User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Secure Connectivity for Mobile Fleets: FortiExtender Vehicle 211F By @PatVita | Director of Product Marketing, FortiExtender If you’re a close follower of Fortinet product news, chances are you’ve heard rumors of a mobility solution coming to the FortiExtender family. I’m happy to say the wait is over: FortiExtender Vehicle is here. Secure Connectivity for Mobile Fleets Many IT teams struggle to service mobile fleets. Whether it’s a public safety, transportation, logistics, or the travel industry fleet, vehicles are unique in that they require secure connectivity to cloud applications but cannot leverage wired broadband. Adding point solutions creates complexity and risk for organizations. Mobile fleets cannot become another silo for enterprise IT. Secure connectivity for must be delivered within a digital platform alongside other areas of IT, such as OT, IoT and wireless access, Enter FortiExtender Vehicle 211F
Dear all, I have diagram as below: --------- tunnel 01 --------------Hub (lo0) (Lo0) Spoke ---------- tunnel 02 ------------- I am using BGP on loopback to set up routing via 2 Tunnels. (FortiOS 7.4.4)And I try to set up SD-WAN Rule to steering BGP traffic (Keepalive, updates...) via tunnel02.In the sd-wan rule: I set: source is Lo0 of spoke and destination is Lo0 of Hub, Outgoing interface: i used Manual : Tunnel02 is first order and tunnel 01 is last order. Member is 2 tunnel interface SD-WAN zone. But after that, I can not see any hit count on the sd-wan rule, and diagnose packet port 179 : traffic still via tunne01. I am wondering what is my mistaken ? (or BGP update processed by SDWAN rules ?) (I have another sd-wan rule to allow all (all source and all destination), used SLA
FortiSOAR Community Update: Powering Up with Industry Favorites! This month's spotlight is on the tools and solutions that have become indispensable to SOC teams across industries. From tackling outbreaks with precision to enhancing system monitoring, these updates are here to streamline your workflows and boost your security posture. Our Outbreak Response Framework together with its Configuration Wizard remain industry champions, offering swift and efficient responses to emerging threats. Coupled with the Fortinet FortiGuard Outbreak connector, these tools ensure you're always one step ahead of the threat landscape. And for those looking to enhance their data protection strategies, the Fortinet FortiDLP connector is here to secure your sensitive information with ease. The IBM Security QRadar SOAR and Maxmind connectors continue to deliver insights and integrations that empower your team. Add FortiSOAR's own System Monitoring and Netscout's Arbor Edge Defense to the mix, and you
Hello everyone!I looking for help for a case,I have Fortigate 92D and interfaces created successfully and it also be router, firewall andDHCP server.I have some ZTE Wifi AP devices support for EasyMesh.I have an issue with that APs when connect them to same interface in Fortigate that mesh function via wired cable will not works, but if I put a Switch between Fortigate and APs everything work fine. EasyMesh not work: Internet ----> Fortigate 92D ----[LAN cable]---> APsEasyMesh work: Internet ----> Fortigate 92D ----[LAN cable]---> Switch ----[LAN cable]---> APs Fortigate 92D is great device for Home because it has a lot of LAN ports so put a Switch to help APs functioning is not a good setup. Thank you!
I've got a client that is gonna have a Connectwise SIEM (Perch) sensor placed in the network. Normally the internal Fortigate Port on the Switch is being mirrored. But with this client the Internal Port is also the FortiLink to Fortiswitche(s). The Port where the Fortigate is connected is port 48. How can I create A mirror port on Port 48, without breaking the FortiLink to the FortiSwitches? The Perch Sensor is connected on Port 30.
I am using a wireless LAN by connecting FortiAP421 and FortiAP431 to Fortigate60E. Occasionally, there are instances where client devices get disconnected. The logs output during those times are as follows:- Wireless client left WTP- Action client-leave-wtp - Reason Unspecified reason. Does anyone know the cause of this log? If I were to investigate, how should I proceed?
Hey Guys We are facing Hight SSL Negotiation time, when WEB filter profile has enable on the rule at Security Profile.When we disable de WEB Filter profile on the rule, the SSL Time improve considerable .To test i'm using this curl command, for google website. But this issue occur with any destination addresscurl —resolve www.google.com.br:443:142.250.219.131 -w "DNS_resolution: %{time_namelookup}| TCP_negotiation_time: %{time_connect}| SSL_negotiation_time: %{time_appconnect}| TTFB: %{time_starttransfer}| Total time: %{time_total} \n" -o /dev/null -vsL https://www.google.com.brWhen WEB Filter profille is enable the SSL_negotiation_time is more 3 secondsWhen WEB Filter profile is disabled the SSL_negotiation_time is not more tham milliseconds When I check on System ==> Fortiguard My Web Filter Status is average 123 ms. Someone experienced this same issue ?
I have a Fortigate 60F with 2 networks. 10.25.0.0/24 is the default internal network and I have 10.25.10.0/24 configured on Port 3. There is not policy routing between these networks yet. I accidently set the Trusted IP restrictions on the Admin account to 10.25.10.0/24 so now I cannot log into the GUI at all, from either network. How do I reset this? Help!
Hello All,I have this issue. FortiGate 40F (v6.4.15 build2095)Fortinet tunnel is showing inactive stateReproduction : I use the GUI not the CLI.1. I created a vpn user2. I assigned this user to a vpn group3. I used th VPN wizard to create an Dialup FortiClient (Windows, Mac OS, Android) :-> https://docs.fortinet.com/document/fortigate/6.4.15/administration-guide/785501/forticlient-as-dialup-client4. In Firewall & Objects-> Addresses :-> Created automatically -> vpn1_range = 192.168.1.1-192.168.1.254-> Created automatically -> vpn1_split = members = lan-> Firewall Policy :-> Created automatically -> vpn_vpn1_remote_0-> The VPN was created, but shows INACTIVE.I really don't understand. Can some help, please ?Kind Regards,Jo
This regards the " Spam URL" Classification under " Fortiguard Web Filtering" . I was wondering if anyone else felt the Spam URL classification has been applied to liberally to too many websites. For example budget.com, the rental car company, fell into this one. While having this on sounded like a good idea at first, I quickly had to turn it off due to frequent blocking of sites my personnel need. I' ll send the occasional correction in to Fortinet, but I' m not going to turn it into a full time job.
Hi - weird one that has never happened before...https://imgur.com/gjjth76Everything is fine license-wise except for this "Industrial Attack Definitions" expiring. This occurs on both of our Fortigate 101F's.The contract was renewed and applied over a month ago, so it's not an update issue it seems. The Industrial DB's definitions have also been updating just fine.We purchased:1 FC-10-F101F-809-02-12 1 Year coverage for FortiGate 101F include:Hardware Advanced HWFirmware & General UpdatesEnhanced Support PremiumTelephone Support PremiumAdvanced Malware ProtectionFortiGuard IPS ServiceFortiGuard URL, DNS & Video Filtering ServiceAntiSpamFortiConverter Service 8x5FortiGuard Attack Surface Security ServiceFortiGuard AI-based Sandbox ServiceDLPWhats the deal? Am I going to lose IDS? Do we need to remove anything from our policies to prevent blocked traffic?These are several years old now and this has never happened before. It's just odd it's happening to both devices because it seem
Could someone clarify what the licensing options are for a FortiAP that is managed by a FortiGate? I'm aware there is an Advanced Management license when using Cloud-managed FortiAP but I want to confirm whether that is required for all FortiAP's or not. If you could point me to a document that explains this in detail, I would appreciate it. I've been searching documentation for a while & haven't found anything clear.
There is a nice articlehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-Disable-Specific-IP-Addresses-or-IP-Address/ta-p/271410but this does not really help, if you want to disable an entry in the Malicious-Server table.Because this has more than 500.000 entries and if the ip-address is in the middle you can scroll down a few weeks.Not possible to search for the ip-address and disable it.
Downloaded Forigate 7.2.2 for my virtual lab and for life of me could not get the evaluation version register. First it was giving me DNS resolve error. I resolved that error now I am, getting " Curl Forticare failed,7 time out." on Gui I am getting error " error communicating with forticare ". I am using WMware workstation 16 Pro.
It's basicly what the title says. We use forticlient to connect to the company's VPN. I was told that the request reaches successfully the server but when it tries to create the ssl tunnel it fails. I already tried to reinstall, changing the wifi connection used.Here I have extracted some info from the sslvpn.log file that I think relates to the problem.Could you help me please? 20241112 09:58:28.682 TZ=-0300 [sslvpn:DEBG] vpn_connection:2451 EMS info added : serial number FCTEMS8823008006, tenant id 00000000000000000000000000000000 20241112 09:58:28.682 TZ=-0300 [sslvpn:DEBG] main:1609 Create socket connection 20241112 09:58:28.695 TZ=-0300 [sslvpn:DEBG] main:1687 Message to UI: A FortiToken code is required for SSL-VPN login authentication. 20241112 09:58:28.695 TZ=-0300 [sslvpn:DEBG] main:1705 153 bytes sent. 20241112 09:58:36.260 TZ=-0300 [sslvpn:DEBG] vpn_connection:659 http connection closed. 20241112 09:58:36.260 TZ=-0300 [sslvpn:DEBG] vpn_connection:521 R
Hello communityI have a question, if anyone can help me.I would like to work for Fortinet in Switzerland, in or around Geneva. Would anyone have a contact to advise me at Fortinet to apply or call me?thank you in advance for your reply.
I have a fortigate in the cloud that when the flow from a linux server passes through it, the source machine in question is on the Oracle Cloud internal network and the destination private load balancer is on another Oracle Cloud network, but I want to force them to communicate only by passing through the firewall. I can close telnet, which shows that the route is correct. I can connect to the destination, but when I try to execute the connection via the linux command line using SSL, it does not negotiate, giving an SSL Handshake error. The problem only occurs when passing through fortigate.If I go through the VPN in others to the same Load Balancer it works normally, only when the connection is coming from an internal network to another internal network that the error occurs. The tests performed were done both with NAT active and without NAT active, but in both tests the error persisted.
Hello,I'm trying to create a notification when my internet link is down to send a message by e-mail, but I'm getting 3 e-mails with DOWN and UP status, would you have a tutorial I can see where I'm going wrong? Another thing, would it be possible to send this by telegram or WhatsApp? I can't do it through teams because Microsoft is giving me an error in the apps. I'll send a printout of my settings
hi,i plan to configure a couple of VDOMs in a FGT, one VDOM is our "main" internet VDOM connected to ISP (and downstream customer VDOMs).i plan to deploy another customer VDOM with eBGP integration.is this VDOM design/setup feasible? are there any "gotcha" that i should know?
Hello all, I am currently preparing QoS for a Dante audio network for some FortiSwitches managed by Fortigate / FortiLink. Dante needs at least priority for PTP (CS7, high) and Audio (EF, medium), and optional for other reserved traffic (CS1, low) according to following documentation:www.getdante.com/support/faq/how-does-dante-use-dscp-diffserv-priority-values-when-configuring-qos/ As far as I understood the Fortiswitch QoS concept, it should be sufficient to map the different DSCP values to different queue-numbers according to their priority (higher priority, higher queue) and to use the default "strict" scheduling, so that higher queues (e.g. the queue for PTP) are always serviced first. DSCP Mapping:CS1 to cos-queue 1 (reserved)EF to cos-queue 5 (audio)CS7 to cos-queue 6 (PTP) QoS Policystrict scheduling for all above named queues Port configurationMap the QoS policy to all uplink-portsTrust DSCP map on all Dante endpoint access ports Would you recommen
Hai we got FortiGate F201E with 7.0.17 matured versionUnable to find any upgrade path on gui and support tool to 7.2 or above any version if we manually choose any version and update ,will there be a chance loose configuration . any end of support announcement for 201EFirewall in critical production
The last time I deleted an old DDNS entry on a Fortigate that had been thrown away, I simply contacted TAC, and they deleted the record. Now TAC says that there has to be a valid subscription in order to have a DDNS entry deleted. The Fortigate in question was End of Life years ago, so renewing the subscription is impossible. How can this be solved, and can it be solved without contacting TAC and creating a support ticket?
Hi FGT/FPX adminsRegarding the latest security incident, IR number FG-IR-24-535 // CVE ID CVE-2024-55591, that affected some FortiOS versions.https://www.fortiguard.com/psirt/FG-IR-24-535Additionally to the remediation actions described on the PSIRT page, you may check if your IP address is affected (published by some third parties) and take the appropriate action if so.
Hi Team, The site to site has already Up.From HQ to Branch Okay, everything can Ping and access.From Branch to HQ unable to ping and access.Route and policy has done on HQ FortiGate 80F.HQ - FortiGate 80FBO - Sophos UTM 9HQ subnet - 192.168.110.0BO subnet - 192.168.1.0, 192.168.3.0 Is it possible I need to add extra Route and Policy on the Branch Sophos UTM?
Hi all,I have installed an additional ISP on my Fortinet firewall, the policy has been applied successfully. I have also 2 catalyst manageable switch. the main directly connected to the switch and the second by hyperlink to the mail.all users from the first switch work well, they get internet, etc... but all users from the second switch do not get internet connection
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.