Mark a Best Answer
Fortinet Community
Recently active
Hello, When we are trying to run the below commnads:exec update-now We are receiving the below error: Command fail. Return code -6 We have update the fw license on the portal and it is not reflecting on the fw dashboard
"Hello guys, how do I perform a speed test through a FortiGate 60F?"
i need to install version 7.0 in order to resolve an issiue with Version 7.4 where the connection is not being established.
Good Day! Some months ago, I switched my old FG30E because of the port problems (falling back to10mbit) to a new, used one, which was licensed to a Premium Support contract (mine was no Premium), that is the only difference, both have the exact same config. Took a routine look yesterday into the System Events and I was quite puzzled: the FG30E constantly tries to update the signatures, although, no scheduled updates ticked or any license active anymore. Furthermore, it clogs my syslog. The intervals are between 1 minute to 30 minutes. "Log Description: AV database updated by scanunit , User Interface n/a Scanunit initiated a virus engine/definitions update" Any chance, I can turn this thing off? Or just ignore it and set System Events to no logging so I wont see it any more? Regards,Stephan
Hi,I have a question regarding the integration of AlgoSec with FortiManager. If our business was to implement FortiManager for approx. 120 Fortinet firewalls, would we still be able to implement AlgoSec on top of that to complete end to end policy management and would it work seamlessly? We also have Juniper & Palo Alto firewalls in the network, hence the reason for needing AlgoSec to allow for better automation across our estate. I've read some FortiManager/AlgoSec documentation and it looks as though it should work, but I'd like to have that confirmed, preferably by someone who has used both of these systems at the same time previously.
20 odd AP'sall finenetwork dropped out yesterday for 5 mins and since then one of the AP's wont come back online FortiAP 231GFortigate version 7.2.9FortiSwitch 124F-FPOE Just get a solid Amber light on the AP for power.AP 'left' and Control Message Maximal Retransmission Limit Reached Things i have tried 1. rebooting the Fortigates2. rebooting the FortiAP 3. changing the cable from the patch panel to where the AP is plugged into the fortiswitch4.running this....config wireless-controller global set max-retransmit 3 <<<< default - please input integer value (0-64) ---> increase to 25 config wireless-controller timers set echo-interval <1-255> ---> increase to 100 end Still no change.Plugging the AP directly into the Fortiswitch brings it back online - but need it back out in prodcution round the building. Any ideas please?
In short: Is there an AI assisted way to upgrade FortiOS, comparing current configurations with releasenotes? When upgrading a system with several releases between the current and destination versions, the traditional approach involves:Collecting Release Notes: Gather all release notes from the current to the destination release.Reviewing and Comparing: Read through the release notes, compare them with your configurations, and identify potential issues.Planning Fixes: Address any issues before or plan to fix them ahead of the upgrade.Following the Recommended Path: Adhere to the upgrade path recommended by Fortinet.Testing Each Update: Test each update to ensure stability and compatibility.This method, while thorough, can be tedious and time-consuming.Leveraging AI for UpgradesWith the advent of AI, there could be a more efficient way to handle upgrades. Here’s a modern approach:Current Setup: I currently run FortiOS 7.0.15 on most smaller devices and have all configuration f
Overview/Scenario1. I have a use case for configuring NAT where in which an isolated Azure virtual desktop session host will traverse a NEW public ip address assigned to my Fortigate Azure NGFW virtual machine's WAN interface.2. Any IPs requiring egress traffic outbound will use cenrtal SNAT in a one-to-one mapping for all ip addresses within my AVD subnet range: `192.168.235.0/24`Questions:1. Could you please critique my implementation logic below? Relativley new to FortiGate, so please excuse the basic questions. I sourced FGT docs on [central SNAT](https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/421028/central-snat)2. As the new Azure public ip is assigned to the WAN interface of my FGT device, would DNAT be required? Not sure how FGT would route traffic from the new public IP inbound to my AVD subnet. However, there is currently no requirement to translate destination addresses to specific services within the isolated AVD subnet Proposed Azure deploymen
We have a FGT 80E with Forti OS 7.0.17 in air gapped network. I tried to update that with a local TFTP server. I updated these packages successfully : apdb , ffdb , isdb , nids , etdb , mmdb But still these databases are empty : Malicious URLs , Botnet Domains and Blocked Certificates . How can I update them too ? In which Package is this information located?
Looking into the benefits of FSSO in our environment for the purposes of restricting internet access. What does FSSO give you that a simple LDAP group doesn't within a firewall policy ? Or are they to be used in conjunction ? Thanks all!
I'm using SAML auth with my ZTNA proxy-policy. Everything worked great until I upgraded from 7.2.8 to 7.4.6.No config changes were made. This is a 91G model, which according to docs should still support full proxying in 7.4 and above. The root of the problem is that the Gate (SP) is no longer re-directing the client to the FAC (IDP) for SAML auth. When the client requests https to the ZTNA server, it presents its EMS certificate and is immediately granted access. Prior to the upgrade, it was presented a SAML login page from FAC and everything worked as expected. Is there more/different configuration in v7.4.6 ? config firewall access-proxy edit "ztna_https_faz" set vip "ztna_https_faz" config api-gateway edit 1 config realservers &nbs
I am using Fortigate 100G in HA and running Firmware 7.2.9. The issues I am facing is the interface is able to reach the NTP Server. NTP Server : 192.168.1.10FGT MGMT : 192.168.1.4 I have added a MGMT interface under dedicated management interface, which changes the MGMT interface in different vdom and getting removed in interface GUI. I want to get the time through management interface. I have configured NTP with below config set ntpsync enableset type customset syncinterval 1config ntpserveredit 1set server "192.168.1.10"once I try to add command "set source ip" it is showing below error "192.168.1.4 does not match any interface ip in vdom root." , as Management interface is removed from root vdom So my question here is can we configured ntp on dedicated management interface vdom, or how can we achive. Also I am referring to below docs in which we can set the interface under ntp server-->edit 1, but I cannot see it in my firewall. https://docs.fo
Dear Sir, We have a almalinux server running a website. This server has a dedicated Public IP.We want to change its private IP address from 192.168.3.A to 192.168.3.B.Before changing the private IP, we have duplicated all relate Fortigate firewall policies for the new IP 192.168.3.B. However, we found that we still cannot connect the website after changing the private IP.The sever is connected to the internet because we can ping outside from the server, and we can also ping the server from other computer in the same subnet. We feel the problem is due to the firewall policy but we don't know where it is. Can anyone advise us what settings can cause this problem?Thank you.
Hello, I have encountered a recurring issue across all versions of FortiClient 7.x while trying to connect to my VPN. After entering my password and pressing "Enter," the password field gets grayed out and becomes unclickable.At the same time, a new field labeled "Answer" appears, asking for a PIN between 4 and 8 alphanumeric characters. When I input the PIN and click "OK," I receive an error message stating that the password must also be entered. Unfortunately, since the password field is disabled, I cannot re-enter it, making it impossible to proceed. I’ve attached a screenshot for clarity. Has anyone encountered this issue before? Is this a known bug in FortiClient 7.x? Thank you in advance for your help!
First of all, I am inheriting this network and I believe this to be setup incorrectly however I've never seen someone try to do it this way. I have a two site-to-site fortigates with a switch behind each. I am getting inconsistent pings to the far switch. The far fortigate is also getting intermittent pings to its switch (they are connected via copper which has been swapped out). The LAN interface is set to 192.168.0.1 and the switch's Management interface is set to 192.168.0.2. Under the FG's LAN interface are SVIs for the various vlans on the switch. It seems to me that the problem is likely that the OOB mgmt interface is being used or is there something on the FG side that I should look at?
I have disabled the autoupdate and coud communication on our Fortigate firewall, running v7.0.14. But, the logs are showing the "Fortigate update now failed" every minute. wondering how to get rid of these messages?
Hello, I wonder if anyone in the community has an MTBF for the FGR-60F?The Spec sheet states:Compact and Reliable Form Factor Designed for small environments, you can place it on a desktop or wall-mount it. It is small, lightweight yet highly reliable with superior MTBF (Mean Time Between Failure), minimizing the chance of a network disruption. Evidence would be great ! Thanks Steve
Hello new to Fortinet. Try to get start with a Fortiswitch. I would like to replace my Cisco L2 Switches with Fortinet but will need to phase them in. I am currently having an issue with my Trunked(Cisco) Ports. As I am new to this setup I am even having a hard time getting with support. Is there a knowledge base or something I can read up on to get myself familiar? Anything that can help point me in the correct direction would be great.
Hi,I would use mac-based device in ipv4 policy, I have created such device as mac-based and this device is visible in "Addresses". But when creating ipv4 policy for destination on "Devices" tab I cannot see this mac-based device.No any mac-address devices (with his own mac-address icons) are displayed in "Devices" tab.What I'm doing wrong? Fortios 6.4
Secure Connectivity for Mobile Fleets: FortiExtender Vehicle 211F By @PatVita | Director of Product Marketing, FortiExtender If you’re a close follower of Fortinet product news, chances are you’ve heard rumors of a mobility solution coming to the FortiExtender family. I’m happy to say the wait is over: FortiExtender Vehicle is here. Secure Connectivity for Mobile Fleets Many IT teams struggle to service mobile fleets. Whether it’s a public safety, transportation, logistics, or the travel industry fleet, vehicles are unique in that they require secure connectivity to cloud applications but cannot leverage wired broadband. Adding point solutions creates complexity and risk for organizations. Mobile fleets cannot become another silo for enterprise IT. Secure connectivity for must be delivered within a digital platform alongside other areas of IT, such as OT, IoT and wireless access, Enter FortiExtender Vehicle 211F
Dear all, I have diagram as below: --------- tunnel 01 --------------Hub (lo0) (Lo0) Spoke ---------- tunnel 02 ------------- I am using BGP on loopback to set up routing via 2 Tunnels. (FortiOS 7.4.4)And I try to set up SD-WAN Rule to steering BGP traffic (Keepalive, updates...) via tunnel02.In the sd-wan rule: I set: source is Lo0 of spoke and destination is Lo0 of Hub, Outgoing interface: i used Manual : Tunnel02 is first order and tunnel 01 is last order. Member is 2 tunnel interface SD-WAN zone. But after that, I can not see any hit count on the sd-wan rule, and diagnose packet port 179 : traffic still via tunne01. I am wondering what is my mistaken ? (or BGP update processed by SDWAN rules ?) (I have another sd-wan rule to allow all (all source and all destination), used SLA
FortiSOAR Community Update: Powering Up with Industry Favorites! This month's spotlight is on the tools and solutions that have become indispensable to SOC teams across industries. From tackling outbreaks with precision to enhancing system monitoring, these updates are here to streamline your workflows and boost your security posture. Our Outbreak Response Framework together with its Configuration Wizard remain industry champions, offering swift and efficient responses to emerging threats. Coupled with the Fortinet FortiGuard Outbreak connector, these tools ensure you're always one step ahead of the threat landscape. And for those looking to enhance their data protection strategies, the Fortinet FortiDLP connector is here to secure your sensitive information with ease. The IBM Security QRadar SOAR and Maxmind connectors continue to deliver insights and integrations that empower your team. Add FortiSOAR's own System Monitoring and Netscout's Arbor Edge Defense to the mix, and you
Hello everyone!I looking for help for a case,I have Fortigate 92D and interfaces created successfully and it also be router, firewall andDHCP server.I have some ZTE Wifi AP devices support for EasyMesh.I have an issue with that APs when connect them to same interface in Fortigate that mesh function via wired cable will not works, but if I put a Switch between Fortigate and APs everything work fine. EasyMesh not work: Internet ----> Fortigate 92D ----[LAN cable]---> APsEasyMesh work: Internet ----> Fortigate 92D ----[LAN cable]---> Switch ----[LAN cable]---> APs Fortigate 92D is great device for Home because it has a lot of LAN ports so put a Switch to help APs functioning is not a good setup. Thank you!
I've got a client that is gonna have a Connectwise SIEM (Perch) sensor placed in the network. Normally the internal Fortigate Port on the Switch is being mirrored. But with this client the Internal Port is also the FortiLink to Fortiswitche(s). The Port where the Fortigate is connected is port 48. How can I create A mirror port on Port 48, without breaking the FortiLink to the FortiSwitches? The Perch Sensor is connected on Port 30.
I am using a wireless LAN by connecting FortiAP421 and FortiAP431 to Fortigate60E. Occasionally, there are instances where client devices get disconnected. The logs output during those times are as follows:- Wireless client left WTP- Action client-leave-wtp - Reason Unspecified reason. Does anyone know the cause of this log? If I were to investigate, how should I proceed?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.