Mark a Best Answer
Fortinet Community
Recently active
Hi, Have a query around ADVPN inter region traffic flow. Lets consider we have two regions and each region has their own Hub to advertise the regional LAN summary routes to its regional spokes. And both the hubs have eBGP neighborship between them to exchange regional summary routesIn this scenario, can understand region 1 spoke can form an advpn tunnel with region2 spokes but there are no mention about whether ADVPN will work between region 1 spoke to region 2 hub?.. There is no clear documentation about this in 7.4/7.6 documentation. RegardsRaja
Hello All, I have a question that I have a VIP with specific IP and running a published service when a client browse the service the VIP appears in computer IP not the client IP who accesses. Is there a way to show the client IP ?
Hi Community, In FortiAnalyzer: is it possible to generate a report that shows me license information from for example FortiGate using a custom dataset? Info like "about to expire licenses" from all FortiGate devices. Also things like you can get from "diagnose autoupdate ver", for example "Last Updated": <snip>Flow-based Virus Definitions---------Version: 93.00577 signedContract Expiry Date: Sun Dec 28 2025Last Updated using scheduled update on Mon Jan 27 17:12:27 2025Last Update Attempt: Mon Jan 27 17:42:10 2025Result: No Updates<snip>
I have generated new SSL certificates for the FortiGate firewall, and trusting the new CA. But it appears that FortiGate is still using the old SSL GUI certificate. I followed this document for regeneration:https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/663527 # execute vpn certificate local generate default-gui-mgmt-cert# execute vpn certificate local generate default-ssl-ca# execute vpn certificate local generate default-ssl-ca-untrusted# execute vpn certificate local generate default-ssl-key-certs # execute vpn certificate local generate default-ssl-serv-keyMy hardware is FortiGate-60F, firmware version 7.2.8 The old certificate is not expired, but I don't trust the old CA anymore. After switching to the new CA, and installing the new CA on my Mac, FortiGate is still presenting the old certificate when I try to log in to admin console via GUI. Inspecting the Certificate page, I only see the new certificates, but SOMEHOW FortiGate is pres
Hi, I had an IPsec tunnel working between HO and Branch Fortigates until I changed the WAN IP Address in HO. The branch office Fortigate is behind a Nat Device with a private IP on its WAN Interface. I even recreated the dial-up Tunnel using the wizard but it is not coming up. How can I troubleshoot to resolve this? Thanks.
Hello Community In a FortiLink split-interface setup, how can i decide, which interface should be prefered? Background100F ClusterInterface x1 and x2 belong to FortiLink Agg Interfacex1 goes to 1024E "Core-Main"x2 goes to FSW1xxF Series Switch "Core-Backup" From 1024E "Core-Main" we go to each access switch (hub & Spoke setup)From 1xx "Core-Backup" we go to access switch-1 then switch-2, switch-3, switch-nBy this, if 1024 should be offline or damaged, we still have each access switch somehow connected to the firewall and can provide services. we do have a massive impact on bandwith within the network, but it works unit one can replace the hardware) Initialy I had the idea to use a hardware switch on the fortigate, but we need block-intra-vlan and other features, that are not supportet on a switch on the FGT A second 1024 is in budget for 2026, since then we have to work with the above setup.So this i why I have to rely on split-interface active, and "need"
G'Day, I've been using FortiSSLVPNclient for years now to facilitate my Remote Desktop Manager controlling my VPN for me via CLI to ensure I'm connected to the correct VPN for the desktop I'm connecting to. The external vendor in charge of the VPNs is switching to use SAML logins for the VPNs though, and while I can configure and test that method in the GUI version of FortiClient successfully, I haven't found a way to use it with FortiSSLVPNclient. Is it possible to trigger a SAML based login via FortiSSLVPNclient?Or if not, is there another tool/exe that can be invoked via CLI that can use SAML to establish a VPN connection? I'm using FortiSSLVPNclient 7.2.1.0779, but it's bafflingly difficult to obtain the tool exes so I'm hoping the problem is that there's a flag I'm missing and not that I need to update/replace it. Also as a less critical but still relevant aside, is it possible to configure the SAML popup window on the VPN side to behave in a password-mana
Hello, I recently installed a second WAN on my FortiGate 40F. I've been facing an issue I'm not able to resolve and looking for some help. I am a beginner though, so I'll try my best to explain my goal clearly and current Goal:- My wan1 has a bunch of static IPs, while wan2 doesn't have any. - I would like to access my file server via a static IP from wan1 from the internet (only wan1 has static IPs)- I would like the application to only upload traffic via wan2 because it is 25x faster.So, it should listen on wan1, but actually use wan2 only for data transmission. Current Setup:- Configured SD-WAN and added both members. WAN2 has a higher priority, and in general it is being used most of the time, which is good for me. - working fine- Created VIP for my server (external 37.37.37.37, internal 192.168.5.111) - working fine My Policies: - SD-WAN to LAN (source all, destination VIP)- LAN to SD-WAN (source all, destination all) F
I have built 5 FortiClient EMS servers on Ubuntu. I cannot log into any of them with the admin user account. I can authenticate in Ubuntu shell with my other admistrative account at the cli, but not into the GUI with that account. I have run the admin user account password reset and I still cannot log in.I am setting this up as a POC and I am using the free version so I cant contact support on this issue. How anyone else experienced this? Thanks!
Hi EveryOne,I need little help on following.I have two location Location A in NY, USA and Location B in Pakistan. Both location have Fortinet firewall with dedicated Ip Addres. Actually I want to use USA Location Internet Like when I will go my web browser and search what is my IP that is always show internet location Of NY, USA Office. In simple words I want to use NY, USA office resources. what configuration I require to connect two diffrent places.Please Help on this.Regards,Umar Ashraf
Hello, I understand that even if a a Telco Internet circuit supports a standard MTU of 1500 and fragmentation is either not supported or reliable, that this is irrelevant to the fragmentation that may take place on traffic passing via a Fortigate IPSEC tunnel across that Internet circuit i.e. the two concepts are separate.So, you could have a telco Internet circuit with 1500 MTU and no fragmentation support, but fragmentation can still work WITHIN the Fortigate established IPSEC tunnel.Am I correct in this thinking ?Thank you kindly.
Hello all! This is my first time working with Fortinet hardware, specifically a FortiGate firewall and I’ve hit a big roadblock. I’m on a massive time crunch and management is coming down on me hard to resolve it, so I’m hoping someone here might know the answer.The long and short of it is, I have a webpage that operates in a closed network (no external network access, physically). This webpage displays a video feed that is put out from a camera via multicast and in that closed network, everything works great. Management says they want to now do a test to see how this website could be accessed on the internal company network. They’ve provided me a FortiGate 90G and said ‘make it work’. I’ve managed to get the webpage itself through the firewall using NAT and it is accessible on the corporate network.. but the video component isn’t coming through. The video player says it could not open the webRTC stream. So far, I have:- Enabled advanced routing and multicast policy in the feature visi
I need to create some kind of notifications that an email with specific words in subject or in body was sent to any email address. I managed to achieve it with Archive account. I've created an Archive account which is forwarding email to another email address and I've created a policy that is archiving emails based on Subject and Body pattern. It works fine if the word in subject or body is equal to the word I've entered in pattern on policy. For example I've created Policy with Policy Type Subject and in Pattern I've enter word: bomb The policy works fine for example for a subject like this: I've sent a bomb to you. Email is properly forwarded to email address I've entered in Archive account. However the policy is not working for subject like this: I've sent few bombs to you. I've tried entering *bomb* in pattern but it's not working. Is it possible to use WILDCARDS in this policy patterns or REGEXP expresions? Or is there any other way to
Hello FORTINET team,We Are One Digit Solutions, A digital marketing and Web development agency, Located In Karachi Pakistan.Report generated according to : https://www.virustotal.com/gui/url-analysis/u-0b3ffe8e0bf972bad2d54098ae2901fc274c3e00a6d4aecd9616f67bf6843029-1657189856I add Report generated by Google's transparency reporthttps://transparencyreport.google.com/safe-browsing/search?url=onedigitsolutions.comOur website is blacklisted for some reason and we think it may be a false positive. We request the removal of our domain from its blacklist because it is a false positive of phishing.Our website has SSL security for the safety of our visitors.Regards
Hello, I have a FortiGate 100F, and my license will expire on February 3, 2025. Is it possible to add a trial license for temporary use? #fortinet #license #fortigate #100f #trial.
Does anyone know if Fortinet is coming with a new G models for Datacenter solutions?
I'm setting up a new FM v7.6.1 trial on Hyper-V and have noticed, frustratingly, that every bit of configuration info I add into FM gets wiped out after every reboot, except the FortiCloud licensing. Three times I have added a 60F, rebuilt the SSIDs/groups/profiles, performed the best practice security hardening, before I figured out what was happening here. I've shut it down both from the Hyper-V GUI and exec shutdown, and when it comes back, the 60F/SSIDs/profiles are all gone. Update: Because I didn't know there were installation instructions, I had downloaded the VM image and secured it before creating additional virtual storage disks. Added the additional storage, and now all the info is retained after a reboot.
The primary firewall was restarted, causing the secondary unit to become the primary. However, it is not syncing with the primary, and both HA cables are active.
Hi, I’m having a lot of trouble getting ourFortiGate firewalls (100Fs / v7.2.10 build1706) to connect to our Microsoft NAS RADIUS server (Windows Server 2022). In NAS there is a tick box that says “Access-Request messages must contain the Message-Authenticator attribute”, my research shows that given version of the Forti software we are running, this should be ticked, however with this ticked Forti reports “Unable to reach RADIUS server” and Windows Event Viewer shows: “An Access-Request message was received from RADIUS client 10.10.100.1 without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.” If I untick it then Forti reports invalid secret (even though it’s been triple checked, reset, and che
I want to configure the proxy of my fortigate and I need to install the “Fortinet_tsagent” to recognize all the users in the Terminal Servers, but in a Windows Server 2003 I get this error when I want to run it:“Service Fortinet SSO Terminal server agent (Fortinet_tsagent) failed to start. Verify that you have sufficient privileges to start system service.” The user I am using has administrator privileges to everything. That is not the problem.Can you help me?
Following from a previous post, which was kindly resolved (External CA for Captive Portal). I am doing further testing and have come across a minor query: How to configure FortiGate Captive Portal... - Fortinet Community This article mentions using DNS, so that it can resolve the FAC address, now, I dont use internal DNS I use google DNS on my Fortigate to resolved external and get out to fortiguard etc, Am I right in assuming, in order to allow the Guest Portal to see Fortiauth, Ill need to set up a local DNS Zone with the internal DNS as forwarders and apply it on the Guest SSID interface? is this the correct way to do it?
The USB modem, which successfully establishes communication on FortiGate 50E and 60E, is not recognized on FortiGate 60F. FortiGate 50E / OS 6.2.15 .... OK FortiGate 60E / OS 7.2.5 .... OK FortiGate 60F / OS 7.2.5 .... NG!On 60F, "Modem failed to open" is repeatedly logged in the system log.Although 60E and 60F have the same OS, only 60F does not recognize the modem. I am confused! #Restored to factory settings and applied only the following configurat#This modem mode switching is not necessary.config system 3g-modem customedit 1 set vendor "SORACOM" set model "SC-QGLC4-C1" set vendor-id 2c7c set product-id 0125 nextendconfig system modem set status enable set auto-dial enable set wireless-port 3 set phone1 "*99#" set username1 "sora" set passwd1 ENC xxxxx set extra-init1 "AT+CGDCONT=1,\"I
Hi, So our fortigate cluster restarted last night. We got the following messages over SNMP :FortiGate: Device has been replaced (new serial number received)FortiGate: System name has changed (new name: xxx-fw1-n1.xxx.net)FortiGate: xxx-fw1 has been restarted (uptime < 10m) This also meant one of our VPN tunnels went down and which generated an alarm. What might have happened here?
Hi All, Does anybody know what does srcserver / dstserver means on logs???? I see that it can be 0 or 1. Mostly I get 0. Documentation is not very clear "Source Server (srcserver) Server of the source. srcserver=0" What does it mean that the server of the source equals 0????
Hello everybody,I am trying to exploit the *.rpm version of fortinet client VPN on OpenSuse Leap 15.2 to connect to a VPN with SSO authentication. While all the SS= steps are completed successfully the client remains forever in the "connecting" status with no error or useful information available in the logs. Is there anyone who has been able to exploit the client on OpenSuse Leap? any suggestion on how to overcome this issue? Thank youDario
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.