Mark a Best Answer
Fortinet Community
Recently active
I have a website that has a calendar, i want the users from, for example : UK to be able to see the available days from the UK URL, if someone outside UK accesses the UK url i want to edit the response for the calendar so the calendar appears that no day is available, is this possible in fortiweb? i don't want for it to go to a error page, just edit the response for the calendar to appear empty to mitigate bots and attacks from fully bookin the calendar. i know we can redirect but i want a response rewrite, i'm using a version below 7.6 i heard 7.6 has this function but i can't find official documentation to prove to my customer to upgrade the fortiweb. thank you,
Hi How can i download forticlient vpn offline installer for windows?
Hi EMS adminsStarting from EMS 7.4.1 there are two installation packages. One binary and one OVA.forticlientems_7.4.1.1872.amd64.binFortiClient EMS installer for x86-64 processor.forticlientems_vm.7.4.1.1872.ova.zipVMware vSphere - ESXi HypervisorIs there one method more recommended than the other?Will the two methods be kept for the next releases?
Here is the basic setup, I have two ISPs one copper & one fibreRunning on 101F ver. 7.0.xWith ISP1, i got a public subnet 1.2.3.0/28With ISP2, I got a public subnet 4.3.2.0/28 Configured IPs on two wan interfaces with 1.2.3.2, 4.3.2.22 Static routes were configured with0.0.0.0/0 default gw 1.2.3.1 (first ISP gateway)0.0.0.0/0 default gw 4.3.2.1 (second ISP gateway) Everything works as intended. I also have VIPs mapped using 1.2.3.0/28 subnet and with appropriate firewall policythey show the correct IP (source IP) when I run something like: dig +short myip.opendns.com @resolver1.opendns.com However, when I repeat the same configuration for VIP using 4.3.2.0/28 subnet, the source ip always shows 1.2.3.2( interface IP of first ISP) in other words if VIP was 4.3.2.3 mapped to 10.10.10.10 on inside, it still shows as 1.2.3.2 How can I get the source IP show the VIP that I created.
Hello, Where can we find offline installers for FortiClient, please? I.E. this version and all future versions. Often the process of the FortiClient installer connecting to the server and obtaining the files is the longest part of a job. At least if we had an offline installer, we could anticipate how long the file would take to transfer or do it as a background process, etc. My current install (update) to FortiClient on a remote laptop has taken half an hour to get to 15%. Thanks,Mark
We are trying to set up notifications (via automation stiches) of system configuration backups. The automation stiches appear to support this as they have entries for the relevant log events (32142 and possibly 32145) but for whatever reason, our FortiGates are not recording the backup events in the event log. The log setting for "Event logging" is set to "All." We can find no other place either in the GUI or CLI reference material that would indicate any other setting to enable the expected functionality. Does anyone have any insight into why the backup events are not being recorded in the event log?The models in question are 100F, 80F, 60F and firmware versions 7.6.0, 7.6.1, and 7.2.10.
Hello, please, is it possible to swap licenses (FortiNAC License for 100 concurrent endpoint devices) from a physical appliance to a virtual appliance.
We are currently running FortiClient for antivirus on our endpoints and this works well with FortiNAC Endpoint Compliance. The issue we are running into is testing a new antivirus that is not listed on the Antivirus list within FortiNAC. Is there a work around to use an unlisted Antivirus for Endpoint Compliance within FortiNAC v7.2.5?
Hello everyone, New to fortigate.I stumble upon a problem. So I have a Fortigate 60F. On interface 5 I have the following network: 172.16.20.0/24 and on interface 2 I have the following network: 172.16.30.0/24. I've created the 2 necessary policies for communication between the 2 networks ( I will later only give access to certain PCS). On 172.16.20.0/24 network we have a NAS with a static IP of 172.16.20.5. Everything works fine between the 2 networks. The issues arises when a client on 172.16.30.0/24 network, establishes a Open VPN connection with a remote location. All map drives for the NAS works for a while and then everything stops working. Also as soon as the connection is established, the ping stops responding. As soon as the OVPN is disconnected everything is back to normal. At this point I have to tell you that my Firewall is behind NAT but with DMZ to our Firewall. Any input is much appreciated!
Hello Community, I'm setting up SSL VPN on a FortiGate device for the first time and could use some guidance. What are the critical settings I should pay attention to for ensuring both ease of use for clients and robust security? If you have any setup tips or resource recommendations,Spoiler (Highlight to read)I am not familier with this technology, passionally I am a professional concreter founder of: www.concretesrichmondva.comI am not familier with this technology, passionally I am a professional concreter founder of: www.concretesrichmondva.complease share!
I created a security policy to allow NEWLY CREATED DOMAINS, unfortunately the url meant to be allowed on the Destination has still been blocked by the firewall, what could be the possible cause of this issue and how may i resolve the issue?
Hi, My ISP Gave me xxx.xxx.xxx.xxx public IP and xxx.xxx.xxx.xxx Getway with xxx.xxx.xxx.2, xxx.xxx.xxx.3, DNS. I make Static Configuration For Interface WAN 2 With Public IP and Gateway. But where do I put the DNS
Just ran into this issue and wanted to let you know: If on a policy the security profiles is disabled (which is the Fortnet default if all filters are empty) you are still forced to enter a ssl inspection profile. However if the profiles are disabled and there is only the ssl inspection profile in the policy then FortiOS ignores that even though you are forced to enter one! In this constellation a Deep Inspection or certificate inspection profile will be ignored and no inspection is done at all!If you enable the security profiles in the policy and add at least one more filter profile besides the ssl inspection one then ssl inspection will work as set in that profile.This was reproduceable on several models (FGT100F and FGT100E and FGT300E) here with latest MA release of FOS 7.2. This can create security issues when one has set only ssl inspection on a policy!Also, Fortinet, why are you forcing me to add a ssl inspection profile and then ignore it?! I also opened a TAC Ti
Is there a way either on the device or on the support pages to see the history of Forti OS updates applied to the device?
Hi! Recently we started a little PoC for a new project. On the project we're looking to implement a FortiGate-100E, a FortiSwitch 224E-POE and FortiAPs (we're now testing with the FP231F, but might choose other models). Our goal is to have in every room an AP with 3 outgoing ports. 2 ports are for fixed devices and 1 port is for a BYOD device. In our current config we're looking to use NAC. It's a powerful method and we got it fully working for wireless devices connecting to different SSIDs. The only thing we're running into right now is applying NAC to the LAN port(s) on the FortiAP. By putting the FP231F into WAN-LAN modus and bridiging the LAN port to a hidden SSID configured to a specific VLAN (13), we managed to put wired connections into the LAN2 port on VLAN 13 (without NAC enabled). When enabeling NAC for the SSID, the device goes into the VLAN the AP is one while the NAC policy states it should go into VLAN 13 (in this specific case). It seems like NAC
I see almost exclusively what FortiEDR can do in searching here, and only some minor dislikes on Gartner. I have a case where it did not detect the encryption process, it was able to impede the vector but ultimately the ransomware was successful in encrypting the media. I need cases where FortiEDR could be inhibited, either from improperly training the model, misconfiguration, or other security software that would impede the detection process. Thanks, Karl
Hi, Have a query around ADVPN inter region traffic flow. Lets consider we have two regions and each region has their own Hub to advertise the regional LAN summary routes to its regional spokes. And both the hubs have eBGP neighborship between them to exchange regional summary routesIn this scenario, can understand region 1 spoke can form an advpn tunnel with region2 spokes but there are no mention about whether ADVPN will work between region 1 spoke to region 2 hub?.. There is no clear documentation about this in 7.4/7.6 documentation. RegardsRaja
Hello All, I have a question that I have a VIP with specific IP and running a published service when a client browse the service the VIP appears in computer IP not the client IP who accesses. Is there a way to show the client IP ?
Hi Community, In FortiAnalyzer: is it possible to generate a report that shows me license information from for example FortiGate using a custom dataset? Info like "about to expire licenses" from all FortiGate devices. Also things like you can get from "diagnose autoupdate ver", for example "Last Updated": <snip>Flow-based Virus Definitions---------Version: 93.00577 signedContract Expiry Date: Sun Dec 28 2025Last Updated using scheduled update on Mon Jan 27 17:12:27 2025Last Update Attempt: Mon Jan 27 17:42:10 2025Result: No Updates<snip>
I have generated new SSL certificates for the FortiGate firewall, and trusting the new CA. But it appears that FortiGate is still using the old SSL GUI certificate. I followed this document for regeneration:https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/663527 # execute vpn certificate local generate default-gui-mgmt-cert# execute vpn certificate local generate default-ssl-ca# execute vpn certificate local generate default-ssl-ca-untrusted# execute vpn certificate local generate default-ssl-key-certs # execute vpn certificate local generate default-ssl-serv-keyMy hardware is FortiGate-60F, firmware version 7.2.8 The old certificate is not expired, but I don't trust the old CA anymore. After switching to the new CA, and installing the new CA on my Mac, FortiGate is still presenting the old certificate when I try to log in to admin console via GUI. Inspecting the Certificate page, I only see the new certificates, but SOMEHOW FortiGate is pres
Hi, I had an IPsec tunnel working between HO and Branch Fortigates until I changed the WAN IP Address in HO. The branch office Fortigate is behind a Nat Device with a private IP on its WAN Interface. I even recreated the dial-up Tunnel using the wizard but it is not coming up. How can I troubleshoot to resolve this? Thanks.
Hello Community In a FortiLink split-interface setup, how can i decide, which interface should be prefered? Background100F ClusterInterface x1 and x2 belong to FortiLink Agg Interfacex1 goes to 1024E "Core-Main"x2 goes to FSW1xxF Series Switch "Core-Backup" From 1024E "Core-Main" we go to each access switch (hub & Spoke setup)From 1xx "Core-Backup" we go to access switch-1 then switch-2, switch-3, switch-nBy this, if 1024 should be offline or damaged, we still have each access switch somehow connected to the firewall and can provide services. we do have a massive impact on bandwith within the network, but it works unit one can replace the hardware) Initialy I had the idea to use a hardware switch on the fortigate, but we need block-intra-vlan and other features, that are not supportet on a switch on the FGT A second 1024 is in budget for 2026, since then we have to work with the above setup.So this i why I have to rely on split-interface active, and "need"
G'Day, I've been using FortiSSLVPNclient for years now to facilitate my Remote Desktop Manager controlling my VPN for me via CLI to ensure I'm connected to the correct VPN for the desktop I'm connecting to. The external vendor in charge of the VPNs is switching to use SAML logins for the VPNs though, and while I can configure and test that method in the GUI version of FortiClient successfully, I haven't found a way to use it with FortiSSLVPNclient. Is it possible to trigger a SAML based login via FortiSSLVPNclient?Or if not, is there another tool/exe that can be invoked via CLI that can use SAML to establish a VPN connection? I'm using FortiSSLVPNclient 7.2.1.0779, but it's bafflingly difficult to obtain the tool exes so I'm hoping the problem is that there's a flag I'm missing and not that I need to update/replace it. Also as a less critical but still relevant aside, is it possible to configure the SAML popup window on the VPN side to behave in a password-mana
Hello, I recently installed a second WAN on my FortiGate 40F. I've been facing an issue I'm not able to resolve and looking for some help. I am a beginner though, so I'll try my best to explain my goal clearly and current Goal:- My wan1 has a bunch of static IPs, while wan2 doesn't have any. - I would like to access my file server via a static IP from wan1 from the internet (only wan1 has static IPs)- I would like the application to only upload traffic via wan2 because it is 25x faster.So, it should listen on wan1, but actually use wan2 only for data transmission. Current Setup:- Configured SD-WAN and added both members. WAN2 has a higher priority, and in general it is being used most of the time, which is good for me. - working fine- Created VIP for my server (external 37.37.37.37, internal 192.168.5.111) - working fine My Policies: - SD-WAN to LAN (source all, destination VIP)- LAN to SD-WAN (source all, destination all) F
I have built 5 FortiClient EMS servers on Ubuntu. I cannot log into any of them with the admin user account. I can authenticate in Ubuntu shell with my other admistrative account at the cli, but not into the GUI with that account. I have run the admin user account password reset and I still cannot log in.I am setting this up as a POC and I am using the free version so I cant contact support on this issue. How anyone else experienced this? Thanks!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.