User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Running a 91G on 7.4.6 and trying to add a secondary HA member in A/P mode. I did the initial config for HA before connecting the heartbeat interfaces (matches the primary, except for priority). After connecting, the secondary unit is seen but the config synch fails. config system ha set group-id 1 set group-name "my91G" set mode a-p set password xxx set hbdev "wan1" 10 "wan2" 20 set session-pickup enable set override disableset priority 56 Here are the errors I am getting. Does this mean I have to manually go into the secondary and make config changes for all of these ? Table 91g_pri_8383 (Primary) 91g_sec_7940 (Secondary)system.global 6c7457c867d70b31b0b1b40ea0b64933 b414354e704f6c2ba1f2cc32d253443bsystem.accprofile 516896996422b4ffb0bc35db970ca064 1339bc428f719fd8dff15e69ec6a229asystem.interface 6b73b9a398a09ecfd00e5b9bb45ae039 a759cd4772291b04c2501119836354afsystem.
We installed two FortiSwitchs in stand alone mode at a new small facility last year. A 448E-POE in main network closet connected to Metro-E and a 124F-FPOE in a network cabinet to link the back to closet with Fiber. Recently we added a FortiGate 60F to manage some planed IoT devices. After reviewing network settings we though the best method to move forward was to utilize Private VLANs to isolate the IoT devices in a single subnet behind the FortiGate. We tested on the 448E-POE switch and then discovered that the 124F-FPOE doesn't support them. Does anyone know if I convert the 124F-FPOE to be managed by the FortiGate, if it will then be able to support Private VLANs? Trying to decide if I need to replace it, or convert it to managed without doing it first since its in a manufacturing facility with the only extended downtime window from 1-4am on Sundays. I really don't want to come in to do the migration if its not going to work only to have to come back in a few weeks
I would like to know if it is possible to update the Firewall firmware of 2 Firewalls that are configured in HA in a way different from the current best practices. What the customer I am working with would like to do is update them as 2 separate firewalls instead of the current configuration that has them basically update at the same time. I believe this is wanted to combat a bad update being applied to both firewalls. Is the only option for an HA solution to have the primary download the Firmware to both devices and apply it all in one go or is there a way to do it as 2 independent updates?
I have a very short question for you all. I have two Fortigate firewalls, both behind NAT, am I still able to create an IPSec site to site tunnel ? It doesn't seem to be listed as a valid configuration anywhere, not in the templates and not on the internet as far as I have searched. I am in control of both NAT routers and both have static, full stack IP's.
Hi Everyone, we like to monitor our local SSL-Certificates from our Fortigate with PRTG to E-Mail us when the day of experation is near. has Anyone found a posibilty to do so ? I looked for a solution the last day an didnt found any. Greetings!
Howdy, I just have a question on a firewall policy that I have been playing around with. I have an IPSec tunnel between my agency and our parent agency allowing traffic to 2 subnets on their end (192.168.139.x). On my end, we have a supernet (172.19.41.x) passing clients using their application to their servers over that tunnel and everything is working well. However, the local LAN at my agency (192.168.56.x) is on a subnet that conflicts with one at the parent agency's, so we cannot pass that traffic over the IPSec tunnel. In an attempt to get around that, I created a firewall policy to pass the traffic but with a NAT IP Pool that falls within the allowed supernet, so the conflicting 192.168.56.x subnet is disguised as the allowed 172.19.41.x subnet. This works going out but does not work coming in. I can ping the parent agency's application server, but I can't connect to it from one of the end user computers. I have the two firewall policies for this below (sanitized), can anyon
Hi, In log view or FortiView I'd like to see netbios / host names next to the IP address - or as a column - for each entry. This would save me from doing individual reverse lookups in our internal DNS. I've looked at the settings and added columns for "host name" but they are not populated. Am I missing a setting somewhere to achieve this?
Hello and sorry for my english, I want to activate revision on my fortigate 901G. I saw this article : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-Revision-option-to-revert-to-a-previous/ta-p/194312 But the commands doesn't works on my fortigate and i find anything in the GUI about this...How to activate revision ? i 'd like to have backup when configuration is change et come back easily in last configuration with revision. thansk a lot
We bought some Firewalls 81F, but unfortunately they all have BLE inbuilt and it is not possible to go through TEMPEST screening. Is it possible to remove inbuilt BLE? Thank you.
Hi all, similar to "Technical Tip: Recommended Release for FortiOS" , does exist a technical tip related to FortiWeb? RegardsMarco
Hello team how to make the two interface to be best path i want each interface to carry different traffic but it canot work beacause the other interface is not best path
hello, I downloaded the following package forticlient_vpn_7.4.0.1636_amd64.debEverytime i dosudo dpkg -i forticlient_vpn_7.4.0.1636_amd64.debI get(Lettura del database... 256845 file e directory attualmente installati.)Preparativi per estrarre forticlient_vpn_7.4.0.1636_amd64.deb...Estrazione di forticlient (7.4.0.1636) su (7.4.0.1636)...dpkg: problemi con le dipendenze impediscono la configurazione di forticlient:forticlient dipende da libappindicator1 (>> 0) | libayatana-appindicator1 (>> 0); tuttavia:Il pacchetto libappindicator1 non è installato.Il pacchetto libayatana-appindicator1 non è installato.forticlient dipende da libnss3-tools (>= 3.21); tuttavia:Il pacchetto libnss3-tools non è installato.dpkg: errore nell'elaborare il pacchetto forticlient (--install):problemi con le dipendenze - lasciato non configuratoElaborazione dei trigger per hicolor-icon-theme (0.17-2)...Elaborazione dei trigger per mailcap (3.70+nmu1ubuntu1)...Elaborazione dei trigger per gnome-men
When checking the log in the fortigate forward traffic menu, the message Accept: DNS Error appears.In what cases does this occur?Deny : DNS Error is We know that DNS Error can be caused by problems such as incorrect responses from the DNS server.But how should we understand Accept?The DNS server is an internal server, and is currently causing problems when using certain services.
I wanted to download the latest firmware for my old Fortigate 50B. Running version is 3.00,build0480,070330. Where can i find it?
Hello,I am using an Ubuntu 22.04.1 LTS client.I installed the forticlient from here: https://www.fortinet.com/support/product-downloads/linuxI have the following issue: when I get prompted to insert the fortitoken key, that prompt lasts only one second, and I can't insert anything.Should I change something in my setup?
Hi All, Reqirements: -I want to access Branch2 to network from Branch1 via head quater. configred Ipsec over sdwan everyting working fine my according as per the lab digram. the problem which i am facing, while accessing the branch2 network from branch1 via HQ.I have added branch2 subnet(192.168.3.0/24) in phase2 selector of tunnel and created policy and route. unable to access branch2 network. If I select local and remote subnet 0.0.0.0/0, 0.0.0.0/0 then working fine. but when I defined network in Phase 2 selector then doesn't work. however traffic is sending via tunne. when I check dia sniffer command. Can you please tell me where is getting worng. I add more subnet in phase two selector of tunnel. What I am able to access, not able to access are as follows.(Branch2-PC2) ping 192.168.1.10 to 192.168.1.10 (HQ)---> reachable(Branch-PC2) ping 192.168.3.10 to 192.168.3.10 (Branch2) ----> not reachble, even after defining local and remote
Hi, conserve mode is something we didn't have for a long time with all the FGs we are managing right now but now it happened the 3rd time with a FG80F cluster. All 3 times the FGs were restarted right away so we didnt have time to react and check. Normally we dont have memory issues or CPU issues in no moment when we are connected, for example right now 64% memory and 0% CPU. We changed some configurations, disabled Features which are not necessary, deactivated IPS (something we dont like), logging in the policies, etc. but it still happened. Any ideas or suggestions? Thanks!
I have a Fortigate 40f (enterprise) and a Fortiswitch 108F Fortilink is up, see below Dunno what i am doing wrong i have no internet acces on the switch, i have now set everything back to factory.
Hi, we have this one site which is giving us memory problems after updating to 7.4.X. First we created Stitches for IPS and WAD and we thought with that we have it under control and we can wait until 7.4.X to come out. But these last days, also with the Stitches we have always over 72% memory usage. Checking memory we get:FG_XXXX # diagnose sys top-memnode (17550): 67393kBreportd (168): 41030kBipsengine (5424): 25112kBlocallogd (175): 22091kBipsengine (5427): 21890kBTop-5 memory used: 177516kB Checking the freeable memory we get only 7%FG_XXX # get system performance statusCPU states: 5% user 1% system 0% nice 93% idle 0% iowait 0% irq 1% softirqCPU0 states: 3% user 1% system 0% nice 95% idle 0% iowait 0% irq 1% softirqCPU1 states: 5% user 0% system 0% nice 93% idle 0% iowait 0% irq 2% softirqCPU2 states: 4% user 2% system 0% nice 94% idle 0% iowait 0% irq 0% softirqCPU3 states: 5% user 0% system 0% nice 94% idle 0% iowait 0% irq 1% softirqMemory: 1910984k total, 13
Hi, we have one office with FG80E on FortiOS 7.4.4 where we have quite some memory issues (varios Stints to manage). Now we are thinking about updating to 7.4.6 (some WAD issues have been resolved) but I was checking if there could be issues with our FortiAPs. We have some 231F models with 7.4.2 which should not have any problems but my concern is about some 221E models with also 7.4.2. Anyone with experience with older FAP models and 7.4.6? Thanks!
Hi guys, I have configured a virtual-switch aka hardware-switch and binded 4 interfaces that belong to a VDOM. config system interface edit "SW_Firewall" set vdom "Firewall" set ip 8x.4y.8z.254 255.255.255.0 set allowaccess ping https ssh set type hard-switch set snmp-index 18 set secondary-IP enable config secondaryip edit 1 set ip 10.22.33.1 255.255.255.0 set allowaccess ping next end next end How can I find out learnt MAC addresses aka "show mac address table" on each physical interface? Thanks!
hi, is there command to check mac add of the device connected to the port of the fortigate? I see port is up and trying to figure it out what is connected on it.
Good evening, I hope you can help me get out of this predicament, I have been trying to register my Issabel Pbx exchange to a trunk of the Dominican Claro telephone company for a few days. The Pbx is behind the Fortinet 60f.At the moment I have a Huawei router which has the VPN configured to connect to the Sip server of Claro, on the other hand I also have Internet service from the same telephone company on the network through another Huawei router, I have two Fortinet interfaces, each one connected to the Huawei routers, I have also configured the routes to the Internet and to the trunk and their respective policies, I have also configured the VIP ports with their respective policies as well, the The issue is that I have access to the internet from the Pbx and I can also pin both the trunk gateway and the IP address of the SIP server, of course, calls between local extensions work well and also with external extensions connected via the Internet, But when the PBX tries to register, it
Hi,I have been assgined to deploy a Frotigate VM, i have created the VM successfully but im having a confusion on how to create interfaces for fortigate, and how to connect it to the Virtualised Environment. The Topology looks like this, its very straight froward setup.a WAN Link going to terminate on the Physical Server, which in trun will be fortigate WAN interface, my question is how to create the Interfaces for the LAN, which will be connected to the webservers. (pls find the diagram attached.)
I have two FGR-60Fs powered at 137VDC but they are off now. I have measured the input and there is voltage, and they have been working correctly for several days. According to the datasheet they can be powered between 12 and 125 VDC, but it does not specify the tolerance. Can anyone tell me what it is?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.