Mark a Best Answer
Fortinet Community
Recently active
The FortiEMS server is running version 7.4.7, while the client version on the workstations and servers is 7.4.5.We plan to upgrade soon.In the clients' "Notifications" tab, I see many "Patching Failed" alerts.The installers were never created with the "Auto update to the Latest Patch" option enabled."Automatic Patching" is also disabled in the Vulnerability Scan settings.We never perform upgrades or patching automatically; we prefer to manage that process ourselves.So, what is triggering these "Patching Failed" alerts?Thanks
URL: https://incoso.co.za/>> This is a false positive. incoso.co.za is the legitimate website of INCOSO (Inhouse Conference Solutions), an established South African event-management company operating since 2007, based in Bellville, Western Cape. The site contains standard business content only: company profile, services, portfolio, testimonials, and a basic name/email contact form. It has no login area, no password fields, and no payment processing, so there is no phishing surface.>> We believe the detection originated from Avast Web Shield running on the machine of the web administrator who deployed the site. During go-live there was a brief window before the site was fully configured and secured, and we believe Avast automatically sampled the site in that state and submitted it to your cloud database, classifying it before the finished, live site existed. The live production site has been complete and secure since launch.>> Avast/AVG is flagging both the homepage a
Hi community,i have in office Fortigate with ip public 87.xx.xx.xx, policy created for internet, I created in windows (PC office)- vpn client conection l2tp other ipsec for conect to mikrotik(home) ip public 193.xx.xx.xx .Issue is when i try to conect vpn windows(client) to mikrotik(server l2tp/ipsec) this conection is down ,but when i try conect pc office to hotspot vpn l2tp/ipsec conection is successfully to mikrotik.Can anybody help with this issue,why my pc canont conect l2tp/ipsec to mikrotik? beetwen MIKROTIK and FORTIGATE not set ,not config any vpn,mikrotik is outside, is in my home.
Hello Community, I hope you're well I stay in process to deploy Fortiweb 400 F, but I have doubts about whether it is advisable to place the Frontend and Backend interfaces in separate VLANs, and if you recommend this topology for a future deployment of Adoms, or if the design should be rethought.I attach the Topology.Greetings!!!!
Can anyone confirm me if FortiGate 70G Firewall requires a separate license to operate or does the product comes with a base license when purchased new.
Hi FWB adminsAccording to FWB’s CLI ref we can access to traffic logs and attack logs via CLI.https://docs.fortinet.com/document/fortiweb/7.6.6/cli-reference/561209/logThe user is admin and its profile is prof_admin (has all rights).However when the mentioned command seems not available.fwb01 # diag log all startParsing error at 'log'. err=1Command fail. CLI parsing error.Any idea?
We manage a multi-branch network with FortiGates centrally managed via FortiManager, all running the same policy package. At specific branches, users attaching 2-3MB files to email through OWA (Outlook Web) experience 20-30 minute upload delays, while other branches on the identical policy are unaffected.Our SSL/SSH Deep Inspection profile already exempts the Finance & Banking and Health & Wellness categories, plus around 20 Microsoft/Outlook-related FQDNs. We confirmed via FortiManager that this exempt list is identical across affected and unaffected branches. Setting the policy to "No Inspection" resolves the issue immediately, confirming deep inspection is the cause.Since the exempt list is the same everywhere but the problem is branch-specific, we suspect some URLs or hostnames used by OWA for attachment upload (possibly Microsoft's Azure Front Door / M365 substrate/CDN endpoints, not just outlook.office.com) are missing from our exempt list and differ depending on branch e
I'm lab testing a few different ADVPN setups and noticed the Cross-regional spoke to hub shortcuts:https://docs.fortinet.com/document/fortigate/7.6.0/sd-wan-architecture-for-enterprise/242856/using-ibgp-between-regions-with-inter-region-advpnThe docs are missing at lot of details so I'm wondering if anyone knows how this dynamic tunnel from Branch 1 (Region A) to HUB in region B is created? Which tunnel interface is used on Region B HUB.Does the static VPN tunnel between the hubs need any ADVPN specific config rather than just standard static tunnels?I have dynamic tunnels working ok within the same region so I have a basic understanding of how the tunnel is formed. Just not clear on when it comes to Multi region, specifically the SPOKE to the HUB in the other region.
Hello, I opened a case with support asking about a 7.4.4 version of Forticlientvpn only for windows , they suggested we post here. My questions are:1) Is there a version of forticlient vpn only 7.4.4 coming out for windows?2) If no can you verify if forticlient vpn only 7.4.3 for windows is not susceptible to https://fortiguard.fortinet.com/psirt/FG-IR-25-685 Thanks!
We use the fortiPAM solution, but it only works in a web browser (so it won’t work on servers and will most likely be useless in this situation).Is there another way to grant access directly from the Linux console? For example:Would it be possible for the company to install FortiClient on Linux (Red Hat or Oracle Linux) and configure FortiGate to grant them access only to selected subnets?It’s the simplest idea I’ve come up with recently. Since FortiPAM is useless for running on a server without a UI, I suppose this would be the best solution.The only question is, will FortiClient work in such an environment?
current version start from 6.0.18My current version of FG-60E is 5.6.10 how can I upgrade this to 7.4.11?there is no path of 5.6.10~6.0.18
My Fortigate device is out of support, and is currently running 7.4.8.It has started to attempt upgrading to the latest patch (7.4.9) as per the new upgrade mechanism: https://docs.fortinet.com/document/fortigate/7.4.0/new-features/320693/automatic-firmware-upgrades-for-fortigate-appliances-with-invalid-support-contracts-or-that-have-reached-end-of-support-7-4-8 However it keeps failing and sending emails that it has failed.logdesc="A federated upgrade could not be completed by the root FortiGate" msg="Federated upgrade failed after reaching state downloading" reason="download failed" Its sent that one a few times, is now also sendning emails regarding the schedule being changed: logdesc="Automatic firmware upgrade schedule changed" user="system" msg="System patch-level auto-upgrade new image installation (re)scheduled to between local time Thu Oct 23 01:42:23 2025 and local time Thu Oct 23 04:00:00 2025. This installation is forced and cannot be cancelled." Do
Is it possible to send traffic from Fortigate-1 InterVDOM to Fortigate-2 InterVDOM ?. I have LACP routed interface between Fortigate 1 and Fortigate 2, both firewalls can ping each other.Both are running FortiOS 7.4.11. Fortigate 1,all lan ports are LACP with multiple VLAN uplinks from switches. Fortigate 2,multiple interVDOM links created between rootVDOM and cust-1 to 3 VDOMs. interVDOM link interface for rootVDOM is configured as 0. customer VDOMs, static routing & firewall policies are created to respective interlink. root VDOM, static routing and firewall policies are created to Fortigate 1 and other VDOMs on this Fortigate. When i try pinging from customer VDOM to Fortigate-1 VDOMS, it keeps on looping on InterVDOM link of respective customer VDOM. In a nutshell, can’t reach between VDOMS of both Fortigates. I’m using “ethernet” instead of “ppp” and segments from APIPA range((169.254.0.0/16) for interVDOM link. What i’m trying to achieve, is it supported ?. Am i missing any
I have a FortiGate 600F firewall, and I would like to configure logging and reporting so that all logs and reports remain within my organization's infrastructure and are not stored or processed outside the organization (e.g., in the cloud).What is the easiest and most appropriate solution to achieve this? Could you please explain the recommended approach and provide the implementation steps?Thank you.
I have already completed the configuration of my FortiGate firewall. However, I now need to enable and configure VDOMs and divide the firewall into multiple VDOMs.Will enabling and configuring VDOMs at this stage affect my existing firewall configuration, policies, interfaces, routes, or other settings? Or can this be done safely without impacting the current configuration?Are there any important considerations, best practices, or precautions that I should be aware of before enabling and configuring VDOMs?Thank you.
Has anyone seen this on a 6300F or 6500F? Looking for a cleaner fix than rebooting the FPC.Specifically wondering:1. Is this a known bug in 7.6.x with a fix in a later build?2. Is there any way to reclaim kernel slab memory without rebooting the FPC?We had an incident last night where FPC1 on our 6300F started dropping packets after about 16 days of uptime. The other 5 FPCs were completely fine. Rebooted FPC1 and everything came back to normal immediately. The log message we saw:fw_forward_handler line=788 msg="The system is in extreme-low-memory state. Drop the packet."When we dug into it with diag hardware sysinfo memory we found the problem — SUnreclaim on FPC1 had grown to 22GB while every other FPC was sitting at around 600MB. MemFree on FPC1 was down to 2%. At incident:FPC1 - SUnreclaim: 22,029,000 kB :warning: - MemFree: 692,292 kB (2%)FPC2 - SUnreclaim: 626,632 kB - MemFree: 21,902,960 kB (66%)FPC3 - SUnreclaim: 621,352 kB - MemFree: 21,918,292 kB (66%)FPC4 - SUnrecla
When the device connect to the network and if the persistent agent uninstalled then how we can block the access?I try simulate even the PA was uninstalled the device can connect and PA status showing green in the host.
Hi guys,I’ve been assigned a project where I need to migrate an existing Fortinet SD-WAN environment BGP on overlay to BPG on loopback, and I would like to gather feedback from anyone who has already dealt with a similar scenario because i did not find documentation about this process to be honest.The current setup consists of a dual-hub architecture where SD-WAN is implemented with BGP running directly over the overlay, using IPsec tunnel interfaces.All routing decisions are tightly coupled with SD-WAN members, and the entire environment is running FortiOS version 7.6.7 on both hubs and spokes.The target design is to move away from BGP on overlay and go to BGP on loopabck.Since I have not found much detailed documentation covering this specific migration path, I am trying to better understand the best approach before proceeding.In particular, I am interested in knowing whether it is feasible to have a parallel environment, i have 100 sites, so is it possibile to migrate a couple sites
How do I Configure server to reject HTTP/1.0 requests with "505 HTTP Version Not Supported" status and enforce minimum HTTP/1.1 protocol version? I am using Fortigate 60f and I need to make necessary changes so that my Merchant Service PCI Compliance passes. This is the last setup that I need and would like to make the fix with GUI, not CLI. Any help would be great appreciated.
Greetings,I am trying to find relevant documentation on how to configure rds nps to communicate with forti authenticator as a 2fa method.Thank you in advance for your support.
Dear Technical Team,I am writing to report an issue regarding TightVNC connections established through FortiPAM when using a guest user account.Issue DescriptionWhen attempting to initiate a TightVNC session via FortiPAM using a configured guest user, the connection fails to establish. "connection has been gracefully closed".Normally we succeeded in web VNC. But we face issue while using TightVNC with guest user.Environment DetailsFortiPAM Version: 1.8Could you please assist in verifying if there are known bugs regarding guest user token lifetimes, or specific configuration policies required to allow guest access for VNC proxies in this firmware version?Looking forward to your guidance.Best regards,Dev Singh KhadayatSystem EngineerGrantha Networks Pvt Limited
Hi Fortinet Community,I need some advice regarding FortiClient on a Linux server.EnvironmentI am using:OS: Ubuntu Server 24.04 without GUI Use case: connect to an external partner’s VPN The partner only supports clients using Fortinet VPN client Current package: FortiClient VPN-only 7.4 for Linux Previous package: I previously installed the paid FortiClient edition version 7.2 from this page: https://www.fortinet.com/support/product-downloads/linuxPreviously, I installed the paid FortiClient edition, but the VPN could no longer be used because there was no license. Since I only need VPN connectivity to the partner, I replaced it with the FortiClient VPN-only version. I currently connect using a command similar to:forticlient vpn connect vpn-profile -u users-vpn -p -w -a -sThe VPN connection can be established, but I am facing several issues and have some questions. QuestionsImpact from previously installed paid FortiClient Since I previously installed the paid FortiClient version 7.2,
Dear communityI likely have a very specific issue that might be completly "normal", I just want to make sure I have my bases covered... Situation:We have two clusters (four fortigates in total) in two different data centers (dc 1 and dc 2). About a dozen of VLANs are connected to both of these two clusters and we use VRRP spanned over these vlans to ensure usage of both clusters.The first three IPs in each vlan is ours - the .1 is the VRRP IP that is active on the master, .2 is the cluster on dc 1 and .3 is the cluster on dc 2. Now we run into asynchronus routing with a specific use case:There are location specific networks (one for dc 1 and one for dc 2) that access the respective local fortigate cluster and are allowed access to the attached vlans.If you happen to be in the location where the VRRP master is, then everything works. You can access the local fortigate cluster (which is vrrp master) and access the hosts in the vlans. No Problem.If you happen to be in the other
My organization has been using FortiClient free version for the past 5-6 years. I have been following the semi-official deprecation of the free version for the past few months. We have been using 7.4.3 now for a few weeks.Now FortiClient 8 has been released and I see no free version (what I assumed would be the case).Quantum Cryptography is becoming front and center in planning for our future with Google and Microsoft saying they should be fully or mostly using PQC by end of 2029. Naturally, FC 8 has PQC support.I wonder what everyone else who is or recently was using the FC free version is planning to do.I know we could get a license for on-prem EMS (but that would be another server to setup and maintain for our small team and there were just two high profile vulnerabilities in it just a couple months ago), or get Fortinet Hosted EMS (but not sure of the price with that), or drop FC altogether and go with a different VPN solution or SASE option etc.We have two dialup IPsec tunnels rig
Hi Fortinet Team, FortiClient EMS certificate not authorized..I am experiencing an issue connecting my FortiGate-90G to an On-Premise FortiClient EMS server via the Fabric Connector. The connection fails with certificate verification errors.Environment Details:FortiGate Model: FG-90G FortiGate and EMS Location: Both devices are in the same local subnet (192.168.2.x). DNS Setup: Configured via a Local DNS Database entry on the FortiGate, pointing the FQDN to the local EMS IP. Pings to the domain name resolve correctly. EMS Certificate: A valid Public Domain Certificate issued by RapidSSL / DigiCert (Domain: winxsfp.com). Symptoms & Errors Observed:The Fabric Connector GUI shows an "Untrusted Certificate" status. I have disabled strict common name checking using the set trust-ca-cn disable command under config endpoint-control fctems, but the issue persists. Running the verification command in the CLI results in the following error output: text FortiGate-90G # execute fctems verify 1
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.