Mark a Best Answer
Fortinet Community
Recently active
Hi! I'm looking to implement an automation in my FortiGate E100 in case on a specific port on my FortiSwitch 224E-POE a new MAC Address is detected. The only problem I'm facing is, how to detect this properly? I did some digging online and found out about sticky MAC addresses. I've enabled this for one specific port where always 1 specific device is connected to. I've setup the sticky MAC to persistently remember 1 address. I managed to get a FortiSwitch notification about the detection of a new device (other than known in the remembered sticky MAC address) in the FortiSwitch Systems logs, but I cannot manage to get a notificaiton about it. In the FortSwitch System Logs I did notice a new enterance, that looks like this:Interface MAC learning limit exceeded, MAC 84:XX:59:XX:e9:XX on port11 (Packet VID: 1). - FortiSwitch system So to just try out I made a Trigger in the Security Fabric Automations for notifications from the FortiSwitch system, lik
Hello,I am currently setting up an IPSec VPN tunnel on our FortiGate firewall, authenticated via Entra ID (formerly Azure AD), and I am encountering issues restricting access to specific VLANs based on Entra ID user groups.Objective:We have successfully configured an IPSec VPN tunnel that allows users to connect and access our internal network (192.168.0.0/16) and VLAN 10 (10.10.0.0/16). However, we want to achieve the following:Existing Setup (Working):All authenticated users can access the internal network and VLAN 10 without issues.New Requirement (Issue):Users from a specific Entra ID group should only have access to VLAN 20 (10.20.0.0/16), and should not be able to access other subnets.Steps Taken:IPSec Tunnel Configuration:Configured an IPSec VPN tunnel with Entra ID authentication (SAML).Successfully tested the tunnel connection and access to the internal network.Added Entra ID groups under User Groups (VPN - Access Vlan 20).Assigned the correct SAML entity and certificates.Addr
Hi, running Forti Manager 7.0.13. When evaluating an upgrade to 7.2.9, i ran several integrity checks. One of the adom checks resulted in feedback : 21 changes(s) will be made. Is there a way to find out what these changes are?
Hi.Has anyone ever been able to deploy FortiEDR Collector to MACOS with Intune?There are literally no info out there on the subject, how does everybody do this.I can't imagine everyone manually installs FortiEDR on MACs.
Dear all,I am working on a EST server that should interact with Fortigate as the EST client. The standard workflow works fine for both, Simple Enrollment and Simple Re-enrollment.Those request can return a 202 - pending status, where, according to the RFC, Fortigate behaves as expected: "The client MUST wait at least the specified "retry-after" time before repeating the same request". My question: in my EST server, I need to identify the retries for a same request. I would thus like to handle a transactionID to be shared between my EST server and Fortigate. But handling of a transactionID is not part of the EST RFC. It can be customized in my implementation of the EST Server, but my question is: does Fortigate handle a transactionID when it receives a 202, and if yes how does it do it ?To go a little further: I would like to differentiate each renew operation with a new transaction ID. That is, the 'retries' have the same transaction ID, but the next renew of the certificate,
Hi,I'm trying to register Fortigate VM for permanent free trial, but unable to do so because of unsupported serial error.I downloaded FGT_VM64_HV-v7.6.1.F-build3457-FORTINET.out.hyperv.zip zip from Fortinet support site. Created VM with 1 CPU, 2048 RAM and with 2 nic. I first I tried to register from command line without success: # get system status Version: FortiGate-VM64-HV v7.6.1,build3457,241127 (GA.F) First GA patch build date: 240724 Security Level: High Firmware Signature: certified Virus-DB: 1.00000(2018-04-09 18:07) Extended DB: 1.00000(2018-04-09 18:07) Extreme DB: 1.00000(2018-04-09 18:07) AV AI/ML Model: 0.00000(2001-01-01 00:00) IPS-DB: 6.00741(2015-12-01 02:30) IPS-ETDB: 6.00741(2015-12-01 02:30) APP-DB: 6.00741(2015-12-01 02:30) Proxy-IPS-DB: 6.00741(2015-12-01 02:30) Proxy-IPS-ETDB: 6.00741(2015-12-01 02:30) Proxy-APP-DB: 6.00741(2015-12-01 02:30) FMWP-DB: 0.00000(2001-01-01 00:00) IPS Malicious URL Database: 1.00001(2015-01-01 01:01) IoT-Detect: 0.00000(
Need fortigate firewall MTBF, where can i find, I have partner portal access, can someone point to specific document/link for these details. I would need the below for a customer.FG-121GFG-201GFGR-70F
Dears, Currently i am running a hyper-v host with 2 network interfaces. Each one has been assigned to one vSwitch, one is on the internet directly and the other is attached to FTGT 71G (transparent mode). When I change the vSwitch of the VM to look at the FTGT it says identified network. If I create a new network adapter to the VM and connect it initially to the vSwitch that is connected to FTGT it works as expected. Have you encountered this type of issue?
Hi,I want to create FortiSandbox windows11 VM custom image but when I give 30gb disk space, windows 11 takes 25gb by itself. There is no space left for components such as office, adobe chrome firefox. I need to leave 5gb more space. What should I do about this? Can anyone who has information help me? Regards
Hello Team, Question about FortiProxyWhen using the browser the login banner comes out correctly and so far so good. But when desktop applications are used (such as arubasign or acrobat reader for digital signature verification rather than other applications) they do not work. How do I handle these exceptions? Is there an agile way to do this?How do you configure fortiproxy to make it handle desktop applications? Thanks
for example a FortiClient profile and a windows profile on the same WAN IP.
Hello, i am using FortiEMS 7.4.2 with a FortiClient.They are both connected but my Client doesnt get any AV signature updates as it still shows its at version 1.0I already switched to FortiGuard Anycast as the server type in the EMS settings but it didnt help.How do i get a newer version of the AV signature and can i even get a newer version?
Hi,I am quite new to Fortinet - I am used to Cisco. I have a Fortigate 40F and a Fortiswitch 124F-PoE. I have them linked by Fortilink and I can see the switch in my Fortigate.I want clients connected to Fortiswitch to get their DHCP from the Fortigate. I cannot see how to do this. I set up a vlan on the Fortigate (Fortiswitch Vlan) and told it the DHCP relay was on an interface on the Fortigate - I have created a hardware switch and made LAN2 a member - I have a DHCP server on that hardware switch. When I plug a device in to a port on the Fortiswitch (port 1) which is in the Fortiswitch vlan I created it does not get an IP address. I am not sure whether I am doing this right. Any advice on this is most appreciated. A simple task I would have thought that I can do in a few minutes on Cisco but this is not at all the same.Thanks in advance.
I have a website that has a calendar, i want the users from, for example : UK to be able to see the available days from the UK URL, if someone outside UK accesses the UK url i want to edit the response for the calendar so the calendar appears that no day is available, is this possible in fortiweb? i don't want for it to go to a error page, just edit the response for the calendar to appear empty to mitigate bots and attacks from fully bookin the calendar. i know we can redirect but i want a response rewrite, i'm using a version below 7.6 i heard 7.6 has this function but i can't find official documentation to prove to my customer to upgrade the fortiweb. thank you,
Hi How can i download forticlient vpn offline installer for windows?
Hi EMS adminsStarting from EMS 7.4.1 there are two installation packages. One binary and one OVA.forticlientems_7.4.1.1872.amd64.binFortiClient EMS installer for x86-64 processor.forticlientems_vm.7.4.1.1872.ova.zipVMware vSphere - ESXi HypervisorIs there one method more recommended than the other?Will the two methods be kept for the next releases?
Here is the basic setup, I have two ISPs one copper & one fibreRunning on 101F ver. 7.0.xWith ISP1, i got a public subnet 1.2.3.0/28With ISP2, I got a public subnet 4.3.2.0/28 Configured IPs on two wan interfaces with 1.2.3.2, 4.3.2.22 Static routes were configured with0.0.0.0/0 default gw 1.2.3.1 (first ISP gateway)0.0.0.0/0 default gw 4.3.2.1 (second ISP gateway) Everything works as intended. I also have VIPs mapped using 1.2.3.0/28 subnet and with appropriate firewall policythey show the correct IP (source IP) when I run something like: dig +short myip.opendns.com @resolver1.opendns.com However, when I repeat the same configuration for VIP using 4.3.2.0/28 subnet, the source ip always shows 1.2.3.2( interface IP of first ISP) in other words if VIP was 4.3.2.3 mapped to 10.10.10.10 on inside, it still shows as 1.2.3.2 How can I get the source IP show the VIP that I created.
Hello, Where can we find offline installers for FortiClient, please? I.E. this version and all future versions. Often the process of the FortiClient installer connecting to the server and obtaining the files is the longest part of a job. At least if we had an offline installer, we could anticipate how long the file would take to transfer or do it as a background process, etc. My current install (update) to FortiClient on a remote laptop has taken half an hour to get to 15%. Thanks,Mark
We are trying to set up notifications (via automation stiches) of system configuration backups. The automation stiches appear to support this as they have entries for the relevant log events (32142 and possibly 32145) but for whatever reason, our FortiGates are not recording the backup events in the event log. The log setting for "Event logging" is set to "All." We can find no other place either in the GUI or CLI reference material that would indicate any other setting to enable the expected functionality. Does anyone have any insight into why the backup events are not being recorded in the event log?The models in question are 100F, 80F, 60F and firmware versions 7.6.0, 7.6.1, and 7.2.10.
Hello, please, is it possible to swap licenses (FortiNAC License for 100 concurrent endpoint devices) from a physical appliance to a virtual appliance.
We are currently running FortiClient for antivirus on our endpoints and this works well with FortiNAC Endpoint Compliance. The issue we are running into is testing a new antivirus that is not listed on the Antivirus list within FortiNAC. Is there a work around to use an unlisted Antivirus for Endpoint Compliance within FortiNAC v7.2.5?
Hello everyone, New to fortigate.I stumble upon a problem. So I have a Fortigate 60F. On interface 5 I have the following network: 172.16.20.0/24 and on interface 2 I have the following network: 172.16.30.0/24. I've created the 2 necessary policies for communication between the 2 networks ( I will later only give access to certain PCS). On 172.16.20.0/24 network we have a NAS with a static IP of 172.16.20.5. Everything works fine between the 2 networks. The issues arises when a client on 172.16.30.0/24 network, establishes a Open VPN connection with a remote location. All map drives for the NAS works for a while and then everything stops working. Also as soon as the connection is established, the ping stops responding. As soon as the OVPN is disconnected everything is back to normal. At this point I have to tell you that my Firewall is behind NAT but with DMZ to our Firewall. Any input is much appreciated!
Hello Community, I'm setting up SSL VPN on a FortiGate device for the first time and could use some guidance. What are the critical settings I should pay attention to for ensuring both ease of use for clients and robust security? If you have any setup tips or resource recommendations,Spoiler (Highlight to read)I am not familier with this technology, passionally I am a professional concreter founder of: www.concretesrichmondva.comI am not familier with this technology, passionally I am a professional concreter founder of: www.concretesrichmondva.complease share!
I created a security policy to allow NEWLY CREATED DOMAINS, unfortunately the url meant to be allowed on the Destination has still been blocked by the firewall, what could be the possible cause of this issue and how may i resolve the issue?
Hi, My ISP Gave me xxx.xxx.xxx.xxx public IP and xxx.xxx.xxx.xxx Getway with xxx.xxx.xxx.2, xxx.xxx.xxx.3, DNS. I make Static Configuration For Interface WAN 2 With Public IP and Gateway. But where do I put the DNS
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.