User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hi to all!! i setup my first ring topology and i am facing random internet disruptions. I have lots of experience on star topology.I am using 2x FG-100F in HA with 2 ISPs. SD-WAN is using pinging to 8.8.8.8 for failover checks. Ports 1 from each Firewall are connected to switch No1. Ports 13 from each Firewall are connected to switch No10. All 10 switches are connected with fiber cables in a ring mode. We are using Fortilink with type aggregate with split disabled. Fortlink includes ports 1 and 13 only. What i am facing is random packet losses when i am pinging from any firewall to 8.8.8.8. If i disconnect the firewalls and connect my laptop with public ip configured, i have no losses. So, i don't think the ISP is an issue. Note1: My FGs are using 7.0.16 FW and my FSs are using 7.4.2Note2: I am not familiar with MCLAG and i don't know if it is needed here.
The goal is to restore a saved database from my PC to a new Fortinac build running Forti-OS v7.2.8. Following this article.https://community.fortinet.com/t5/FortiNAC/Technical-Tip-Restore-FortiNAC-Database-from-CLI/ta-p/201729 Having two issues: 1- Using WinSCP, I connect to Fortinac, get authenticated, but it stalls out at "starting the session". Same result on multiple NAC appliances. 2- Looking at my directory structure in the linux shell, I do not even have this directory: "/bsc/campusMgr/master_loader/mysql/" Any ideas ?
Hi all,since there is a knowledge base article about it, I was wondering if a HA setup with the "exec ha ignore-hardware-revision enable" set is officially supported. Meaning will support assist in troubleshooting, if there are any issues with the firmware for example or specifically the HA clustering?Thank you.
Firewall: FortiGate 60FFirmware: 6.4.8 Build 1914 (GA)Mode: NATNGFW Mode: Profile-basedCentral SNAT: EnabledSwitches: S148FPSwitches Firmware: S148FP-v7.0.2-build0049 Issue: VLAN 30 (Workstations) cannot add a printer via TCPIP to VLAN 60 (Printers) Firewall Policy is set to wide open for traffic to pass either way, but cannot connect any printer. I have tried to use a NAT rule going both ways with no luck. Also tried a multicast policy both way with no luck. Been going back and fourth with a Fortinet tech but have gotten no where. If more details are required, please let me know. Any advise would be appreciated.
Hi,I am getting the same error message same as in this KB: Incompatibilities with NGFW Policy mode d... - Fortinet Community Already tried to use a Custom Application Group, but I'm still getting the same error message:"app 43322 is incompatible with NGFW Policy mode due its large scan-range detection requirements." Is there any other way to resolve this? How do I know which value to input if I adjust this part of the configuration?config ips global set ngfw-max-scan-range 4096end
Hi I'm unable to log into the VPN on my laptop, however I can login on my colleagues. When we try on my laptop we get the following error; SSLVPN Error: Code=-30001010(v1.0.1041).HTTPS failed(NullResponse)HTTPS Exception: HResult=0x80072EFDA connection with the server could not be established We are running the same version/build of Windows and all updates have been applied. The Forticlient software has been setup through Windows > Settings > Network & Internet > VPN
Hi All, I'm using "Device Identity" feature. My device, a Tablet Android (TAB_RFLPTM000001) have the mac address "38:2d:d1:8f:ef:a5". At this moment it get the IP "10.10.0.201" by DHCP (Windows Server, not firewall). In Device Definitions page it show using another IP address "10.10.0.198". Look the arp table attached and see that in arp table the relation between MAC<->IP is corret, but in device definitions not. I think that because this the traffic is not getting in the correct policy. How the firewall check the correct IP address of the Device? Any suggestion? Look attached. Regards.
Hello everyone;There is an Enterasys B5G 48P switch in our institution. We ordered FortiNAC. Has anyone configured it with B5 before without any problems? I couldn't find a detailed solution in the documentation.
Hi, Can 2x 10 GE SFP+ FortiLinks ports be used as WAN or LAN ports? If yes is there any document to set as WAN or LAN?Upon checking the datasheet they have already GE RJ45 WAN Ports. Thanks!
Hi, I have a FortiManager running 7.4 with three ADOMs. I am using tacacs+ wildcard authentication with accprofile override using Cisco ISE as authentication server. All administrators authentication get Read_Write profile for all ADOMs. I would like to use the feature per-ADOM admin profile as described in this article to give administrators belonging to "Group1" to get Read_Write for one of the ADOMs and Read_Only for all of the others. From the article above this seems possible with ext-auth-adom-override enabled. However, I am not sure how this would be configured on the tacacs server as that is not covered in the article.Today I send the following attributes from TACACS server:service=fortigateadmin_prof=Read_Writeadom=Adom1adom=Adom2adom=Adom3. How should I configure the tacacs server to send Read_Write for Adom1 and Read_Only for Adom2 and Adom3?
Dear Fortinet Support Team, I am currently facing two issues with my Fortigate 60F device, running firmware version 7.6.1, and I would appreciate your assistance. 1- Enabling Explicit Proxy:I am trying to enable the Explicit Proxy feature on my Fortigate 60F device. However, I am unable to find this option in the "Feature Visibility" section. Could you please guide me on how to enable this feature or help me identify why it's not appearing in the list? 2- Advanced DLP Features:The "Advanced DLP Features" are currently disabled, and I received the following message: To use the advanced features, the main Data Loss Prevention feature must first be enabled in Feature Visibility or via the CLI: config system settings set gui-dlp-profile enable end Unfortunately, I received the following error message: command parse error before 'gui-dlp-profile' Command fail. Return code -61 Could you kindly advise on how to resolve this issue and suc
Hi Fortinet Community,im working with fortinet to use the VPN as a bridge to my customer server, and i can't use Fortinet VPN on my Macbook pro M1 and when fortinet ask permission to access the system preference etc, i couldn't find the setting, i would like to know is there any solution for this? or Fortinet VPN is actually can't run on Macbook Pro M1.Thanks.
Hi Team,Is it necessary to have a Fortimanager to manage the Forti VNF that will be deploymed on a VMWare SD WAN edge https://docs.vmware.com/en/VMware-SD-WAN/3.3/VMware-SD-WAN-by-VeloCloud-Administration-Guide/GUID-B67A0A3B-45A5-4C06-B892-AB88932EBF7D.htmlas per this document it asks for it but is it necessary or do we have any other way to manage the VNF on VCE.Regards,Sanjay S
Hello everyone,How can I configure FortiClient VPN (full-tunnel mode) to:Use internal DNS server (e.g. 192.168.1.x) for resolving internal domain names onlyUse public DNS (8.8.8.8) for all external domain queriesAvoid the current 6+second delay caused by failed DNS resolution attempts to internal DNSCurrently, all DNS queries first try the internal DNS server before failing over to 8.8.8.8, causing noticeable delays. I want to maintain full-tunnel mode for security but need more efficient DNS resolution.I am attaching screenshot an nslookup and the tunnel configuration so you guys have a clearer understanding and hopefully can help me.
HelloOn support portal, asset management, when you want to register a new asset, you have the below choice:-------------------------------------------------------End User TypeThe product will be used by A government user A non-government userIn this context a government end user is any central, regional or local government department, agency, or other entity performing governmental functions, including:Governmental research institutions.Governmental corporations or their separate business units which are engaged in the manufacture or distribution of items or services controlled on the Wassenaar Munitions List.International governmental organizations.------------------------------------------------------- I'm purely technical and don't know much things about the regulations, so I have the following simple questions:Is there anything additional required to register a product for government usage?What if a gov user selects by mistake "A non-government user"? Can it impact
Hellowe have a problem that we unable to allow fortitray. If we try to use Forticlient VPN only version to connect to our vpn, it prompts a windows that Fortitray needs to be allowed. If we press on open security & privacy it just shows the general screen of security & privacy and not the windows where you can allow fortitray. We were using Forticlient 7.0.3 and upgraded to 7.0.7 but the issue persists.
I have a lot of user web traffic that is ultimately hitting the implicit deny because instead of matching the general 80/443 web rule we have in place with the appropriate UTM, it is hitting the implicit deny. The commonality with all of this traffic is that rather than being seen as SSL or web browser application traffic it is being seen as a CDN application (Akamai, Fastly, AWS, etc...). I'm trying to determine what would be the best way to handle it. I thought about creating a clone of the standard web browsing rule and making it specific with CDN applications, but in the logs they all report as "unscanned" sites and I don't think the web filtering would work in those cases, which I fear would leave some holes I don't want. Was hoping someone else has dealt with this, or something similar, and had a course of action they took. Thanks!
I'm on a FortiGate 61F running 7.4.3. I have a VoIP PBX behind it using SIP Trunks. When this was all set up originally I only had a single WAN connection (connected to WAN 2), and I did have to disable the SIP ALG helper in order to resolve dropped call issues. I used this command and found the entry dealing with SIP and port 5060:config system session-helpershowI deleted it and all was well. Now I have added a backup ISP which is connected to WAN 1. When on the backup I have calls dropping and I narrowed it down to SIP ALG by using a SIP ALG detector exe. When I run the detector on a laptop behind the forti on primary WAN it does not detect SIP ALG.When I run the detector on a laptop behind the forti on backup WAN it does not detect SIP ALG on TCP.When I run the detector on a laptop connected directly to the backup WAN modem it does not detect SIP ALG.I thought deleting that session-helper entry was global, not just for one of the WAN por
Hi all¡ I have a simple scenario where 2 fortigates connect to area 0 using a Point to Point OSPF network and a /30 IPv4 network.One distributes connected routes and the other receives them. I would like to filter some of those routes using a route map with an ACL but, when I apply it the routes are not filtered. I have created 2 ACL, one used to filter one network and another used to permit all the rest of traffic. Finally, a route map with these 2 ACL. config router access-listedit "ACL_OSPF_DENY"config ruleedit 1set prefix 192.168.1.0 255.255.255.0set exact-match enablenextendnextedit "ACL_OSPF_PERMITANY"config ruleedit 1set prefix anyset exact-match enable <-- comment, witouth this command it doesn't work either. config router route-mapedit "RM-OSPF"config ruleedit 1set action denyset match-ip-address "ACL_OSPF_DENY"nextedit 2set match-ip-address "ACL_OSPF_PERMITANY"If I get the OSPF routes afther having applied the route map (using GUI), the 192.168.1.0 netw
Hi,Hoping that someone could help in regards to the correct OID required to query FortiAuth-VM in order to get the number of FortiTokens available for usage, since the one I've found in a old forum post is not returning the correct value - https://community.fortinet.com/t5/Support-Forum/FortiAuthenticator-OIDs/td-p/228761 Upon querying, 1.3.6.1.4.1.12356.113.1.202.6.0 , I get a value of 244 which is more than the total amount of registered/available tokens in FAC-VM. iso.3.6.1.4.1.12356.113.1.202.6.0 = INTEGER: 244FortiToken MobileUsed: 148Populated: 155Available: 7Disabled: 0 Using .1.3.6.1.4.1.12356.113.1.202.3.0 returns the correct amount of tokens since I also got 1 Yubikey registered (populated). iso.3.6.1.4.1.12356.113.1.202.3.0 = INTEGER: 156FortiToken Mobile / Yubikey TokensUsed: 148Populated: 155Available: 7Disabled: 0Used: 0Populated: 1Available: 1Disabled: 0I am trying to create a plugin in the internal monitoring platform in order to
Hi, Our FortiWLC 50D died on us and I am trying to see if I can rescue our little wifi network with a Fortigate VM. We only have 5 FortiAP access points. The evaluation license claims that the only limitations are:Support for low encryption operation onlyMaximum of 1 CPU and 2GiB of memoryMaximum of three interfaces, firewall policies, and routes eachNo FortiCare Supporthowever, the menu called "Managed FortiAPs" simply does not appear. I have checked the Feature visibility setting, rebooted and so on.. It is running version v7.6.1 build3457, I also tested 7.2.10. build1706, same issue. The docs also states that: "Hardware configuration restrictions apply." but I can't find any details on this. I have been trying to figure out how the licenses work, but it is hard. From what I can tell a one year license is about double the price of a FortiGate 40F which I don't need a license for and will manage our little network just fine. Please he
Hello,I'm trying to dedicate one wan link to a server in my infrastructure. I'm using a cluster of 601F, 3 Vdoms (Root, Internal, housing). The wan i want to use for my server is already NATed (ISP router cannot be set in bridge mode....) So i created the wan interface, using a private IP (192.168.10.10/24) on one VLAN interface of my root Vdom. Firewall is able to ping the ISP router But then i can't understand how i'm supposed to route traffic to/from my server through the 2 vdoms ...Do i need to create a VIP on the root vdom, pointing to the IP address of the internal Vdom on the Vlnk and then another VIP on the internal Vdom pointing to the server ?Is there any other solutions ? Thank youMatthieu
Hello, I have two fortigate 200f computers configured in HA active-active, a few days ago the master entered an error, when trying to start again it got stuck in activating the ram, the case was escalated with fortinet and RMA was made, however , this continued to happen, to this day the devices have been changed twice by RMA and it continues to happen, the firmware is at version 7.2.3. Does this happen to anyone else? Do you know how it can be solved?Regards!
For MAC-based filtering, please ensure the below points What is the maximum limit of MAC addresses that can be added?If we utilize the maximum limit of MAC address entry, is it to be cause any performance-related issues on the wireless controller (FGT) and FAP?Is there any option to import bulk MAC addresses from FMG at once or to add multiple MAC addresses one by one?
i can't run more than one VPN ipsec remote access .as i have make two VPN (admin, sales )i cant access to tunnel sales from the forticlient . and when review the logg i see that any vpn match with admin tunnel , so it cant be up as its doesnt have the same preshared key if i want to join with sales i have to disable the Tunnel VPN (admin).does anyone know how to solve this
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.