User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/33053/outbound-firewall-authentication-with-microsoft-entra-id-as-a-saml-idpI’ve been trying to integrate SAML authentication between FortiGate and Azure Active Directory, but despite everything being configured correctly, I’m encountering issues logging in.Configuration:SAML settings on FortiGate are correctly configured, including Entity ID, Single Sign-On URL, Single Logout URL, and IDP Entity ID (matching the Azure AD SAML application).The SAML assertion received from Azure AD contains the correct username and group values as per the FortiGate SAML configuration.Reply URL and Assertion Consumer Service (ACS) URL in Azure AD are set to match FortiGate's settings.SAML signing certificate is correctly set in both Azure and FortiGate.Issue:When trying to log in, after authentication through Azure AD, it redirects back to the Fort
how many URL can be created in static URL filter?
I have tried to download a FortiNAC demo from the support page to test on a virtual machine but it seems to be unavailable, do you know of any way to download a demo for Vmware, or is the web demo the only one available? I hope you can help me, thanks.
Hello, we had quite some issues with this FG60 7.4.6 and SD WAN. With the update to 7.4.6 we dont have anymore "conserve mode" issues and we can exclude this as a problem. BUT we tried now 3 times with SLA performance and all 3 times it happened after 12, 24 or 36 hours that the interface got DOWN. This interface is our VPN interface and we never had issues, VPNs were always UP. I found a known issue (1023878) which should have been resolved in 7.4.5 but having 7.4.6 I think we still have the issue. Anyone having the same problem and comming up with a solution or an idea? I tried to disable the WAN2 but nothing, I cant get it up again, the link is down even after removing all WANs from the Performance SLA. I am sure that the WAN is woring just fine. Thanks
I want to switch from using the SSL-VPN to ZTNA but my FortiEMS says that i have 0 Zero Trust licenses.I haven't used any as it shows in the EMS (0 of 0 used) and my EMS says that Zero Trust Access is included.I am using FortiEMS 7.0.11.Is it a problem with the version? Can i use version 7.4 on a windows machine or is it only available for linux?
Hello,I have to set BGP on my Fortigate 600E appliance with my isp.I already configured neighbors, AS and advertised routes and everything is working fine except: There's 1 network in my routing table which is 10.10.0.0/16I have to advertise to my neighbor only the 10.10.60.0/24 network and not the whole /16 subnet (he set it in his prefix filter) soI added another static route of 10.10.60.0/24 for my local routing table with the same gateway as the 10.10.0.0/16 has, and advertised it to my BGP Neighbor. Now, my neighbor gets all the networks I advertise except the 10.10.60.0/24 Routing table (only the routes assosiated with that issue) : S 10.10.0.0/16 [1/0] via 15.15.15.1, port5, [0/50] S 10.10.60.0/24 [10/0] via 15.15.15.1, port5 BGP Advertise to neighbor (get router info bgp neighbors <ip address of neighbor> advertised-routes):*> 10.10.60.0/24 93.52.12.2 100 32768 &nb
Hi all,anyone aware how can i add "virtual-wan-link" SD-WAN zone into normalized interface mapping in Fortimanager ? I am able to add every other SD_WAN zone, as long as the name is different than the default "virtual-wan-link".. Fortimanager is running 7.4.5
I thought it was possible to have the Hub hand out an ip addresses via mode-cfg from the Dialup IPSec tunnel, doesn't seem to work. Is it supposed to work when a branch Fortigate dials into the Hub Fortigate. Here are my IPSec configurations for the Hub and a Spoke. (The tunnels are up, it's just that the spoke will not grab an IP Address or the Hub is not handing them out)HUB:config vpn ipsec phase1-interfaceedit "advpn_1"set type dynamicset interface "port3"set ike-version 2set peertype oneset net-device disableset mode-cfg enableset proposal aes256-sha256set add-route disableset auto-discovery-sender enableset peerid "100"set ipv4-start-ip 172.50.100.100set ipv4-end-ip 172.50.103.200set ipv4-netmask 255.255.252.0set psksecret set dpd-retrycount 2set dpd-retryinterval 10nextend-----------------------------------------------------------------Spoke:config vpn ipsec phase1-interfaceedit "advpn_1"set interface "wan2"set ike-version 2set peertype anyset net-device enableset
In FortiAnalyzer (v7.6.2 KVM), I authorized the Fortigate (v7.2.8), and Added the Fortigate in the devices list. They are all FortiCloud connected on the same account. On the Fortigate, when going to Security Fabric - Connectors - Logging & Analytics - right clic EDIT - Settings - FortiAnalyzer , I Enabled, wrote the server ip, and if I wait, there is the circle of death for the Connection status, but if I click on Cloud Logging, and come back to FortiAnalyzer, it's now connected! If I click on OK, I get the message "Empty values are not allowed. Attribute interface MUST be set" error. See image. The versions are compatible in the matrix, so anyone has any idea what's the bug?   FortiGateFortiAnalyzer
Hello,We have a bunch of Fortigates which are acting as SSL VPN hubs and we use Azure SSO for user's authentication. So far so good, but recently we bought FortiManager for managing those firewalls and basically i want to create a single Policy Block which will contain all SSL VPN policies for all resources, so the users can connect to the nearest Fortigate and have same access to whatever Fortigate they connect. But the issue i am facing is related to Azure SAML configuration and the impossibility to use single group object ID ( retrieved from Azure AAD ) which can be applied to all Fortigates...Please suggest, how can i fix this, without having separate policies for every single Firewall and when change is needed i need to change the respective policy on all devices
hi at all,so, fortinet got some CVE's, nevermind... Every CVE i check if its attackable to our environment, ok...but the FG-IR-24-250 one, i dont understand the concept...Can someone explain this to me?How could the unauthenticated attacker access the gui, or more like, how am i vulnerable?Could the attacker attack is, if he get access to a gui? Like if he can access the SSL VPN Portal, he can use this attack unauthenticated pordal?or is it only possible if the attacker got access to the admin GUI?Admin GUI isnt accessable from external, and all SSL VPN Portals the Web-mode is disabled, but as the Web-mode-Login-PAge is still accessable... so is this a way to attack?maybe everything is lost in translation at my point, and other people understand this CVE, but the reseller and technical service provider didnt understand the attack-possibilities too...Can someone help me to learn something?:(
How do I get FCREMOVE.exe for a free copy of Forticlient I am unable to download the tools and I have a free copy of Forticlient installed and I can not remove it It is not showing in add/remove programs. We can't uninstall We can't install. We are stuck Any ideas?
Hello all,I am trying to get IPSec VPN with 2FA to work on a 60F running 7.6.1I have used the Wizard to create the VPN, and I have tried to manually set up the VPN tunnel, I have also followed the available instructions to create the tunnel via CLI. It all ends in the same problem : I have a working P1 and P2, I get prompted for the token, and FortiClient claims it´s connected. I can see the traffic counter counting traffic to the firewall, but not receiving anything.I have set up FortiAnalyzer, and there I can see the traffic as allowed traffic hitting the correct policy.I can see the session in FortiView on the firewall, with traffic in both directions. Neither traffic sniffer nor flow debug shows any packet. I have tried two different Windows endpoints, all the same. Spent one week on this. Where can I dig now ? Cheers, Chris
One of our reports are returning empty.Already checked the empty reports guide on KB and haven't helped:- FortiAnalyzer 7.4.6- Fortigate 7.4.6 (target device that returns empty report).- Dataset live data test OK (selecting the target device).- Chart live data test OK (selecting the target device).- Creating a report containing the above chart and selecting the target device returns empty.- Workaround: if we move the name of the target device into to the dataset and run again with "all devices" option, it works. Any ideias what could be wrong?
I'm using the forticlient with Ubuntu 24.04.1 LTS. After running an apt upgrade the forticlient was also upgraded from version 7.2.5.0854 to 7.2.7.0905. Now I'm no longer able to connect to my VPN. I get the following error messages in the log file sslvpn.log: 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] nmtools:255 Command to set ipv4.ignore-auto-routes returned with status 256. 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] nmtools:1060 Failed to modify connection docker0 property ipv4.ignore-auto-routes 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] dns:1007 Failed to finish Network Manager configuration 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] vpn_connection:2072 Config DNS failed I have already removed some docker interfaces, which occurred before in the log as error messages, but I cannot remove the docker0 interface, only to get the client running. I have also upgraded to the Version 7.4, but I get the same error messages. I tried
Hello, I'm new to FortiWeb and would like to monitor the overall in-and-out throughput on the dashboard, with a time interval of either one week or 24 hours. Could you please assist me with this?
I have configured SNMP V3 on Fortigate Firewall with proper steps. After adding the device to opmanager getting ERROR showing "Credentials Not configured : Add valid credentials to monitor the performance metrics of the device". I have also enabled snmp access on the interface.
Hello Everyone,I want to configure DKIM on our Fortimail unit to sign outgoing messages, but I have a lot of questions that I need your help with. First of all, our Fortimail unit is 200F unit, working in transparent mode. We have 2 protected domains configured inside this unit. The two domains are MS exchange serversFor my questions:Can I configure the DKIM signing in Transparent mode, or it should be in gateway or server mode for this to work?If it is applicable in transparent mode, and I successfully configured it, will this configuration be affected or stop working if I change the working mode of the fortimail unit to gateway mode?Do I have to make a record for the DKIM inside my exchange servers internal DNS, or it should be published only on the external DNS?Does the protected domains SSL certificates have to be imported inside the Fortimail, or the DKIM has nothing to do with the certificates?Is it better to configure the DKIM inside my exchange servers, or it's better to be con
Hello, I am working on cleaning up security vulnerabilities on users within the FortiClient EMS which typically lacks a DC connection and operates in a complex structure. There are over 100 computers with 7-Zip installed, and they want it removed. Is there a way to achieve this through EMS ?
Hello, we just put in 2 branches a FG 80 cluster with 7.4.5. Both connected to Arruba Switch with ISP A Internet Access and ISP B 5G Failover. Our ISP now comments that the 5G router are in dormant and they dont reveice the VRRP events. Since router and 5G backup are connected to the switch I dont see why we should configure multicast policy. Trying out with multicast policy we risk some strange behavior with the Fortigates? Thanks!
We are using a services name Endpoint Central, but oneday my Firewall aret condition about this services as malicious-url.i'm adding this to whitelist, web overrated, policy but not successful.Maybe the mistake, how can i remove this services from malicious-url.  
I'm trying to set up Wake on LAN (WOL) so that I can wake my work PC from home. I can wake my PC from within our local network, but not from my home computer. The company is not keen on setting up port forwarding to broadcast the Wake on LAN packet (magic packet) for security reasons, but they have given me SSL-VPN access to the company server. However, when I run the Wake on LAN program from home, it doesn't wake my computer. I did a search on the Internet, and apparently VPNs don't like doing broadcasts. Does anyone know if there is a setting in the FortiGate 400D that I can configure to allow it broadcast the magic packet via VPN access?
i have problem when i add fortigate to fortimamanger ver 7.6 this command config system global set fgfm-peercert-withoutsn enableendnot in fortimamanger 7.6
I have a FortiGate 101F that I just set up and I created a few policies like in the image below.Everything is working but can someone check if I've done it right. Internal LAN, is out network switch/Access point, Maxis-Internet is or internet line. Have I done the security profiles correctly?We're not subscribed to AntiVirus, so that's why its not in Internet policy, but somehow there's a basic one for Internal.
I have two FG61Fs running 7.4.6 with a Dial-Up IPSec VPN between them. I recently added a second WAN connection for failover purposes. I use the link monitor to kill the static route with higher priority when my primary goes down. That works great. For the VPN, I added a second tunnel bound to the backup WAN interface. Both IPSec interfaces are in a zone, and I use the zone in the policies. I cloned the static route from the original tunnel and changed the interface to the new backup tunnel and gave it a greater priority value than the original.The screenshot below shows the remote side. This is what I see when on my primary WAN. If I unplug the primary WAN at the home office, the HomeOfficeTMO (backup) tunnel Phase 2 comes up - but I can't pass any traffic over it. If I manually disable the Static Route for the primary WAN tunnel on the Home Office, it starts to work. I thought that if the primary WAN tunnel was down that woul
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.