User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
hi,i'm going to configure a new FGT.is it preferred to put/configure ALL VIP/DNAT rules on top then put ALL FW policy/SNAT afterwards?can someone advise what's the best practice in FGT?
I can no longer connect to the console of my FortiGate 60F.Does anyone know how to solve this?I am trying to access the console with teraterm. When I start up fortigate, I can access the console, but after a while, pressing Enter does not respond.I believe there is no physical problem because I can connect to the console of devices other than fortigate using the same cable and PC.The firmware I am using is FGT60F-7.4.5-FW-build2702-240916.
Hi Team,I'm trying to Create an IPSEC Site to Site to a Sophos UTM.Below was my configuration in FortiGate: Just wanna to confirm that my configure correct or not as default. FortiGate
Hi Everyone,I have a FortiGate 40F firewall and a 48-port Unifi switch. I am using different vlans to manage Wi-FI for our customers, Wi-Fi for our staff, Local LAN, CCTV and IP Phone on the same switch. I am facing voice breaking issue on my IP Phones. I want to implement VOICE QOS so that my IP Telephones gets high priority and get clear voice without any break. Can anybody guide me on this how can I create VOICE QOS. I have created a QOS with minimum bandwidth of 20MB and maximum of 100Mbps but that is not helping.
Hello everyone,I installed the latest version 7.4.2.1737 of FortiClient VPN, but when I try to connect, the program gets stuck at 10%. It seems like the application adds extra characters to the password field when I click on "Connect" (the field shows more * than it initially did).All updates have been applied. I even installed this https://aka.ms/vs/17/release/vc_redist.x64.exe as recommended on a forum.Regards. Edit: it's working after fresh uninstall.
Hello, we're in the process of planning/implementing application policies and having a hard time understanding matching criteria and how a profile entry behaves with an application policy defined. Looking at a profile based policy and using DNS as an example, I could create an app policy with the block action set for DNS related application signatures and associate that to the LAN -> WAN policy entry which would then block devices in the LAN zone from reaching DNS servers in the public cloud. Is what I don't understand is what happens when you need to apply multiple policies? Say I need to block the entire LAN zone from using public DNS but then wanted to block TeamViewer for a specific network inside the LAN zone. The traffic would process down the list and match the first profile entry (Lets say that's the TeamViewer blocking entry) carrying a DNS payload and that policy isn't going to match application and then allow the traffic out to the internet and
Dear Team,According to the article "Technical Tip: Special Notice for low end units (<2Gb RAM) upgrading to FortiOS 7.4.4 and 7.6.0," or "SSL VPN not supported on FortiGate 90G series models" We understand that FortiGate units with less than 2GB RAM will lose SSL VPN functionality, including the security posture check supported by SSL VPN, when upgrading to newer versions. I would like to inquire about the core reason for this. Will larger models of FortiGate also face this dilemma in the future? Additionally, if larger models also gradually do not support SSL VPN along with the security posture check, what would be the alternative solution?Regards,Bruce Liu
Hello Fortinet Community I have an issue with traffic distribution, the traffic is not distributed evenly between my wan interfaces. I came to realize that the weight of member(2) is not 0 so that I can achieve load-balancing between both interfaces. AlUla-FW # diagnose sys sdwan memberMember(1): transport-group: 0, interface: port1, flags=0x0 , gateway: 10.0.1.1, source 10.0.1.10, priority: 1 1024, weight: 0Config volume ratio: 1, last reading: 4357479365138B, overload volume 227260MBMember(2): transport-group: 0, interface: port3, flags=0x0 , gateway: 10.0.4.1, source 10.0.4.10, priority: 1 1024, weight: 37Config volume ratio: 1, last reading: 2419071026478B, volume room 37MB Can anyone advice on how to change the weight of the second member. Thank You.
Hi, Has anyone tried creating sql query to check bandwidth to specific destination tcp port?
I work with a big governamental network that uses sdwan solution. Recently we are having some issues according to PPPoE debugging. Let's pretend that there are 2 links working in PPPoE mode. Then, when we are trying to debug (diag debug application PPP -1) we don't from what PPPoE interface the logs are coming. Is there some way to find out from what interface is that debugging?
Hi All, URL blocking using both method - FortiGuard Category Based Filter with static url fitler. Scenario 1 : I don't want to block entire category, want to block specific url. >>>>>>> When I am blocking static url in URL Filter then it is working, URLs are getting blocked. Scenario 2: I want to block entire category, want to allow specific url. When I block entire category in fortiguard category filter and in the static URL filter allow the URL (facebook.com) even then it is getting blocked.When I choose exmpt then it is working.Also I use web rating override then it is working. My questions are why URL is not getting allowed when I block entire cateory in Fortiguard category file (social media). which one will be given prefernce during web filtering :Static URL filter or Fortigaurd category filter. thanks
Hi All, We alle share great knowledge here, and in the Knowledge Base.. but it seems like the Search feature has 'gone on holliday'?!?Or have I gone totally blind?I can't find any search feature here on the Support Forum, or on the Fortinet Community page.. do Fortinet expect us to search via external search engines and make a site:community.fortinet.com addition there? That seems like crazy silly... PS: Label is bogus, as there is not Community
i have HUB & SPOKE scenario as shown in the picture with dual WAN connections one is DIA and the Second is private WAN Microwave Network and I configured auto discovery in to WAN interfaces and all spokes can access the HUB and spokes to spokes shortcut come up and suppose the internet VPN is selected first duo to aging time in BGP table when branch1 try to access branch 3 the shortcut tunnel come up and working fine but when the internet interface come down in branch 3 in example the microwave VPN tunnel not start between the branches . how can i configure this scenario to allow fail-over shortcut VPN ?Note the spokes to HUB fail-over working fine and no SDWAN Configured in this scenario and IBGP Multi-path and additional path is configured in all devices and the HUB playing as BGP router reflector
Hello Team,I am seeing something Weird. I am not finding firmware about Fortigate 30G. There is even no possibility to check upgrade path on that model on the fortinet support site. Is it normal ? is there anyone here who ever succeed to get firmware download on FGT 30G. Please let me know, if you have information about it
We currently have two ISPs setup as an SD-WAN on a Fortigate 200 in an HA pair. We need to add a third ISP, but we do not want to make the third ISP a part of the SD-WAN. The third ISP will be used exclusively for a specific internal VLAN and a specific type of traffic. That is, we need to direct a specific VLAN out the third ISP. The specific VLAN only should go out the "third WAN." I found another forum post that seems to indicate that this is possible: https://community.fortinet.com/t5/Support-Forum/Multiple-WANs-for-separate-LANs/m-p/95377#M95287 The VLAN is currently going out our SD-WAN. If I have it correct that such a setup is possible, what are the steps? 1) Add ISP to the Fortigate.a) Configure an available port with info for ISP.2) Create a Firewall policy for VLAN to go out ISP #3.3) Create a Policy Route to direct WAN traffic from the specific VLAN out ISP #3 Does this sound right? Any other considerations/concerns? 
I'm on Ubuntu 22.04.4 LTS with GNOME 42.9 with this Forticlient version 7.2.4.0809When I try to create a new VPN connection, I can see Advanced Settings as described on official docs HERE
Hi, Today I just got an issue on FortiEDR cloud console. I cannot open the event viewer page. It gives me an error message "Events retrieval failure. Transaction rolled back because it has been marked as rollback-only" The other problem is, Google Chrome is being blocked and was in the list of Application Control Manager, so I intend to check on Event Viewer page who added the Chrome into the blocklist, but at the same time I am facing the issue said above.
We are planning to upgrade a bunch of FGT100F to 7.2.10 very soon. The official upgrade path states that this can be done in one single step. Did anyone already do that and did you experience any problems afterwards?Or was that just related to FOS <= 7.0.14 but not 7.0.15 or newer?
Hi, I hope you can help me. Followed this KB: Renew Certificate Expired on FortiGate - Fortinet CommunityRun #execute vpn certificate local generate default-ssl-key-certsentered 'y' to confirm, but I am still seeing that the built-in cert is expired in System --> Certificates The system time is same with my timezone.I can reach FortiGuard servers.Unit is in stand alone mode. Is there anything else which I need to look into? Thank you very much!
Does anyone have a working cleaned config of ADVPN in a Dual Hub setup with BGP on Loopback and the spokes being full meshed to the Hubs? I have everything setup and all tunnels are running, but when it comes to the SDWAN SLA's the Hub1 is currently only utilizing 1 overlay. Tags and Policy routing have been applied. FortiNet doesn't have published configs on this setup (that I can find) due to the complexity however as of 7.0 (running 7.2.8) they do state in their design documents you no longer need the bgp per overlay, but I almost feel like I need to go back to not running BGP on the Loopbacks. Basically just seeing if anyone has BGP on loopback up and running when spokes are dual ISP'd with meshed connections to the Hubs. Super simplified setup:Spoke1 ISP1 -> Hub1 ISP1 net 1Spoke1 ISP2 -> Hub1 ISP1 net 1Spoke1 ISP1 -> Hub1 ISP2 net 2Spoke1 ISP2 -> Hub1 ISP2 net 2Spoke1 ISP1 -> Hub2 ISP1 net 3Spoke1 ISP2 -> Hub2 ISP1 net 3Hub1 net2 and Hub
Hello everyone,I am new to FortiClient EMS and currently in a roll-out state. How do I prevent unwanted computers from connecting to the EMS? (EMS on-prem, running in a DMZ and public available to the internet) In theory someone can install FortiClient and connect to our EMS.I do install FortiClient for our users because they do not have admin privileges - so I did not enable user verification. Is there any other way to prevent unwanted devices from connecting to EMS?
hi,i'll be refreshing HW and will migrate our cisco ASA to FGT.my questions are: 1.our ASA environment is a context-based/multi-tenant FW, so when i create a new VDOM, do i always choose "central NAT" since it's closer on how ASA is implemented? 2.we have an ASA context solely used for IPSec VPN. do i also choose "central NAT" in this scenario? 3.can i create a new VDOM directly on the FGT device or is it best practice to do it via FMG? 4.i'll be ordering a forticonverter license to help with my ASA migration. is the result/conversion 100% accurate? or do i still need to manually inspect the output/config? 5.after i converted the ASA context/config in forticonverter, how do i apply the config on a FGT? do i apply the config directly on the FGT device? or via FMG? apologies for all these questions since it will be my first time converting ASA to FGT.looking forward to your reply. thanks in advance!
Hello,I noticed a difference in the log view behavior after upgrading to FortiAnalyzer 7.6.1.In the current version (7.6.1), when I access the "Log View" section, all logs from my FortiGate devices are grouped together, without an immediate distinction between different devices.In the previous version (7.2.3), logs were displayed in a cascading format, and on the left side, it was easy to identify the originating FortiGate for each log entry.This change makes it more challenging to quickly locate logs from a specific device. Is there an option or configuration to restore the previous view?Thank you for your attention.Best regards,
Hello,I recently performed a fresh installation of FortiAnalyzer and am encountering an issue when attempting to add a secondary hard drive. Despite following the documented procedures, I am unable to complete the operation.Specifically:When using the "execute lvm extend" command, the process does not yield any meaningful result.The "execute lvm info" command returns the message "unavailable" on the disk 2I have verified that the added hard drive is visible at the hardware level, but it seems that FortiAnalyzer does not recognize or properly manage it through LVM.Could you please provide guidance on how to resolve this issue? Thank you for your support.Best regards,
i have a set of public urls which are required to be VA/PT scanned by an external agency.. the problem is when the traffic gets initiated from the PT server i can see traffic getting blocked in fortigate via an IPS profile mapped in the access policy..i then added the IP of PT server in exemption list post which there were no IPS deny logs ..however, there are logs with 'blank" action and a message of server-rst... there is no issue with application at the same time as it is working fine as checked from a diff system.. i am suspecting a setting in fortigate which is seeing this as an attack but cant figure out what it is.. anyone faced a similar issue ? any help is appreciated. thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.