Mark a Best Answer
Fortinet Community
Recently active
There is a nice articlehttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-Disable-Specific-IP-Addresses-or-IP-Address/ta-p/271410but this does not really help, if you want to disable an entry in the Malicious-Server table.Because this has more than 500.000 entries and if the ip-address is in the middle you can scroll down a few weeks.Not possible to search for the ip-address and disable it.
Downloaded Forigate 7.2.2 for my virtual lab and for life of me could not get the evaluation version register. First it was giving me DNS resolve error. I resolved that error now I am, getting " Curl Forticare failed,7 time out." on Gui I am getting error " error communicating with forticare ". I am using WMware workstation 16 Pro.
It's basicly what the title says. We use forticlient to connect to the company's VPN. I was told that the request reaches successfully the server but when it tries to create the ssl tunnel it fails. I already tried to reinstall, changing the wifi connection used.Here I have extracted some info from the sslvpn.log file that I think relates to the problem.Could you help me please? 20241112 09:58:28.682 TZ=-0300 [sslvpn:DEBG] vpn_connection:2451 EMS info added : serial number FCTEMS8823008006, tenant id 00000000000000000000000000000000 20241112 09:58:28.682 TZ=-0300 [sslvpn:DEBG] main:1609 Create socket connection 20241112 09:58:28.695 TZ=-0300 [sslvpn:DEBG] main:1687 Message to UI: A FortiToken code is required for SSL-VPN login authentication. 20241112 09:58:28.695 TZ=-0300 [sslvpn:DEBG] main:1705 153 bytes sent. 20241112 09:58:36.260 TZ=-0300 [sslvpn:DEBG] vpn_connection:659 http connection closed. 20241112 09:58:36.260 TZ=-0300 [sslvpn:DEBG] vpn_connection:521 R
Hello communityI have a question, if anyone can help me.I would like to work for Fortinet in Switzerland, in or around Geneva. Would anyone have a contact to advise me at Fortinet to apply or call me?thank you in advance for your reply.
I have a fortigate in the cloud that when the flow from a linux server passes through it, the source machine in question is on the Oracle Cloud internal network and the destination private load balancer is on another Oracle Cloud network, but I want to force them to communicate only by passing through the firewall. I can close telnet, which shows that the route is correct. I can connect to the destination, but when I try to execute the connection via the linux command line using SSL, it does not negotiate, giving an SSL Handshake error. The problem only occurs when passing through fortigate.If I go through the VPN in others to the same Load Balancer it works normally, only when the connection is coming from an internal network to another internal network that the error occurs. The tests performed were done both with NAT active and without NAT active, but in both tests the error persisted.
Hello,I'm trying to create a notification when my internet link is down to send a message by e-mail, but I'm getting 3 e-mails with DOWN and UP status, would you have a tutorial I can see where I'm going wrong? Another thing, would it be possible to send this by telegram or WhatsApp? I can't do it through teams because Microsoft is giving me an error in the apps. I'll send a printout of my settings
hi,i plan to configure a couple of VDOMs in a FGT, one VDOM is our "main" internet VDOM connected to ISP (and downstream customer VDOMs).i plan to deploy another customer VDOM with eBGP integration.is this VDOM design/setup feasible? are there any "gotcha" that i should know?
Hello all, I am currently preparing QoS for a Dante audio network for some FortiSwitches managed by Fortigate / FortiLink. Dante needs at least priority for PTP (CS7, high) and Audio (EF, medium), and optional for other reserved traffic (CS1, low) according to following documentation:www.getdante.com/support/faq/how-does-dante-use-dscp-diffserv-priority-values-when-configuring-qos/ As far as I understood the Fortiswitch QoS concept, it should be sufficient to map the different DSCP values to different queue-numbers according to their priority (higher priority, higher queue) and to use the default "strict" scheduling, so that higher queues (e.g. the queue for PTP) are always serviced first. DSCP Mapping:CS1 to cos-queue 1 (reserved)EF to cos-queue 5 (audio)CS7 to cos-queue 6 (PTP) QoS Policystrict scheduling for all above named queues Port configurationMap the QoS policy to all uplink-portsTrust DSCP map on all Dante endpoint access ports Would you recommen
Hai we got FortiGate F201E with 7.0.17 matured versionUnable to find any upgrade path on gui and support tool to 7.2 or above any version if we manually choose any version and update ,will there be a chance loose configuration . any end of support announcement for 201EFirewall in critical production
The last time I deleted an old DDNS entry on a Fortigate that had been thrown away, I simply contacted TAC, and they deleted the record. Now TAC says that there has to be a valid subscription in order to have a DDNS entry deleted. The Fortigate in question was End of Life years ago, so renewing the subscription is impossible. How can this be solved, and can it be solved without contacting TAC and creating a support ticket?
Hi FGT/FPX adminsRegarding the latest security incident, IR number FG-IR-24-535 // CVE ID CVE-2024-55591, that affected some FortiOS versions.https://www.fortiguard.com/psirt/FG-IR-24-535Additionally to the remediation actions described on the PSIRT page, you may check if your IP address is affected (published by some third parties) and take the appropriate action if so.
Hi Team, The site to site has already Up.From HQ to Branch Okay, everything can Ping and access.From Branch to HQ unable to ping and access.Route and policy has done on HQ FortiGate 80F.HQ - FortiGate 80FBO - Sophos UTM 9HQ subnet - 192.168.110.0BO subnet - 192.168.1.0, 192.168.3.0 Is it possible I need to add extra Route and Policy on the Branch Sophos UTM?
Hi all,I have installed an additional ISP on my Fortinet firewall, the policy has been applied successfully. I have also 2 catalyst manageable switch. the main directly connected to the switch and the second by hyperlink to the mail.all users from the first switch work well, they get internet, etc... but all users from the second switch do not get internet connection
hi,i'm going to configure a new FGT.is it preferred to put/configure ALL VIP/DNAT rules on top then put ALL FW policy/SNAT afterwards?can someone advise what's the best practice in FGT?
I can no longer connect to the console of my FortiGate 60F.Does anyone know how to solve this?I am trying to access the console with teraterm. When I start up fortigate, I can access the console, but after a while, pressing Enter does not respond.I believe there is no physical problem because I can connect to the console of devices other than fortigate using the same cable and PC.The firmware I am using is FGT60F-7.4.5-FW-build2702-240916.
Hi Team,I'm trying to Create an IPSEC Site to Site to a Sophos UTM.Below was my configuration in FortiGate: Just wanna to confirm that my configure correct or not as default. FortiGate
Hi Everyone,I have a FortiGate 40F firewall and a 48-port Unifi switch. I am using different vlans to manage Wi-FI for our customers, Wi-Fi for our staff, Local LAN, CCTV and IP Phone on the same switch. I am facing voice breaking issue on my IP Phones. I want to implement VOICE QOS so that my IP Telephones gets high priority and get clear voice without any break. Can anybody guide me on this how can I create VOICE QOS. I have created a QOS with minimum bandwidth of 20MB and maximum of 100Mbps but that is not helping.
Hello everyone,I installed the latest version 7.4.2.1737 of FortiClient VPN, but when I try to connect, the program gets stuck at 10%. It seems like the application adds extra characters to the password field when I click on "Connect" (the field shows more * than it initially did).All updates have been applied. I even installed this https://aka.ms/vs/17/release/vc_redist.x64.exe as recommended on a forum.Regards. Edit: it's working after fresh uninstall.
Hello, we're in the process of planning/implementing application policies and having a hard time understanding matching criteria and how a profile entry behaves with an application policy defined. Looking at a profile based policy and using DNS as an example, I could create an app policy with the block action set for DNS related application signatures and associate that to the LAN -> WAN policy entry which would then block devices in the LAN zone from reaching DNS servers in the public cloud. Is what I don't understand is what happens when you need to apply multiple policies? Say I need to block the entire LAN zone from using public DNS but then wanted to block TeamViewer for a specific network inside the LAN zone. The traffic would process down the list and match the first profile entry (Lets say that's the TeamViewer blocking entry) carrying a DNS payload and that policy isn't going to match application and then allow the traffic out to the internet and
Dear Team,According to the article "Technical Tip: Special Notice for low end units (<2Gb RAM) upgrading to FortiOS 7.4.4 and 7.6.0," or "SSL VPN not supported on FortiGate 90G series models" We understand that FortiGate units with less than 2GB RAM will lose SSL VPN functionality, including the security posture check supported by SSL VPN, when upgrading to newer versions. I would like to inquire about the core reason for this. Will larger models of FortiGate also face this dilemma in the future? Additionally, if larger models also gradually do not support SSL VPN along with the security posture check, what would be the alternative solution?Regards,Bruce Liu
Hello Fortinet Community I have an issue with traffic distribution, the traffic is not distributed evenly between my wan interfaces. I came to realize that the weight of member(2) is not 0 so that I can achieve load-balancing between both interfaces. AlUla-FW # diagnose sys sdwan memberMember(1): transport-group: 0, interface: port1, flags=0x0 , gateway: 10.0.1.1, source 10.0.1.10, priority: 1 1024, weight: 0Config volume ratio: 1, last reading: 4357479365138B, overload volume 227260MBMember(2): transport-group: 0, interface: port3, flags=0x0 , gateway: 10.0.4.1, source 10.0.4.10, priority: 1 1024, weight: 37Config volume ratio: 1, last reading: 2419071026478B, volume room 37MB Can anyone advice on how to change the weight of the second member. Thank You.
Hi, Has anyone tried creating sql query to check bandwidth to specific destination tcp port?
I work with a big governamental network that uses sdwan solution. Recently we are having some issues according to PPPoE debugging. Let's pretend that there are 2 links working in PPPoE mode. Then, when we are trying to debug (diag debug application PPP -1) we don't from what PPPoE interface the logs are coming. Is there some way to find out from what interface is that debugging?
Hi All, URL blocking using both method - FortiGuard Category Based Filter with static url fitler. Scenario 1 : I don't want to block entire category, want to block specific url. >>>>>>> When I am blocking static url in URL Filter then it is working, URLs are getting blocked. Scenario 2: I want to block entire category, want to allow specific url. When I block entire category in fortiguard category filter and in the static URL filter allow the URL (facebook.com) even then it is getting blocked.When I choose exmpt then it is working.Also I use web rating override then it is working. My questions are why URL is not getting allowed when I block entire cateory in Fortiguard category file (social media). which one will be given prefernce during web filtering :Static URL filter or Fortigaurd category filter. thanks
Hi All, We alle share great knowledge here, and in the Knowledge Base.. but it seems like the Search feature has 'gone on holliday'?!?Or have I gone totally blind?I can't find any search feature here on the Support Forum, or on the Fortinet Community page.. do Fortinet expect us to search via external search engines and make a site:community.fortinet.com addition there? That seems like crazy silly... PS: Label is bogus, as there is not Community
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.