Mark a Best Answer
Fortinet Community
Recently active
Hi everyone, I am encountering an issue with FortiAnalyzer while generating my report. Many IP addresses are displayed without their corresponding hostnames. I attempted to use Subnets, but it did not work as expected. My task:that every IP in report will has "descriptions" (They will be signed) Does anyone know how I can achieve this? Any guidance would be greatly appreciated.Thank you!
Hi, I read that the NP6XLite processor ensures hardware acceleration of network traffic, which enables the processing of large volumes of data without heavy CPU load. This acceleration mainly applies to basic functions such as routing, NAT, IPsec, and firewall, and advanced functions such as UTM (for example, antivirus, web filter, DLP or IPS) usually require the intervention of the main CPU, since the hardware acceleration on the NP6XLite is not optimized for these more complex processes. When hardware acceleration is enabled and UTM rules are applied, there may be situations where some traffic is not redirected back to the CPU and UTM rules may not be applied correctly.But is it correct? I thought that NP6XLite is used for UTM functions such as IPS, web filter, etc.
I have a site-to-site VPN setup between two Fortigate fws. This VPN has been setup for years and have had no issues. Yesterday, I lost the ability to communicate to either LAN between the VPN. The tunnel shows as up on both sides and I've tried rebooting, resetting the connection, and still nothing. Before yesterday I could communicate successfully between both sites but now nothing. It is also an IPsec VPN. Any ideas? I also have other VPNs on each firewall (none other are Site to Sites) and they each work. Version 5.6 on one side and 7.4.3 on the other.
Hi all, As you can see using % 45:45:10 here. And now one "45" is offline. So, what is the correct current %:% for the remaining TWO interfaces? Thanks,
Is it possible to configure Fortigate to use Fortiauthenticator with MFA and AD authentication, with NTLM v1 disabled on DC's ?With ntlm v1 enabled everything works fine, but with v1 disabled, authentication fails with error :Windows AD user authentication(mschap) with no token failed: AD auth error: Logon failure (0xc000006d)Login to fortiauthenticator works fine, with AD account, but when trying to login using vpn client, it fails.
Hello In a multi regional setup where site-to-site ipsec tunnels between hubs are establish ed, I am trying to use embedded sla information between them to signal best ipsec tunnels. Like one being spoke from the other. The issue is that hub with "detect mode remote" doesn't see any sla information in the " diag sys sdwan health-check remote" although it is received from spokes. Configuration is the same, the only difference could be the type of tunnel? Any help appreciated Best regardd
FAP-441K APs have two 10/5/2.5/1 Gb RJ45 network interfaces. But, does Fortinet make a PoE switch with a 10 Gb RJ45 port that also supports MCLAG? If they don’t….why put 10Gb in the APs? Best I could find was the FS-648F-FPOE where 16 of the ports are 5Gb RJ45. Thanks
Hello, First post here, and I am new to Fortinet products. I am looking to replace an EOL'd WatchGuard firewall with a FortiGate (e.g., 71F/G). Its a Verizon FIOS residential circuit using their G1100 Quantum router behind their ONT. That means: (1) the G1100 cannot be placed in bridge mode, (2) Verizon does not issue publicly-routable static IPs to residential customers, and (3) the WAN side of my firewall will be getting a local (i.e., non-routable) address from the G1100. The WG operates in this unfortunate double-NAT situation acceptably - it gets its updates and it moves traffic. A couple of other relevant details: (1) elimination of the G1100 isn't acceptable due to a MOCA requirement for three set top boxes, and (2) those set top boxes are on the other side of my firewall (i.e., the current WG firewall is the single point of connection for my network to the G1100 LAN side). Also, I am not currently using a VPN client to connect to my network from the Internet, but would lik
HiI added a personal VPN connection to my FortiClient EMS. It connects to the VPN and everything looks ok. But when i do a route print it hasnt addad any interface, gateway or routes for the VPN. The corprate VPN works fine though.What can the problem be?If I do the exact same with another computer the personal VPN works fine, so it seems that it has something to do with my computer.Both computers have fresh updated Windows 11 on the same network. I have tried different versions of the FortiClient, both non-EMS clients and versions from 7.0.1 to the newest. Turned of the firewall. Nothing helps.It looks like the FortiClient isnt allowed to add the routes for my personal VPN, but only on this one PC?Any help or suggestions are appreciated. /Anders
May I create two different ssl-vpn portals with two different ports? For examples 10443 and 11443.
Hello, Fortigate 600 v7.2.9.Ports 1 and 2 on the Fortigate are not yet in use. I activate both.I plug PC1 into port 1 and PC2 and port 2.Should the two PCs be able to talk to each other now (of course I gave them both an IP address from the same network)? So are they in the same Layer 2 network?Or do you have to tell the Fortigate that ports 1 and 2 should be in the same vLAN, so to speak.I'm not actually talking about ports, but rather aggregates, but the logic should be the same. ThanksAlbMin
Hey everyone,so, I got the impression that many of you on this sub are migrating from SSL VPN to IPSEC VPN for remote access due to recent CVEs and Fortinet giving off the impression of preferring IPSEC VPN as well (removing it from smaller appliances, etc.).Thing is, most of our customers (not necessarily using FortiGates even) migrated to SSL VPN years ago due to specific reasons, for example:- IPSEC RA-VPN not working well in public places/hotels because it is usually blocked there- IPSEC RA-VPN having problems with home office users that are being NATted from native IPv6 to IPv4 which in some cases breaks IPSECSSL VPN being much more robust in those cases. What's your take on this? Just interested to see different viewpoints here
Hi all,it's possible to create an email warning message (on the fortigate or fortianalyzer) when the interface limit has been exceeded over 2 minute? Thank's in advanceMaurizio
Dear community, anybody using Fortigate API to retrieve log traffic with this endpoint : /api/v2/log/disk/traffic/forward/system?filter=srcip==10.227.108.88&rows=10 I can get logs for a specific source or destination IP, but do you know anyway to get logs for a network ( example : 10.0.0.0/8) ? Running version :"version":"v7.2.10","build":1706 Thanks in advance for your help ;) Looking the FortiDev documentation, only available filters are the following, but they didn't make the trick to filter on network after several test : filterarray[string] (query)Filtering multiple key/value pairsOperator | Description== | Case insensitive match with pattern.!= | Does not match with pattern (case insensitive).=@ | Pattern found in object value (case insensitive).!@ | Pattern not found in object value (case insensitive).<= | Value must be less than or equal to pattern.< | Value must be less than pattern..>= | Value must be greater th
Team, I have all the required licensing for FortiSASE (advanced, SPA etc) and have a requirement to provide access to private resources (RDP) for contractors (non-managed devices). Before I go down this route, is this a supported configuration using agentless ZTNA? Or am I better placed to leverage a different solution?TIA.Justin.
Hi this amazing community!I am pretty new in Fortinet world (from basically cisco background). Company advised to see alternate vendor so i am considering Fortinet stack as better fit for us. I know its more like consultation questions but want to hear from you all based on your experience:1. Can we configure front door VRF in ADVPN like in DMVPN? main reason is security (separate internet and local traffic on vrf level). My thought is we probably don't need VRF as its firewall where we can enable security feature on public line but my manager pushing for front door VRF to separate traffic saying security reason. 2. Can we assign Public IP behind the FortiGate (without NAT) device? We will gone have PA for client VPN (for at least 1-2 yrs).3. Can we assign multiple Public IP on a WAN interface? we have 2 block of /29 public from a provider and another /32 just for internet. from that two /29, some service needs direct public IP (like client VPN) and some other services just
Hello Team,We have a cisco switch in our environment and want to configure 802.1X user authentication through Active Directory.Necessary configuration has been done on cisco switch and also on fortinac but the user is not able to authenticate. Switch logs are shared below:Jan 23 11:21:31.767: %AUTHMGR-5-START: Starting 'dot1x' for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %DOT1X-5-FAIL: Authentication failed for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client
Hello, I am looking for older version of FortiClient VPN version 7.0.8.0427. Can someone please help me with the information about where I can get the software.Thanks,VRG
Hi I am in the process of upgrading our devices to v.7.2.x. I have already upgrade FortiManager and FortiAnalyzer to v.7.2.9 with no issues. I have now upgraded one of our FortiGate HA clusters to v.7.2.10. When I go to install policy, this fails. It appears to be trying to reconfigure a wireless-controller vap. The response I get is:---------------------------------------------------------------------------------------------------------$ unset voice-enterprise$ unset dynamic-vlan$ unset mpsk-profile$ nextCurrent passphrase is invalid. Must be 8 to 63 characters long or 64 hex digits.object set operator error, -651 discard the settingCommand fail. Return code 1---------------------------------------------------------------------------------------------------------I'm not sure why it is trying to reconfigure this vap. It has the same settings as other vaps. The settings in FortiManager appear to be the same as configured on the FortiGate itself, so I'm confused as to why it is tryi
I need help please: I have fortigate 601e firmware v6.2.3 my problem is the traffic that comes from the FortiGate is going outside the GOOGLE DNS, use the dot interface IP address point -to-point for more security I want to use the Nat service for this type of traffic. I can't find how. can someone help me please?
Dear allWe are trying to optimize our SD-WAN solution for Office 365 traffic steering.We are in China. We'd like to route all Optimize category of Office 365 traffic from this article to use our local internet egress while route other Office 365 traffic to our offshore site utilizing their egress in West Europe. So, the question is, which following ISDB object is referring to all other Office 365 traffic from Fortigate object list? is it Microsoft-Office365, Microsoft-Office365.Published, or even Microsoft-Office365.Published.Allow? Basically, we just want to find an object covering all of the O365 traffic so it can address all traffic after the Optimize.
Hi!I seek clarification on the feature Protecting an SSL server (aka. firewall ssl-ssh-profile's server-cert-mode is "replace").Is it mandatory that the specified "Server certificate" (in SSL/SSH Inspection Profile) be identical to the actual server certificate - yes or no?Thanks! PS. Plausible example where I'd prefer that "Server certificate" is NOT identical to actual server certificate is when I prefer it be a wildcard certificate (thus valid for multiple servers within same domain).
I tested SSL-VPN and IPsec Remote Access with Fortigate VM Evaluation.But,it didn't work both.Is that Evaluation limitation?I found Restrictions,as "Support low encryption operation only",that means I can't use SSL-VPN and IPsec Remote Access?
Hello guys, this is my first time working with Fortigate appliance. I’ve a cluster of two F201, with two IPSec tunnel, one with Azure Cloud, and one with an external customer with a WatchGuard firewall. Azure tunnel has no issue (strange :grinning_face_with_sweat:), while the other one has a very particulate behavior. Both of them in IKEv2 with AES256/SHA256. If I start a ping from local to remote side using that tunnel, there is an high packet loss, but after about 40s of pinging the tunnel become stable, until it goes back to idle, and again another 40s and so one. It’s not a phase 2 flapping, because from the diag the SA is up for hours. What I’m missing?Any help is really appreciated thanks!
Hello, Fortigate v7.2.9.How can you display the MAC address table? I don't mean the arp table, I know the command. get system arp ThanksAlbMin
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.