User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Error-Unable to establish VPN connection. The VPN server may not be reachable.
Hi Everyone!I am testing EMS for FortiClient VPN depolymant and have depoloyed the ova image of EMS 7.4.1 on my esxi and switched to multi site management. I tried to create a deployment package to deploy FortiClient via invention. At the final step (4) of the Installer package creation process i get the following error: failed to create deployment package: not enough disk space.It does not depend if i use multi site configuration or not. i tried both. Same error.The Interface tells me, that there is 30% free space availible. Has anyone encountered the same error and has a fix?Regards,Thomas
Introduce: OS 7.4.6Site A has 2 tunnel VPN (site-site 1 and site-site 3)Site B has 2 tunnel VPN (site-site 2 and site-site 3)Site HO has 2 tunnel VPN (site-site 1 and site-site 2) Scenario:- Site A and Site B disconnected tunnel site-site 3 Request:How to configure routing on 2 tunnel site-site 1 and 2 for Site A can access Site B through site HeadOffice is middle.#IPsec, #FortiGate
Hi there, is there any (existing or planned) feature to be able to add the FortiAnalyzer to a SIEM (e.g. Microsoft Sentinel)?Kind regards
Due to well-known reasons, Microsoft Office 365 services in China are operated in isolation. As a result, the Internet service groups Microsoft Office 365 in FortiGate are not fully applicable to China. So an ISDB group is required specifically for Microsoft Office 365 in China.https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges-21vianet
Hi all,We currently have an IPS profile for Internet bound traffic (only certificate inspection, not deep ssl), and we block file sharing sites like OneDrive, Google Drive, etc.But we’re always getting requests in scenarios where users are on vendor based websites or vendor based portals and those sites are using Google drive or OneDrive on the backend to host their files, and they’re getting blocked. Also get a ton of wetransfer link download request from actual legitimate partners and vendors which is wild bc some of it deals with legal.Curious how you curtail these types of requests as I’m doing it the old fashion way which is super time consuming (once approved, open the access over a phone call, download, and then lock it back up). Even the wetransfer links are not easy unless we did deep ssl inspection and whitelisted the full url via a web filter profile, and even then, time consuming as each request would represent a new profile.Would love to hear how others are handling
Hi, we have enabled captive portal on the lan interface. Can captive portal time out when user logged out from computer or can we enable option to logout from the captive portal to user.Please guide..
Hi, The page https://osticketatl.ddns.net/osticket/open.php as blocked, how to unblock the page. This page is a workflow in use on the school
Hello, When we are trying to run the below commnads:exec update-now We are receiving the below error: Command fail. Return code -6 We have update the fw license on the portal and it is not reflecting on the fw dashboard
"Hello guys, how do I perform a speed test through a FortiGate 60F?"
i need to install version 7.0 in order to resolve an issiue with Version 7.4 where the connection is not being established.
Good Day! Some months ago, I switched my old FG30E because of the port problems (falling back to10mbit) to a new, used one, which was licensed to a Premium Support contract (mine was no Premium), that is the only difference, both have the exact same config. Took a routine look yesterday into the System Events and I was quite puzzled: the FG30E constantly tries to update the signatures, although, no scheduled updates ticked or any license active anymore. Furthermore, it clogs my syslog. The intervals are between 1 minute to 30 minutes. "Log Description: AV database updated by scanunit , User Interface n/a Scanunit initiated a virus engine/definitions update" Any chance, I can turn this thing off? Or just ignore it and set System Events to no logging so I wont see it any more? Regards,Stephan
Hi,I have a question regarding the integration of AlgoSec with FortiManager. If our business was to implement FortiManager for approx. 120 Fortinet firewalls, would we still be able to implement AlgoSec on top of that to complete end to end policy management and would it work seamlessly? We also have Juniper & Palo Alto firewalls in the network, hence the reason for needing AlgoSec to allow for better automation across our estate. I've read some FortiManager/AlgoSec documentation and it looks as though it should work, but I'd like to have that confirmed, preferably by someone who has used both of these systems at the same time previously.
20 odd AP'sall finenetwork dropped out yesterday for 5 mins and since then one of the AP's wont come back online FortiAP 231GFortigate version 7.2.9FortiSwitch 124F-FPOE Just get a solid Amber light on the AP for power.AP 'left' and Control Message Maximal Retransmission Limit Reached Things i have tried 1. rebooting the Fortigates2. rebooting the FortiAP 3. changing the cable from the patch panel to where the AP is plugged into the fortiswitch4.running this....config wireless-controller global set max-retransmit 3 <<<< default - please input integer value (0-64) ---> increase to 25 config wireless-controller timers set echo-interval <1-255> ---> increase to 100 end Still no change.Plugging the AP directly into the Fortiswitch brings it back online - but need it back out in prodcution round the building. Any ideas please?
In short: Is there an AI assisted way to upgrade FortiOS, comparing current configurations with releasenotes? When upgrading a system with several releases between the current and destination versions, the traditional approach involves:Collecting Release Notes: Gather all release notes from the current to the destination release.Reviewing and Comparing: Read through the release notes, compare them with your configurations, and identify potential issues.Planning Fixes: Address any issues before or plan to fix them ahead of the upgrade.Following the Recommended Path: Adhere to the upgrade path recommended by Fortinet.Testing Each Update: Test each update to ensure stability and compatibility.This method, while thorough, can be tedious and time-consuming.Leveraging AI for UpgradesWith the advent of AI, there could be a more efficient way to handle upgrades. Here’s a modern approach:Current Setup: I currently run FortiOS 7.0.15 on most smaller devices and have all configuration f
Overview/Scenario1. I have a use case for configuring NAT where in which an isolated Azure virtual desktop session host will traverse a NEW public ip address assigned to my Fortigate Azure NGFW virtual machine's WAN interface.2. Any IPs requiring egress traffic outbound will use cenrtal SNAT in a one-to-one mapping for all ip addresses within my AVD subnet range: `192.168.235.0/24`Questions:1. Could you please critique my implementation logic below? Relativley new to FortiGate, so please excuse the basic questions. I sourced FGT docs on [central SNAT](https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/421028/central-snat)2. As the new Azure public ip is assigned to the WAN interface of my FGT device, would DNAT be required? Not sure how FGT would route traffic from the new public IP inbound to my AVD subnet. However, there is currently no requirement to translate destination addresses to specific services within the isolated AVD subnet Proposed Azure deploymen
We have a FGT 80E with Forti OS 7.0.17 in air gapped network. I tried to update that with a local TFTP server. I updated these packages successfully : apdb , ffdb , isdb , nids , etdb , mmdb But still these databases are empty : Malicious URLs , Botnet Domains and Blocked Certificates . How can I update them too ? In which Package is this information located?
Looking into the benefits of FSSO in our environment for the purposes of restricting internet access. What does FSSO give you that a simple LDAP group doesn't within a firewall policy ? Or are they to be used in conjunction ? Thanks all!
I'm using SAML auth with my ZTNA proxy-policy. Everything worked great until I upgraded from 7.2.8 to 7.4.6.No config changes were made. This is a 91G model, which according to docs should still support full proxying in 7.4 and above. The root of the problem is that the Gate (SP) is no longer re-directing the client to the FAC (IDP) for SAML auth. When the client requests https to the ZTNA server, it presents its EMS certificate and is immediately granted access. Prior to the upgrade, it was presented a SAML login page from FAC and everything worked as expected. Is there more/different configuration in v7.4.6 ? config firewall access-proxy edit "ztna_https_faz" set vip "ztna_https_faz" config api-gateway edit 1 config realservers &nbs
I am using Fortigate 100G in HA and running Firmware 7.2.9. The issues I am facing is the interface is able to reach the NTP Server. NTP Server : 192.168.1.10FGT MGMT : 192.168.1.4 I have added a MGMT interface under dedicated management interface, which changes the MGMT interface in different vdom and getting removed in interface GUI. I want to get the time through management interface. I have configured NTP with below config set ntpsync enableset type customset syncinterval 1config ntpserveredit 1set server "192.168.1.10"once I try to add command "set source ip" it is showing below error "192.168.1.4 does not match any interface ip in vdom root." , as Management interface is removed from root vdom So my question here is can we configured ntp on dedicated management interface vdom, or how can we achive. Also I am referring to below docs in which we can set the interface under ntp server-->edit 1, but I cannot see it in my firewall. https://docs.fo
Dear Sir, We have a almalinux server running a website. This server has a dedicated Public IP.We want to change its private IP address from 192.168.3.A to 192.168.3.B.Before changing the private IP, we have duplicated all relate Fortigate firewall policies for the new IP 192.168.3.B. However, we found that we still cannot connect the website after changing the private IP.The sever is connected to the internet because we can ping outside from the server, and we can also ping the server from other computer in the same subnet. We feel the problem is due to the firewall policy but we don't know where it is. Can anyone advise us what settings can cause this problem?Thank you.
Hello, I have encountered a recurring issue across all versions of FortiClient 7.x while trying to connect to my VPN. After entering my password and pressing "Enter," the password field gets grayed out and becomes unclickable.At the same time, a new field labeled "Answer" appears, asking for a PIN between 4 and 8 alphanumeric characters. When I input the PIN and click "OK," I receive an error message stating that the password must also be entered. Unfortunately, since the password field is disabled, I cannot re-enter it, making it impossible to proceed. I’ve attached a screenshot for clarity. Has anyone encountered this issue before? Is this a known bug in FortiClient 7.x? Thank you in advance for your help!
First of all, I am inheriting this network and I believe this to be setup incorrectly however I've never seen someone try to do it this way. I have a two site-to-site fortigates with a switch behind each. I am getting inconsistent pings to the far switch. The far fortigate is also getting intermittent pings to its switch (they are connected via copper which has been swapped out). The LAN interface is set to 192.168.0.1 and the switch's Management interface is set to 192.168.0.2. Under the FG's LAN interface are SVIs for the various vlans on the switch. It seems to me that the problem is likely that the OOB mgmt interface is being used or is there something on the FG side that I should look at?
I have disabled the autoupdate and coud communication on our Fortigate firewall, running v7.0.14. But, the logs are showing the "Fortigate update now failed" every minute. wondering how to get rid of these messages?
Hello, I wonder if anyone in the community has an MTBF for the FGR-60F?The Spec sheet states:Compact and Reliable Form Factor Designed for small environments, you can place it on a desktop or wall-mount it. It is small, lightweight yet highly reliable with superior MTBF (Mean Time Between Failure), minimizing the chance of a network disruption. Evidence would be great ! Thanks Steve
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.