User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Looked at the admin guide, and the example it shows, is www.google.com (As a subnet object???)Need to add a simple subnet object like "192.168.0.0/16". Is this possible?I have many address objects of type Subnet, that were created in a FortiGate before FortiManager came along. When trying to add in FortiManager, It clears the subnet address I try to add within IP/Netmask and then says "Invalid IP address"Does FortiManager have a different concept of a subnet address object than the FortiGate does?I know I can add an IP range (probably), but that means I have to go through and edit "all" of the exiting definitions. In the FortiGate, when adding a subnet object, I can name it something like "sn-bob" and it does (or at least did not previously) require that it resolve to anything. I'm hoping that I am missing something stupid.
I'm having an issue with Dual 5g mode on my FP231G APs. Radio 1 is offRadio 2 is the low 5g channelsRadio 3 is the high 5g channels Dense deployment (it's a school and every classroom has an AP) The issue is all clients are only connecting to radio 2. Radio 3 is propagating, I can see it with the fluke WIFI scanner. DAARP is working, the client experience is pretty good except I'm getting some very high channel utilization numbers due to the fact that the clients are all connected to just 4 channels on radio 2. I made a new connection profile with single radio 5g and that's working great, all the channels are utilized and my channel utilization issues are gone or very minimal. I made a test profile with dual 5g enabled, radios 1 and 2 off, and clients connect to radio 3 without a problem. My questions are:Is there a way in the config to encourage clients to connect to radio 3 when using dual 5g mode? Is this likely just a client issue and
"I have two FAZ devices at two different locations, and I want to configure HA between them. There is an MPLS link between the sites, and both FAZ devices are in different subnets. Can we create a VRRP cluster across two different subnets?"
We recently upgraded multiple FortiGates (60F through 2600F) to 7.2.8 the day after the latest release was made available. Last week, one of these (60F) stopped passing traffic. We could ping the management interface and could do a "tnc -p 443 <IP>" where we'd see the 3-way handshake in a packet capture, but the login page would time out. We tried to console in - there was no prompt, but it'd echo back what we typed in. I did try an "exec reload", but nothing happened. But then, we couldn't get authenticated. This firewall required a hard reboot to bring back online. The only significant things in the system logs were these two events: - Critical: Kernel enters memory conserve mode- Critical: Kernel enters extreme low memory mode This was just a few msec after an antivirus update, but I'm not certain if they are related. We had the exact same thing happen today on another FortiGate. We have an upgrade scheduled for the main hospital this Friday, but I'm very hesita
HelloAll "internal" Fortigates send logs to our Fortianalyzer's port1.We want a "dmz" Fortigate to send logs to Fortianalyzer's port2, this is because traffic from "dmz" to "internal" is not permited.How can i isolate traffic between Fortianalyzer's ports in order to safeguard the above policy?The dmz Fortigate is not hosted to us so we can not use a mgmt interface. Thanks
Hello,We have a customer currently using IPSEC VPN using a pre shared key. The users sign-in using their on-prem AD username and password. We have ADSync setup sync the accounts to Microsoft 365 and the PC’s are hybird joined. The customer would like to start using Microsoft MFA to authenticate the VPN. I can’t seem to find a step by step guide to set this up has anyone setup this that can provide information on how to set it up correctly? Ideally I want to keep the current IPSEC setup but just add Microsoft MFA to authenticate.
Hi all, I have a problem, Fortinet support have been less than useful. FortiGate We have a cloudflare Zero trust setup that stops any DNS requests to malicious sites. What I want to do is intercept these requests on the Fortigate before they get to Cloudflare.In the past I have been manually adding eachnew site that cloudflare makes me aware of, this is time consuming. I have been on leave and returned to over 100 URLs to add to the DNS filter on the Fortigate. I was hoping to just import a csv or text file of the URLs into the Fortigate DNS filter list. Apparently this is not possible. I have seen some talk of using a cloudflare API to do this but not sure how. Has anyone found a way to do this. The Stock Frotinet answer of "put in a new feature request" is laughable when solutions are needed quickly and when we all know, that feature will never get added. I don't know why they can't have a plain text input for the list. E.G. on our smoothwall
I can only add one, like I do to add 14 domains. I need it to be with Let's encrypts. Can you help me? thank you
Hello, Can we create a local user for SSL-VPN to change password after there 1st login?
Hello,Is there an option to extend the forticlient ems cloud session time? By default the time is very short.Thanks.
Hi all¡¡ In short, we have a Server for softphones in our DMZ and internal ToIP Servers. All traffic between servers passes trought a Fortigate. All traffic I'm going to talk about is SIP UDP Traffic. There is some strange things I don't understand. There are differences if I capture traffic from firewall or from servers. I don't have a rule to allow that the internal server Initiates SIP connections to DMZ server. Internal-->DMZ:5060 but I have a rule to allow 5060 traffic from DMZ server to Internal server DMZ-->Internal:5060. 1)If I capture SIP traffic from the ToIP servers (internal or external) it seems that it's the internal server that connects to the DMZ server 5060 port. The Invite packets are from Internal server to external server:50602)If I capture SIP traffic from the firewall (pcap) or I check a debug, it seems that it's the DMZ server that connects to the internal server 5060 port. The invite messages are send from the DMZ server to Internal se
Hey all,Just noticed a bunch of vulnerabilties from low-high impacting 7.2.9. Most of them are resolved in 7.2.10, but two of them require 7.4.5. It appears to be a mature release, anyone have any odd issues with it where it should be avoided? If so, what release >7.4.5 to you recommend for stability?Thanks!
Hello, Could we allow copy/paste throught RDP and SSL-VPN service (using FortiClient, not Bookmark)? Thank you for your help,Chris
Hi Team, Today I found a user event log as below User daemon-admin restored the image from ha-daemon And my firewall automatically upgraded from 7.4.5 to 7.4.6. Kindly confirm whether it is genuine or not.
Hi guys,I'm seeing a log in my fortiproxy where the traffic is denied due to 403 and the category is cat=225. Any idea what is this cat=225? I don't see this category anywhere in the web filter. Could 225 be a customized category in my fortiproxy? FortiGuard web filter categories | FortiGate / FortiOS 7.6.1 | Fortinet Document LibraryThanks!
Hello and sorry for my english, I want to schedule backup of my fortigate to SFTP server. So i installed new SFTP server. From CLI on fortigate, if i try the command : execute backup config sftp "/global/backup-global.conf" 172.21.0.32 SFTPuser 123654 it works perfectly, the configuration is save on remote server.So after that a create action with this command and execute with super_admin profile.After that i created trigger to launch Daily at 23:01After i created stitch with first trigger and second action script. But the stitch doesn't work at all. It is enable, script is OK so i don't understand why at all...On my fortigate, i have vdom, the stitch is on globalthanks a lot
Hi, We have 1 hub and 2 branches in our setup. All these 3 location has one internet link and one MPLS link (Hybrid underlays) We are having BGP on loopback overlay setup We have requirement of ADVPN between Spoke 1 to Spoke2, with the help of SDWAN rule we are steering this ADVPN traffic through internet link (And MPLS as second member order) and could see child tunnel (inet_0) formed in Spoke 1 and Spoke2. Traffic originating from Spoke 1 to Spoke2. Everything works fine in normal scenario. We could see that Routes for spoke 2 (192.168.3.0/24) is learning through inet shortcut tunnel and MPLS parent tunnel tunnel in Spoke1. When Spoke 2 internet link goes down, this causes Inet child tunnel goes out of SLA, as per SDWAN rule member order next member MPLS parent tunnel is created and then child tunnel gets formed in MPLS (MPLS_0) at both branches Spoke 1 and spoke2. Until this point, its working fine. Till this point, at Spoke1 - spoke2 route will le
I saw some conversation about stopping auto-upgrade on FGTs before after 7.2.8. And, we're doing it manually for those FGTs that are NOT managed by FMG. Then when we tried the same for those managed by FMG, the change was rejected because it's managed by FMG.And solution is in this KB:https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-automatic-firmware-upgrades-on/ta-p/326998#:~:text=set%20allow-push-firmware%20disable%3A%20Disables%20the%20ability%20to%20push,firmware%20updates%20from%20being%20pushed%20to%20the%20devicesBut it's not totally clear about the behavior for those command:config system central-management set allow-push-firmware disable set allow-remote-firmware-upgrade disableendWhat we want to set up is:1. Stop FMG pushing auto-firmware upgrade to managed FGTs2. Also stop FGT upgrading firmware by itself3. We still want to upgrade those managed FGT firmware via FMG manuallyTo accomplish this,config system central-management
I'm new to Fortigate and I need to get MFA working for SSLVPN users from an LDAP Server. With other manufacturers, such as Sophos, I just need to enable MFA for users and have them read the QR code in their respective authentication app. With Fortigate, do I need to use Fortitoken mobile exclusively?Another question: is it true that to use MFA with Fortigate, I need to pay for a token?
Our setup is such that we're trying to get our FG1101E to act as both router and firewall with BGP routing. We have our ISP provided single fiber uplink at 10gbps (SFP+) which has a defined Point to Point IP /29 IP address that's used to peer with a BGP neighbour. The BGP side of things appears to work ok, with our prefix for public IPs are being advertised and received to our ISP, and they are sending at default route to us. What we're trying to achieve is to be able to egress to the web using an IP on the advertised prefix, these are public IPs assigned to us as an organisation. We're able to use them in the context of an outbound rule, for this to work we have to create an IP_Pool overload object and use that in the rule which shows to the world we're coming from an IP we own. If we don't do that, then our IP is shown as the BGP peer IP. We are trying to get to a place where we can use some sort of virtual interface with the IP loaded on fro
Hello, I want to limit the VPN connection of local or imported ldap user as data and time using usage profile on FortiAuthenticator. I am listening on 1646 radius acconting. 1646 port is open on FortiGate and FortiAuthenticator. When the user exceeds the specified limit, no warning and interruption is observed. Can anyone realize this application or have any suggestions? By the way, when the user connects, I cannot see any session in Monitor > Radius Session field. I have followed all the warnings in this document:https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682
I have free trial license fortimanager and i want workaround to upgrade fortigate with it as when i try to upgrade give me error message (no valid FMWR license) so can anyone helps me?
Hello everyone,Since we did move to FortiClient EMS end of last year I do want to start diving into ZTNA now: I do have a VLAN that is not connected to my windows domain server (Domain Controller, File-Server, ...). This VLAN is for third party machines and computers (robotics, PLC, IOT devices, ...)Now there is a use case that some of our plc programmers want to work in this specific VLAN for the ease of access to the robotics but also need to access e.g. windows File-Server. What is the easiest way to set it up? Basically I was thinking about creating a policy that only allows FortiClient EMS managed devices. I do see the ZTNA Tags created from EMS in the FortiGate. Should I go for the "IP/MAC Based Access Control" in a "standard" FortiGate policy where I can secelt the ZTNA tags? Or do I need a full ZTNA policy?   ZTNA policies documentation seems to often point into a kind of webserver scenario - that is not really needed here. So do I need a ZTNA ser
My new 60F Wi-Fi will only do 5 or 2.4ghz which I think is normal.I am using 2.4ghz since one device is IoT and likes 2.4ghz only.Many devices are happy but the 16 Pro is not - I tried a few settings and channels (3 choices) and it wont connect.Any ideas please?
My aim is mainly blocking bad sites (malware, C2, phishing) not controlling certain types. Web filter and DNS make sense, though perhaps are a tad similar. ISDB seems to offer some IP blockers. Would ISDB cover my wish by blocking connections pre/post malware to malicous domains (IP behind)? Thank you
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.