications from the FortiSwitch system, lik
Hello,I am currently setting up an IPSec VPN tunnel on our FortiGate firewall, authenticated via Entra ID (formerly Azure AD), and I am encountering issues restricting access to specific VLANs based on Entra ID user groups.Objective:We have successfully configured an IPSec VPN tunnel that allows users to connect and access our internal network (192.168.0.0/16) and VLAN 10 (10.10.0.0/16). However, we want to achieve the following:Existing Setup (Working):All authenticated users can access the internal network and VLAN 10 without issues.New Requirement (Issue):Users from a specific Entra ID group should only have access to VLAN 20 (10.20.0.0/16), and should not be able to access other subnets.Steps Taken:IPSec Tunnel Configuration:Configured an IPSec VPN tunnel with Entra ID authentication (SAML).Successfully tested the tunnel connection and access to the internal network.Added Entra ID groups under User Groups (VPN - Access Vlan 20).Assigned the correct SAML entity and certificates.Addr
Hi, running Forti Manager 7.0.13. When evaluating an upgrade to 7.2.9, i ran several integrity checks. One of the adom checks resulted in feedback : 21 changes(s) will be made. Is there a way to find out what these changes are?
Hi.Has anyone ever been able to deploy FortiEDR Collector to MACOS with Intune?There are literally no info out there on the subject, how does everybody do this.I can't imagine everyone manually installs FortiEDR on MACs.
Dear all,I am working on a EST server that should interact with Fortigate as the EST client. The standard workflow works fine for both, Simple Enrollment and Simple Re-enrollment.Those request can return a 202 - pending status, where, according to the RFC, Fortigate behaves as expected: "The client MUST wait at least the specified "retry-after" time before repeating the same request". My question: in my EST server, I need to identify the retries for a same request. I would thus like to handle a transactionID to be shared between my EST server and Fortigate. But handling of a transactionID is not part of the EST RFC. It can be customized in my implementation of the EST Server, but my question is: does Fortigate handle a transactionID when it receives a 202, and if yes how does it do it ?To go a little further: I would like to differentiate each renew operation with a new transaction ID. That is, the 'retries' have the same transaction ID, but the next renew of the certificate,
Hi,I'm trying to register Fortigate VM for permanent free trial, but unable to do so because of unsupported serial error.I downloaded FGT_VM64_HV-v7.6.1.F-build3457-FORTINET.out.hyperv.zip zip from Fortinet support site. Created VM with 1 CPU, 2048 RAM and with 2 nic. I first I tried to register from command line without success: # get system status Version: FortiGate-VM64-HV v7.6.1,build3457,241127 (GA.F) First GA patch build date: 240724 Security Level: High Firmware Signature: certified Virus-DB: 1.00000(2018-04-09 18:07) Extended DB: 1.00000(2018-04-09 18:07) Extreme DB: 1.00000(2018-04-09 18:07) AV AI/ML Model: 0.00000(2001-01-01 00:00) IPS-DB: 6.00741(2015-12-01 02:30) IPS-ETDB: 6.00741(2015-12-01 02:30) APP-DB: 6.00741(2015-12-01 02:30) Proxy-IPS-DB: 6.00741(2015-12-01 02:30) Proxy-IPS-ETDB: 6.00741(2015-12-01 02:30) Proxy-APP-DB: 6.00741(2015-12-01 02:30) FMWP-DB: 0.00000(2001-01-01 00:00) IPS Malicious URL Database: 1.00001(2015-01-01 01:01) IoT-Detect: 0.00000(
Need fortigate firewall MTBF, where can i find, I have partner portal access, can someone point to specific document/link for these details. I would need the below for a customer.FG-121GFG-201GFGR-70F
Dears, Currently i am running a hyper-v host with 2 network interfaces. Each one has been assigned to one vSwitch, one is on the internet directly and the other is attached to FTGT 71G (transparent mode). When I change the vSwitch of the VM to look at the FTGT it says identified network. If I create a new network adapter to the VM and connect it initially to the vSwitch that is connected to FTGT it works as expected. Have you encountered this type of issue?
Hi,I want to create FortiSandbox windows11 VM custom image but when I give 30gb disk space, windows 11 takes 25gb by itself. There is no space left for components such as office, adobe chrome firefox. I need to leave 5gb more space. What should I do about this? Can anyone who has information help me? Regards
Hello Team, Question about FortiProxyWhen using the browser the login banner comes out correctly and so far so good. But when desktop applications are used (such as arubasign or acrobat reader for digital signature verification rather than other applications) they do not work. How do I handle these exceptions? Is there an agile way to do this?How do you configure fortiproxy to make it handle desktop applications? Thanks
for example a FortiClient profile and a windows profile on the same WAN IP.
Hello, i am using FortiEMS 7.4.2 with a FortiClient.They are both connected but my Client doesnt get any AV signature updates as it still shows its at version 1.0I already switched to FortiGuard Anycast as the server type in the EMS settings but it didnt help.How do i get a newer version of the AV signature and can i even get a newer version?
Hi,I am quite new to Fortinet - I am used to Cisco. I have a Fortigate 40F and a Fortiswitch 124F-PoE. I have them linked by Fortilink and I can see the switch in my Fortigate.I want clients connected to Fortiswitch to get their DHCP from the Fortigate. I cannot see how to do this. I set up a vlan on the Fortigate (Fortiswitch Vlan) and told it the DHCP relay was on an interface on the Fortigate - I have created a hardware switch and made LAN2 a member - I have a DHCP server on that hardware switch. When I plug a device in to a port on the Fortiswitch (port 1) which is in the Fortiswitch vlan I created it does not get an IP address. I am not sure whether I am doing this right. Any advice on this is most appreciated. A simple task I would have thought that I can do in a few minutes on Cisco but this is not at all the same.Thanks in advance.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.