User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hello,From yesterday we experiencing problems with websites beeing blocked because they belong to category that is blocked. This category is "unrated" which under DNS Filter is set to Redirect to block page.One of those websites is "docs.fortinet.com". Ofcourse that particular website category is "Information Technology", but for some reason Forigate categorizes it as "unrated".I can access docs.fortinet.com as soon as I add it to Static Domain Filter.To make the matters worse, this doesn't apply to every site.Where can I search the problem?
Hi,on my computers when Fortigate deny access on webpage and display message, this message have only text. When I see the same message on Fortigate configuration, I see that this message have also images and background. How could I fix this?
We're a K-12 boarding school with a ton of BYOD devices on our network. Currently, we have three SSIDs: Open (Mac auth), 802.1x MS-CHAP v2, and WPA2-Personal for guest access. We need to keep the open network around for devices that can't do 802.1x auth like gaming consoles. My question is, how do you handle BYOD device authentication? Is 802.1x still the only game in town? We need it to be fast and simple. I'd like to avoid EAP-TLS for these types of devices as it can make the onboarding more difficult. This is why we're still using EAP-PEAP. Any suggestions?
Someone has set up their FortiToken to go to my email and it's not my mates playing a prank...My email is somewhat exotic too, to manage to land that on the first try is impressive but also very bad for infosec.If you're a Marvel fan involving Goose and some German words, we need to have a quick chat.
Hi Eveyone, Just want to inquire what it the current recommended Firmware for FortiSwitch S148FF ? I got an information that the Firmware v7.6.0-build1015 is not that stable as of yet. Your comments is highly appreciated. Thanks in Advance !
Hello, We are currently running two FSSO agents for two different domains on two different servers under these domains. Is it possible to query two different domains from a single server with a single FSSO agent? Is it possible to install two different FSSO agents on a single server? What is the best practice method for this? Regards,
Hello, I have some questions. The customer branch and headquarters use devices from other vendors to establish IPsec tunnels for internal network access. The headquarters exit firewall is Fortigate, and the IPsec encrypted traffic for internal network access passes through Fortigate. In this case, can Fortigate provide security protection for the traffic of these internal network access
We have a few clients with public facing Citrix NetScalers with a login using MFA. The Fortigate has got Deny for Threat Feeds and limited to Geography of 1 county. but we users are getting hit with password lock outs against AD before the MFA kicks in. Can ZTNA be please in front of the public facing VIP https mapping and only open up if the Forticlient is present and connected? I have concerns on the Citrix Published desktop launching and working correctly using the Citrix Workspace client application to connect via the https proxy the Netscaler provides. via the HTTP Proxy ZTNA provides. Basically we need the ZTNA to only open up to the public IP's of Forticlients to the VIP's and not intercept nor tunnel traffic. Since Citrix already does the encryption and proxy of the ICA traffic over https. and adding it again into another session could likely break it and have massive performance issues.#XenApp #Citrix
Howdy Folks! I am new to the Network Engineering side of things, as I was a Sales Engineer/Solution Architect for the last 15 years. That being said, I have a laymen's understanding of the FortiGates, but very little hands-on configuration experience. I reviewed the VDOM overview (https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/), and think I have a general understanding of what needs to be done, but need to understand the "why", order of operation, and dependencies so I can put all the different piece of the puzzle together.The above document doesnt go into VDOM and VLANs, so there is a big area of question. I have been tasked to create an outline as to how to implement VDOMs in the following scenarios... Scenario#1 - Single WAN connection being broken out into (2) separate VLANs that require a separate VDOM for Management/control. Thought is to use VDOM1/Root to for the WAN-side FW instance and VDOMs 2&3 for the LAN-side VLAN specific F
Hello, I have configured a site-to-site VPN on a 40F with version v7.2.10 build1706 (Mature), which is listed above, the problem is that some computers can connect, others cannot connect from the same site, it is valid with the server administrator it indicates that there are no restrictions on connected users, in the policy as origin (LAN) there is an IP configured with a /24 mask in the policy there are no restrictions configurations some. I appreciate your help.
I created a SSL Realm because I had another SSO SAML with Azure ID, and I had to add another one for another diferent Tenant, but after doing all the configuration, the SSO for the new realm it's not appairing
Last year we launched a network security solution in the Azure Marketplace that protects both east-west and north-south traffic as it passes through Azure Virtual WAN (vWAN). This security is provided through FortiGate VM, in the form of a managed Network Virtual Appliance (NVA) There are multiple use cases supported with our offering. This includes a secure SD-WAN, SD-WAN with next-generation firewall (NGFW), and solely NGFW with layer 4-7 inspection. The integration of FortiGate VM with Secure SD-WAN and Azure vWAN allows users to more effectively interconnect with applications and workloads running in Azure with the rest of their hybrid and multi-cloud deployments. The result is an even simpler, further automated, and operationally efficient cloud on-ramp and SD-WAN experience and the ability to apply NGFW policies to vWAN traffic. Now, we have released an extension of this offering to include internet-inbound traffic, also known as Destination NAT. We are one o
Hello, I have a problem. Some companies do not have FortiGate licenses. Is it still possible to perform a firmware update? For example, from Firmware v7.4.3 build 2573 (Feature) to Firmware v7.6.1 build 2573 (Feature)
Hi All,The is an IPSec tunnel between a branch office and a head office. In the branch office there is a subnet 192.168.166.0/24 SSL VPN (10.212.134.0/24) - HO-FG - IPSec VPN Tunnel - BO (192.168.166.0/24) 192168.166.0/24 route with interface BO-TUNNEL is added as a static routeSubnet 10.212.134.0/24 - 192.168.166.0/24 is added in the VPN phase 2 settings. At the moment the issue is that when SSL VPN users connect to the HO the subnet 192.168.166.0/24 is not advertised so as a result SSL VPN users cannot access 192.168.166.0/24 subnet in the branch office. Could you please help to advertise 192.168.166.0/24 subnet to SSL VPN connections.
Hi, i have followed the configuration guide from the below link Configure SAML SSO for WiFi SSID over Cap... - Fortinet Community, and the authentication works well, within the default settings. However, since the captive portal user traffic is not encrypted, I decided to switch to WPA2 with PSK and captive portal. After this change, users receive an IP address (after providing the PSK), but the auth process doesn't occur, SAML auth request is not showing during the debug, and users see a "site cannot be reached" error when trying to access any website. Is it possible to configure SAML SSO but with any level of user traffic encryption? Fortigate 61f - soft 7.2.9
Hi, I have a problem with a remote IPsec connetion. I changed from SSL VPN to IPSec and now I have the problem, that the CEO wants to connect from home but unfortunately he has the same network at home (eg at home 10.10.14.0/24 and office 10.10.14.0/24). Since we cannot change network at the office and also we cant change anything at the home network we are looking for a solution. First I thought that only including remote hosts like e.g 10.10.14.250/32 in the IPSec config Accessible Networks could help but it was not the case. Any suggestions? Thanks!
When modifying any content in the VIP configuration file imported from Fortigate on Fortimanager, clicking the confirm button prompts Map to IPv6 Port This field is required. However, Fortigate does not actually enable IPv6. If using the VIP configuration file created from Fortimanager, this phenomenon does not occur. Fortimanager version is 7.4.5
Dear Community members, I am facing the issue with SDWAN un even traffic distribution, i have chosen all available load balancing algorithms but most of the sessions are always build on single zone member. Also i setup the SDWAN rules, the interface selection is on manual mode and load balancing is enable between both.
I am attempting to limit access to our SSL-VPN to only specific IP addresses. It works great for IPv4, but any clients on AT&T mobile internet don't work because they receive an IPv6 public IP address. I tried adding the public IPv6 addresses to the allowed hosts but it still will not allow the connection it just says "Unable to establish the VPN connection. The VPN server my be unreachable" For troubleshooting I added the "all" IPv6 addresses object to the allowed addresses group but it still will not allow a connection. I can't find in the logs were these blocked connections would be so that I can troubleshoot the issue. My questions are:Is there something else I need to do in the settings on the FortiGate-101F to allow these IPv6 connections?Where would I find the logs of connections blocked by the "Limit access to specific hosts" setting?
We are planning to set up a High Availability (HA) cluster in Active-Active mode using two FortiGate 901 firewalls.Our question is straightforward: is it possible to create and manage an HA Active-Active cluster without using FortiManager?As far as I understand, the creation of the HA cluster does not require FortiManager. After the cluster is established, all settings configured on the primary unit can be automatically synchronized to the secondary unit through FGCP. Additionally, the primary unit can be accessed and managed directly via its web interface.I would appreciate an official response to this query so that I can share it with my manager.Thank you for your assistance.
If you buy a new firewall alone, does it do anything like stnd packet filtering?If you buy DNS & Video Filtering Service, will it work alone and offer firmware updates or do you need this plus FortiCare?Thank you
We just changed firewall providers to Fortigate, and coming from Dell SonicWALL. We were referenced to the FortiConverter for moving policies/rules/migration over to the Fortigate. I'm a bit hesistent about doing so, as I feel like things won't be converted over entirely. I was curious about others experiences.I'm thinking about just running side-by-side and configuring as I go versus just copying/pasting contents between each platform.
I need help understanding how this all works. I have a small company so we opted to give out one invitation code per user. Now I am trying to setup a deployment and installer. In FortiClient EMS Cloud I created an Installer and linked it to an invitation. I then went to Manage Deployment and created a deployment for the previous installer. Since the user I picked on was my user account but on my Windows VM I started up the VM and made sure it was connected to the EMS server which it was. Nothing happened. I VPNed in with the older client. Nothing happened. I rebooted the VM. Nothing happened. First off, did I do the Installer / Deployment correctly? Secondly, what triggers the upgrade on the client side? And how long should I need to wait for the upgrade to happen?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.