Mark a Best Answer
Fortinet Community
Recently active
Hello, Being new to the Fortinet ecosystem, I am not yet familiar with all the details of the FortiManager solution. However, I have installed the FortiManager VM with a trial license to perform tests in preparation for future use with a full license.I have two FortiGate 30G devices running the latest available firmware version for these models: 7.2.8.They are properly "synchronized" with my FortiManager, but when I make a Policy modification and push the changes using "Re-install Policy," an error occurs.In the "Preview" before the push, I can clearly see the test modification I made and only that modification. However, later in the "View Installation Log" file, new commands are added, which causes the error. The Policy does get successfully pushed, but this creates a configuration "conflict" with each push due to the additional commands/checks. Starting log (Run on device) Start installing FortiGate-… $ config firewall policy FortiGate-… (policy) $ edit 20 FortiGat
Hi, I am trying to configure LDAP for user authentication against AD. This works fine for users that are directly member of the group that is mentioned in the User Group configuration. The design, however, is that a user is member of a Role and the Role is member of the group. When I have this configured in AD it does not work anymore. When I make the user a direct member of the group again it works. How to get this working? Regards, Wim
Hello, Customer has FortiGate + fortiap deployments at all of their locations (around 22 and growing). We used to use windows NPS for 802.1x, recently we switched to Fortinac (Fortinac-f 7.2.8). Everything works as expected. But the problem is in the FortiGate GUI, wifi-controller -> wifi clients section we used to view user information as Domain/username (COPMPANY/USER1) After the transition, half of the users started appear as Domain/computername FQDN (COMPANY/PCHOSTNAME.COMPANY.LOCAL) Both type clients work fine, but this makes IT support a bit tricky since they are mostly using usernames to check on users. Is there a reason for this to happen? If it was for all users, than I would say ok there is ma parameter to deal with. But having some users with usernames and some users with hostnames is a bit confusing. Regards,
Hi, guys, I am using Fortigate 400E, 600E with FortiOS v6.4.2 and V6.4.4. For some reasons, my company perfers GRE tunnel. It is found that the poor performance SLA of the GRE tunnel between two fortigates ( often some percentage of packet loss often found, while the internet lines are running well - no packet loss ), any advice, thx a lot ? Any article/doc to fine tune the GRE tunnel parameters/attributes ?
Hello, i read and applied the documentation but the issue is that i cant obtain the permanent VM trial license from FortiCare. I cant conatin the "account-id xxxx@fortinet.com" "ccount-password xxxxxxx" Trying from the cli: "execute vm-license-options account-id xxxx@fortinet.com execute vm-license-options account-password xxxxxxxexecute vm-license."  
Hello, I'm configuring ldap server on a fortigate v 7.6.x.The ldap server is behind IPSec VPN. The clients on the LAN already contact the server in question as they have made domain joins and use that ip as the DNS of their network card.When I go to configure the ldap bind to ‘ip_LDAPServer’ on port 389 this fails. Do you have any suggestions? Thanks fort the supportBR
Hi, Is it possible to create a usage quota (either time og amount of data) for a policy.If you, please advice me how to do this in the gui.I am using a Fortigate 81E-POE with firmware 7.2.2 Thanks. /Kim
FG-Version: 7.2.10 Hi Community, I’m looking for help on how to disable logging for specific policy rules in Fortigate devices that are part of a security fabric. I’ve tried changing the rules, but it hasn't worked. Has anyone figured this out? Any advice would be really appreciated! Thanks!
Hello everyone, While upgrading FortiClients on Debian-based machines, I encountered a problem that I would like to share with you here to find possible solutions or workarounds.In the official Fortinet documentation for FortiClient version 7.4 for Linux-based systems (https://docs.fortinet.com/document/forticlient/7.4.2/linux-release-notes/213138/install-forticlient-linux-from-repo-fortinet-com), the following command is given to add the GPG key for installation on Debian-based systems:wget -O - https://repo.fortinet.com/repo/forticlient/7.4/debian/DEB-GPG-KEY | gpg --dearmor | sudo tee /usr/share/keyrings/repo.fortinet.com.gpgWhen execute the following error is shown:Connection established to repo.fortinet.com (repo.fortinet.com)|208.91.114.61|:443 ... connected.HTTP request sent, waiting for response ... 404 Not Found On Fortinet's official download page for version 7.4 (https://www.fortinet.com/support/product-downloads/linux ), Debian-based distributions are not sho
Greetings, we're currently trying to build our new IPsec VPN Config coming from SSL-VPN.While reading the XML Reference Guide for configuring IPsec i stumbled upon an Inconsistency on "implied_SPDO" The "<implied_SPDO>" and the "<implied_SPDO_timeout>" literally contradict each other.For example on: https://docs.fortinet.com/document/forticlient/7.4.2/xml-reference-guide/96295 (however its the same on all Versions that i looked at) implied_SPDO states that Internettraffic is allowed when its set to 1.implied_SPDO_timeout however states that "FortiClient blocks all outbound non-IKE packets when <implied_SPDO> is set to 1" and "Thus, setting <implied_SPDO> to 1 may have the side effect of blocking access to the captive portal, which in turn blocks access to the IPsec VPN server" Which makes no sense, according to various KB Articles here this looks like that non-IKE packets are allowed whe
Hi, in case any banking customer located in particular country and while initializing Fortisase portal we select same country pop only. Can we select additional pop location later on as per the requirement ?Also what to do if there is no logging pop location within the country. As customer belongs to banking sector will not allow to select logging to another country's pop.Pleas guide..
Hello, I have some old Fortigate equipment that need the latest version of the firmware, and I just noticed that Fortinet does not provide it until I have a support contract. Is this true? and I need to purchase the contract to download it for my old equipment?
Refer to the list:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-FortiOS/ta-p/227178 May I ask why there is still no FortiGate model recommended to use FortiOS 7.2 and 7.4? FortiOS 7.0 is nearing its End of Engineering Support (EOES) (less than 5 months from now), and for some latest vulnerabilities the 7.0 patch this time (7.0.13) was released slower than the 7.2 patch (7.2.6). We usually upgrade version branch before EOES of our currently-in-use branch. But this "recommended list" is giving us concerns.
Hi,This morning i get complained from my users they cannot connect the VPN client. This weekend The FW installed automatically (never turned on auto install) the latest 7.4.X firmware which is 7.4.7.My FW configured with Entra enterprise app to use the 2fa.The users got stuck at Forticlient 48% with error stating there is an error in password or permissions -7200.Reverting back to the 7.4.6 fixed the issue for now https://100001.onl/ .Also oddly enough the connection was "connected at the FW , but disconnected at the Forticlient. There was an error under username in the FW: Two-Factor Authentication is not enabled.Anyone else see this?
Hello guys, I have a cluster configured to ask users authentication using Entra ID account. This is working when using host connected to an interface that is directly managed by Fortinet (and it creates the local in policy for port 1003), but I need to make it works also from a routed subnet that is passing thru a transit interface (it’s an MPLS line), but the redirect doesn’t work for this interface. I've created the zone and relative rules, but nothing to do. any suggestion? thanks in advance!
Hi everyone, recently I did fortinac enforcement to my environment, first I integrated the NAC with my fortigate, and then I checked that all machines are okay getting the right policy and right VLAN. After I did the enforcement it starts shows some agent connection errors, and machines getting the wrong vlan policy because of that connection error. how can I do troubleshooting, as before enforcement machine was able to communicate with NAC, after enforcement it was assigned to Reg-VLAN because no connection! Im sure there is a policy to all all traffic with all services and ports.Im sure the machine has Agent installed and 802.1X configuration. other machines in the same branch working fine as you can see on the below screenshot. only some getting that weird error. any advice?
FortiNAC Trying to wrap my head around what happens if a remote site goes down and cannot reach FortiNAC ? I'm assuming that the existing switch or AP config will remain in it's current state... What happens when a rogue host tries to connect to the LAN ?What happens when a registered host tries to connect ? Any other considerations ? Thanks !
Hi everyone, I do have Fortigate, Foriswitch, and FortiNAC in my environment. I did a normal LLDP profile on my fortigate to let Fortiswitch handle my cisco phones and data vlans. it was working fine. I have created custom LLDP profiles named "LLDP-Prof2" can see it at below and all are okay till now. The issue once I do NAC enforcement and add NAC security policy on fortiswitch, nothing works fine till I change the LLDP profile to default !! which is confusing me. I have open ticket with Fortisupport but unfortunately NAC team asking to check with the switch team and switch team do the same and till now no one has advised me about that kindly if anyone can help and explain how LLDP affects and the relation between LLDP and NAC. The reason that I need to understand if there is something wrong in my config, to avoid any issue when I do need to remove NAC enforcement as again I have to change from default to my custom LLDP prof. my LLDP Config:config switch-controller lldp
Hi everyone, I am encountering an issue with FortiAnalyzer while generating my report. Many IP addresses are displayed without their corresponding hostnames. I attempted to use Subnets, but it did not work as expected. My task:that every IP in report will has "descriptions" (They will be signed) Does anyone know how I can achieve this? Any guidance would be greatly appreciated.Thank you!
Hi, I read that the NP6XLite processor ensures hardware acceleration of network traffic, which enables the processing of large volumes of data without heavy CPU load. This acceleration mainly applies to basic functions such as routing, NAT, IPsec, and firewall, and advanced functions such as UTM (for example, antivirus, web filter, DLP or IPS) usually require the intervention of the main CPU, since the hardware acceleration on the NP6XLite is not optimized for these more complex processes. When hardware acceleration is enabled and UTM rules are applied, there may be situations where some traffic is not redirected back to the CPU and UTM rules may not be applied correctly.But is it correct? I thought that NP6XLite is used for UTM functions such as IPS, web filter, etc.
I have a site-to-site VPN setup between two Fortigate fws. This VPN has been setup for years and have had no issues. Yesterday, I lost the ability to communicate to either LAN between the VPN. The tunnel shows as up on both sides and I've tried rebooting, resetting the connection, and still nothing. Before yesterday I could communicate successfully between both sites but now nothing. It is also an IPsec VPN. Any ideas? I also have other VPNs on each firewall (none other are Site to Sites) and they each work. Version 5.6 on one side and 7.4.3 on the other.
Hi all, As you can see using % 45:45:10 here. And now one "45" is offline. So, what is the correct current %:% for the remaining TWO interfaces? Thanks,
Is it possible to configure Fortigate to use Fortiauthenticator with MFA and AD authentication, with NTLM v1 disabled on DC's ?With ntlm v1 enabled everything works fine, but with v1 disabled, authentication fails with error :Windows AD user authentication(mschap) with no token failed: AD auth error: Logon failure (0xc000006d)Login to fortiauthenticator works fine, with AD account, but when trying to login using vpn client, it fails.
Hello In a multi regional setup where site-to-site ipsec tunnels between hubs are establish ed, I am trying to use embedded sla information between them to signal best ipsec tunnels. Like one being spoke from the other. The issue is that hub with "detect mode remote" doesn't see any sla information in the " diag sys sdwan health-check remote" although it is received from spokes. Configuration is the same, the only difference could be the type of tunnel? Any help appreciated Best regardd
FAP-441K APs have two 10/5/2.5/1 Gb RJ45 network interfaces. But, does Fortinet make a PoE switch with a 10 Gb RJ45 port that also supports MCLAG? If they don’t….why put 10Gb in the APs? Best I could find was the FS-648F-FPOE where 16 of the ports are 5Gb RJ45. Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.