Mark a Best Answer
Fortinet Community
Recently active
Does anyone know if Fortinet is coming with a new G models for Datacenter solutions?
I'm setting up a new FM v7.6.1 trial on Hyper-V and have noticed, frustratingly, that every bit of configuration info I add into FM gets wiped out after every reboot, except the FortiCloud licensing. Three times I have added a 60F, rebuilt the SSIDs/groups/profiles, performed the best practice security hardening, before I figured out what was happening here. I've shut it down both from the Hyper-V GUI and exec shutdown, and when it comes back, the 60F/SSIDs/profiles are all gone. Update: Because I didn't know there were installation instructions, I had downloaded the VM image and secured it before creating additional virtual storage disks. Added the additional storage, and now all the info is retained after a reboot.
The primary firewall was restarted, causing the secondary unit to become the primary. However, it is not syncing with the primary, and both HA cables are active.
Hi, I’m having a lot of trouble getting ourFortiGate firewalls (100Fs / v7.2.10 build1706) to connect to our Microsoft NAS RADIUS server (Windows Server 2022). In NAS there is a tick box that says “Access-Request messages must contain the Message-Authenticator attribute”, my research shows that given version of the Forti software we are running, this should be ticked, however with this ticked Forti reports “Unable to reach RADIUS server” and Windows Event Viewer shows: “An Access-Request message was received from RADIUS client 10.10.100.1 without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.” If I untick it then Forti reports invalid secret (even though it’s been triple checked, reset, and che
I want to configure the proxy of my fortigate and I need to install the “Fortinet_tsagent” to recognize all the users in the Terminal Servers, but in a Windows Server 2003 I get this error when I want to run it:“Service Fortinet SSO Terminal server agent (Fortinet_tsagent) failed to start. Verify that you have sufficient privileges to start system service.” The user I am using has administrator privileges to everything. That is not the problem.Can you help me?
Following from a previous post, which was kindly resolved (External CA for Captive Portal). I am doing further testing and have come across a minor query: How to configure FortiGate Captive Portal... - Fortinet Community This article mentions using DNS, so that it can resolve the FAC address, now, I dont use internal DNS I use google DNS on my Fortigate to resolved external and get out to fortiguard etc, Am I right in assuming, in order to allow the Guest Portal to see Fortiauth, Ill need to set up a local DNS Zone with the internal DNS as forwarders and apply it on the Guest SSID interface? is this the correct way to do it?
The USB modem, which successfully establishes communication on FortiGate 50E and 60E, is not recognized on FortiGate 60F. FortiGate 50E / OS 6.2.15 .... OK FortiGate 60E / OS 7.2.5 .... OK FortiGate 60F / OS 7.2.5 .... NG!On 60F, "Modem failed to open" is repeatedly logged in the system log.Although 60E and 60F have the same OS, only 60F does not recognize the modem. I am confused! #Restored to factory settings and applied only the following configurat#This modem mode switching is not necessary.config system 3g-modem customedit 1 set vendor "SORACOM" set model "SC-QGLC4-C1" set vendor-id 2c7c set product-id 0125 nextendconfig system modem set status enable set auto-dial enable set wireless-port 3 set phone1 "*99#" set username1 "sora" set passwd1 ENC xxxxx set extra-init1 "AT+CGDCONT=1,\"I
Hi, So our fortigate cluster restarted last night. We got the following messages over SNMP :FortiGate: Device has been replaced (new serial number received)FortiGate: System name has changed (new name: xxx-fw1-n1.xxx.net)FortiGate: xxx-fw1 has been restarted (uptime < 10m) This also meant one of our VPN tunnels went down and which generated an alarm. What might have happened here?
Hi All, Does anybody know what does srcserver / dstserver means on logs???? I see that it can be 0 or 1. Mostly I get 0. Documentation is not very clear "Source Server (srcserver) Server of the source. srcserver=0" What does it mean that the server of the source equals 0????
Hello everybody,I am trying to exploit the *.rpm version of fortinet client VPN on OpenSuse Leap 15.2 to connect to a VPN with SSO authentication. While all the SS= steps are completed successfully the client remains forever in the "connecting" status with no error or useful information available in the logs. Is there anyone who has been able to exploit the client on OpenSuse Leap? any suggestion on how to overcome this issue? Thank youDario
Hello, Being new to the Fortinet ecosystem, I am not yet familiar with all the details of the FortiManager solution. However, I have installed the FortiManager VM with a trial license to perform tests in preparation for future use with a full license.I have two FortiGate 30G devices running the latest available firmware version for these models: 7.2.8.They are properly "synchronized" with my FortiManager, but when I make a Policy modification and push the changes using "Re-install Policy," an error occurs.In the "Preview" before the push, I can clearly see the test modification I made and only that modification. However, later in the "View Installation Log" file, new commands are added, which causes the error. The Policy does get successfully pushed, but this creates a configuration "conflict" with each push due to the additional commands/checks. Starting log (Run on device) Start installing FortiGate-… $ config firewall policy FortiGate-… (policy) $ edit 20 FortiGat
Hi, I am trying to configure LDAP for user authentication against AD. This works fine for users that are directly member of the group that is mentioned in the User Group configuration. The design, however, is that a user is member of a Role and the Role is member of the group. When I have this configured in AD it does not work anymore. When I make the user a direct member of the group again it works. How to get this working? Regards, Wim
Hello, Customer has FortiGate + fortiap deployments at all of their locations (around 22 and growing). We used to use windows NPS for 802.1x, recently we switched to Fortinac (Fortinac-f 7.2.8). Everything works as expected. But the problem is in the FortiGate GUI, wifi-controller -> wifi clients section we used to view user information as Domain/username (COPMPANY/USER1) After the transition, half of the users started appear as Domain/computername FQDN (COMPANY/PCHOSTNAME.COMPANY.LOCAL) Both type clients work fine, but this makes IT support a bit tricky since they are mostly using usernames to check on users. Is there a reason for this to happen? If it was for all users, than I would say ok there is ma parameter to deal with. But having some users with usernames and some users with hostnames is a bit confusing. Regards,
Hi, guys, I am using Fortigate 400E, 600E with FortiOS v6.4.2 and V6.4.4. For some reasons, my company perfers GRE tunnel. It is found that the poor performance SLA of the GRE tunnel between two fortigates ( often some percentage of packet loss often found, while the internet lines are running well - no packet loss ), any advice, thx a lot ? Any article/doc to fine tune the GRE tunnel parameters/attributes ?
Hello, i read and applied the documentation but the issue is that i cant obtain the permanent VM trial license from FortiCare. I cant conatin the "account-id xxxx@fortinet.com" "ccount-password xxxxxxx" Trying from the cli: "execute vm-license-options account-id xxxx@fortinet.com execute vm-license-options account-password xxxxxxxexecute vm-license."
Hello, I'm configuring ldap server on a fortigate v 7.6.x.The ldap server is behind IPSec VPN. The clients on the LAN already contact the server in question as they have made domain joins and use that ip as the DNS of their network card.When I go to configure the ldap bind to ‘ip_LDAPServer’ on port 389 this fails. Do you have any suggestions? Thanks fort the supportBR
Hi, Is it possible to create a usage quota (either time og amount of data) for a policy.If you, please advice me how to do this in the gui.I am using a Fortigate 81E-POE with firmware 7.2.2 Thanks. /Kim
FG-Version: 7.2.10 Hi Community, I’m looking for help on how to disable logging for specific policy rules in Fortigate devices that are part of a security fabric. I’ve tried changing the rules, but it hasn't worked. Has anyone figured this out? Any advice would be really appreciated! Thanks!
Hello everyone, While upgrading FortiClients on Debian-based machines, I encountered a problem that I would like to share with you here to find possible solutions or workarounds.In the official Fortinet documentation for FortiClient version 7.4 for Linux-based systems (https://docs.fortinet.com/document/forticlient/7.4.2/linux-release-notes/213138/install-forticlient-linux-from-repo-fortinet-com), the following command is given to add the GPG key for installation on Debian-based systems:wget -O - https://repo.fortinet.com/repo/forticlient/7.4/debian/DEB-GPG-KEY | gpg --dearmor | sudo tee /usr/share/keyrings/repo.fortinet.com.gpgWhen execute the following error is shown:Connection established to repo.fortinet.com (repo.fortinet.com)|208.91.114.61|:443 ... connected.HTTP request sent, waiting for response ... 404 Not Found On Fortinet's official download page for version 7.4 (https://www.fortinet.com/support/product-downloads/linux ), Debian-based distributions are not sho
Greetings, we're currently trying to build our new IPsec VPN Config coming from SSL-VPN.While reading the XML Reference Guide for configuring IPsec i stumbled upon an Inconsistency on "implied_SPDO" The "<implied_SPDO>" and the "<implied_SPDO_timeout>" literally contradict each other.For example on: https://docs.fortinet.com/document/forticlient/7.4.2/xml-reference-guide/96295 (however its the same on all Versions that i looked at) implied_SPDO states that Internettraffic is allowed when its set to 1.implied_SPDO_timeout however states that "FortiClient blocks all outbound non-IKE packets when <implied_SPDO> is set to 1" and "Thus, setting <implied_SPDO> to 1 may have the side effect of blocking access to the captive portal, which in turn blocks access to the IPsec VPN server" Which makes no sense, according to various KB Articles here this looks like that non-IKE packets are allowed whe
Hi, in case any banking customer located in particular country and while initializing Fortisase portal we select same country pop only. Can we select additional pop location later on as per the requirement ?Also what to do if there is no logging pop location within the country. As customer belongs to banking sector will not allow to select logging to another country's pop.Pleas guide..
Hello, I have some old Fortigate equipment that need the latest version of the firmware, and I just noticed that Fortinet does not provide it until I have a support contract. Is this true? and I need to purchase the contract to download it for my old equipment?
Refer to the list:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-FortiOS/ta-p/227178 May I ask why there is still no FortiGate model recommended to use FortiOS 7.2 and 7.4? FortiOS 7.0 is nearing its End of Engineering Support (EOES) (less than 5 months from now), and for some latest vulnerabilities the 7.0 patch this time (7.0.13) was released slower than the 7.2 patch (7.2.6). We usually upgrade version branch before EOES of our currently-in-use branch. But this "recommended list" is giving us concerns.
Hi,This morning i get complained from my users they cannot connect the VPN client. This weekend The FW installed automatically (never turned on auto install) the latest 7.4.X firmware which is 7.4.7.My FW configured with Entra enterprise app to use the 2fa.The users got stuck at Forticlient 48% with error stating there is an error in password or permissions -7200.Reverting back to the 7.4.6 fixed the issue for now https://100001.onl/ .Also oddly enough the connection was "connected at the FW , but disconnected at the Forticlient. There was an error under username in the FW: Two-Factor Authentication is not enabled.Anyone else see this?
Hello guys, I have a cluster configured to ask users authentication using Entra ID account. This is working when using host connected to an interface that is directly managed by Fortinet (and it creates the local in policy for port 1003), but I need to make it works also from a routed subnet that is passing thru a transit interface (it’s an MPLS line), but the redirect doesn’t work for this interface. I've created the zone and relative rules, but nothing to do. any suggestion? thanks in advance!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.