Mark a Best Answer
Fortinet Community
Recently active
May I create two different ssl-vpn portals with two different ports? For examples 10443 and 11443.
Hello, Fortigate 600 v7.2.9.Ports 1 and 2 on the Fortigate are not yet in use. I activate both.I plug PC1 into port 1 and PC2 and port 2.Should the two PCs be able to talk to each other now (of course I gave them both an IP address from the same network)? So are they in the same Layer 2 network?Or do you have to tell the Fortigate that ports 1 and 2 should be in the same vLAN, so to speak.I'm not actually talking about ports, but rather aggregates, but the logic should be the same. ThanksAlbMin
Hey everyone,so, I got the impression that many of you on this sub are migrating from SSL VPN to IPSEC VPN for remote access due to recent CVEs and Fortinet giving off the impression of preferring IPSEC VPN as well (removing it from smaller appliances, etc.).Thing is, most of our customers (not necessarily using FortiGates even) migrated to SSL VPN years ago due to specific reasons, for example:- IPSEC RA-VPN not working well in public places/hotels because it is usually blocked there- IPSEC RA-VPN having problems with home office users that are being NATted from native IPv6 to IPv4 which in some cases breaks IPSECSSL VPN being much more robust in those cases. What's your take on this? Just interested to see different viewpoints here
Hi all,it's possible to create an email warning message (on the fortigate or fortianalyzer) when the interface limit has been exceeded over 2 minute? Thank's in advanceMaurizio
Dear community, anybody using Fortigate API to retrieve log traffic with this endpoint : /api/v2/log/disk/traffic/forward/system?filter=srcip==10.227.108.88&rows=10 I can get logs for a specific source or destination IP, but do you know anyway to get logs for a network ( example : 10.0.0.0/8) ? Running version :"version":"v7.2.10","build":1706 Thanks in advance for your help ;) Looking the FortiDev documentation, only available filters are the following, but they didn't make the trick to filter on network after several test : filterarray[string] (query)Filtering multiple key/value pairsOperator | Description== | Case insensitive match with pattern.!= | Does not match with pattern (case insensitive).=@ | Pattern found in object value (case insensitive).!@ | Pattern not found in object value (case insensitive).<= | Value must be less than or equal to pattern.< | Value must be less than pattern..>= | Value must be greater th
Team, I have all the required licensing for FortiSASE (advanced, SPA etc) and have a requirement to provide access to private resources (RDP) for contractors (non-managed devices). Before I go down this route, is this a supported configuration using agentless ZTNA? Or am I better placed to leverage a different solution?TIA.Justin.
Hi this amazing community!I am pretty new in Fortinet world (from basically cisco background). Company advised to see alternate vendor so i am considering Fortinet stack as better fit for us. I know its more like consultation questions but want to hear from you all based on your experience:1. Can we configure front door VRF in ADVPN like in DMVPN? main reason is security (separate internet and local traffic on vrf level). My thought is we probably don't need VRF as its firewall where we can enable security feature on public line but my manager pushing for front door VRF to separate traffic saying security reason. 2. Can we assign Public IP behind the FortiGate (without NAT) device? We will gone have PA for client VPN (for at least 1-2 yrs).3. Can we assign multiple Public IP on a WAN interface? we have 2 block of /29 public from a provider and another /32 just for internet. from that two /29, some service needs direct public IP (like client VPN) and some other services just
Hello Team,We have a cisco switch in our environment and want to configure 802.1X user authentication through Active Directory.Necessary configuration has been done on cisco switch and also on fortinac but the user is not able to authenticate. Switch logs are shared below:Jan 23 11:21:31.767: %AUTHMGR-5-START: Starting 'dot1x' for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %DOT1X-5-FAIL: Authentication failed for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (d0bf.9c0f.2698) on Interface Gi1/0/24 AuditSessionID C0A8018C000000ED06B56251Jan 23 11:21:47.143: %AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client
Hello, I am looking for older version of FortiClient VPN version 7.0.8.0427. Can someone please help me with the information about where I can get the software.Thanks,VRG
Hi I am in the process of upgrading our devices to v.7.2.x. I have already upgrade FortiManager and FortiAnalyzer to v.7.2.9 with no issues. I have now upgraded one of our FortiGate HA clusters to v.7.2.10. When I go to install policy, this fails. It appears to be trying to reconfigure a wireless-controller vap. The response I get is:---------------------------------------------------------------------------------------------------------$ unset voice-enterprise$ unset dynamic-vlan$ unset mpsk-profile$ nextCurrent passphrase is invalid. Must be 8 to 63 characters long or 64 hex digits.object set operator error, -651 discard the settingCommand fail. Return code 1---------------------------------------------------------------------------------------------------------I'm not sure why it is trying to reconfigure this vap. It has the same settings as other vaps. The settings in FortiManager appear to be the same as configured on the FortiGate itself, so I'm confused as to why it is tryi
I need help please: I have fortigate 601e firmware v6.2.3 my problem is the traffic that comes from the FortiGate is going outside the GOOGLE DNS, use the dot interface IP address point -to-point for more security I want to use the Nat service for this type of traffic. I can't find how. can someone help me please?
Dear allWe are trying to optimize our SD-WAN solution for Office 365 traffic steering.We are in China. We'd like to route all Optimize category of Office 365 traffic from this article to use our local internet egress while route other Office 365 traffic to our offshore site utilizing their egress in West Europe. So, the question is, which following ISDB object is referring to all other Office 365 traffic from Fortigate object list? is it Microsoft-Office365, Microsoft-Office365.Published, or even Microsoft-Office365.Published.Allow? Basically, we just want to find an object covering all of the O365 traffic so it can address all traffic after the Optimize.
Hi!I seek clarification on the feature Protecting an SSL server (aka. firewall ssl-ssh-profile's server-cert-mode is "replace").Is it mandatory that the specified "Server certificate" (in SSL/SSH Inspection Profile) be identical to the actual server certificate - yes or no?Thanks! PS. Plausible example where I'd prefer that "Server certificate" is NOT identical to actual server certificate is when I prefer it be a wildcard certificate (thus valid for multiple servers within same domain).
I tested SSL-VPN and IPsec Remote Access with Fortigate VM Evaluation.But,it didn't work both.Is that Evaluation limitation?I found Restrictions,as "Support low encryption operation only",that means I can't use SSL-VPN and IPsec Remote Access?
Hello guys, this is my first time working with Fortigate appliance. I’ve a cluster of two F201, with two IPSec tunnel, one with Azure Cloud, and one with an external customer with a WatchGuard firewall. Azure tunnel has no issue (strange :grinning_face_with_sweat:), while the other one has a very particulate behavior. Both of them in IKEv2 with AES256/SHA256. If I start a ping from local to remote side using that tunnel, there is an high packet loss, but after about 40s of pinging the tunnel become stable, until it goes back to idle, and again another 40s and so one. It’s not a phase 2 flapping, because from the diag the SA is up for hours. What I’m missing?Any help is really appreciated thanks!
Hello, Fortigate v7.2.9.How can you display the MAC address table? I don't mean the arp table, I know the command. get system arp ThanksAlbMin
Hello community, I have the following scenario:I have my FGT with 2 WANs (Comcast + T-Mobile). I need to create 40 site-to-site VPNs to different locations. These remote sites only have one WAN.At the remote sites, I plan to create a VPN to WAN1 and another backup VPN to WAN2 on my FGT. Is there a way to configure the FGT to use both WANs with just one VPN per site, avoiding the need to create a second VPN to each location? ThksDamian
I am trying to set up mlag from my core fortigate 1024E switches to a unifi 48 pro poe device using fiber connections.We were able to get the connection to work at one point for about 15 minutes. Someone made a change and it stopped working. Currently the config of the mlag on the Fortiswitch side is:edit mlag 6set mode lacp-passiveset mclag enableset lacp-speed fastThis is direct from CLI on the switch since we had a short time of mlag working all changes have been on the fortiswitch side. I am not sure what change was made because I am not sure what the config was when it was working.Any pointers would be helpful
Hi can this post be unarchived i need the info as its a bit unclear how to enable it as its grayed out.https://community.fortinet.com/t5/FortiClient/Technical-Tip-Enable-IKE-v2-in-IPSec-on-FortiClient-MacOS/ta-p/371314
Our set up was working before.main branch - 2 DNS servers - Main Fortigatethen over the internet to our other branch Fortigateswith the accidental removal of the DNS server, then restoring from back up the server is back and connected back in our network. No settings were changed on the branch Fortigates and everything looks good on the main Fortigate. unfortunately the branch Fortigates all say our specific DNS servers are unreachable.Can someone point me in the right direction?
I can't find the right configuration.I can successfully authenticate users using Entra ID and firewall policies.However, what I want to achieve is to have a rule that allows traffic for unauthenticated users and several rules for authenticated groups (Entra ID). I don’t see the option for a captive portal that allows on-demand SSO authentication.It’s possible that I’m thinking this wrong since we migrated from Sophos XG, where you could log in to its captive portal and authenticate with Entra ID SSO.Any help will be appreciated
Setting up a CCTV system on the network that can be accessed by a mobile app. Manufacturer states certain ports must be opened to allow the mobile app to speak with the local server on the NVR. Tried setting up a policy allowing this through those ports but the mobile app still won't connect and I spoke with TAC who said I probably have to have a static IP for the policies to stay up. He helped me set up a Virtual IP. This is for a home network and the ISP won't provide a static IP for a residential set up. Actually the ISP seems to stay static for a while so I wouldn't mind too much just changing it on the policies if the IP changes but I can't even get it to connect with the current one - that's probably a separate issue. Puzzling because I had almost an identical set up with my old system and it seemed to work fine with the mobile app speaking to the NVR. A Ring system with an alarm base station and wifi cams also seems to work fine with the mobile app receiving alerts and notificat
I am taking an ethical hacking course to learn more about security and currently have a Fortigate, Fortiswitch and Fortiap which has proven to be very effective in providing a secure environment against someone with malicious intent. I'm just nervous about security risks in using this in a "lab" environment. If I read up basic security precautions am I exposing myself to a lot of extra risk? I feel as though learning about the tools will make me safer in the end but I don't want to risk exposing my network if there is no way to safeguard my learning experience. Would it be safer to use Kali in the browser version (I understand it is much more limited). Should I wait until I learn more about network security as in "if you have to ask..."
LS,I'm trying to install a new GUEST SSID using the fortimanager, 7.2.8.------- Start to retry -------- FW003 $ config wireless-controller vap FW003 (vap) $ edit "WK-GUEST" FW003 (WK-GUEST) $ config mac-filter-list FW003 (mac-filter-list) $ edit 1 FW003 (1) $ next FW003 (mac-filter-list) $ end FW003 (WK-GUEST) $ next FW003 (vap) $ end ---> generating verification report ( wireless-controller vap mac-filter-list ) add entry 1 <--- done generating verification report install failedAny thoughts?
In our organization, we are evaluating replacing Cisco ISE with a Fortinet solution. One of the key functions of ISE is the authentication of Telnet and SSH admin sessions on Cisco switches and routers using AAA.My question is whether FortiNAC can replicate this functionality.An example of use case would be the following:The network administrator initiates an SSH session to configure a VLAN on a port of a Cisco switch.This request is verified by Cisco ISE, which either grants or denies access to perform the configuration.I will be grateful for any help you could give me.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.