Mark a Best Answer
Fortinet Community
Recently active
How do I get FCREMOVE.exe for a free copy of Forticlient I am unable to download the tools and I have a free copy of Forticlient installed and I can not remove it It is not showing in add/remove programs. We can't uninstall We can't install. We are stuck Any ideas?
Hello all,I am trying to get IPSec VPN with 2FA to work on a 60F running 7.6.1I have used the Wizard to create the VPN, and I have tried to manually set up the VPN tunnel, I have also followed the available instructions to create the tunnel via CLI. It all ends in the same problem : I have a working P1 and P2, I get prompted for the token, and FortiClient claims it´s connected. I can see the traffic counter counting traffic to the firewall, but not receiving anything.I have set up FortiAnalyzer, and there I can see the traffic as allowed traffic hitting the correct policy.I can see the session in FortiView on the firewall, with traffic in both directions. Neither traffic sniffer nor flow debug shows any packet. I have tried two different Windows endpoints, all the same. Spent one week on this. Where can I dig now ? Cheers, Chris
One of our reports are returning empty.Already checked the empty reports guide on KB and haven't helped:- FortiAnalyzer 7.4.6- Fortigate 7.4.6 (target device that returns empty report).- Dataset live data test OK (selecting the target device).- Chart live data test OK (selecting the target device).- Creating a report containing the above chart and selecting the target device returns empty.- Workaround: if we move the name of the target device into to the dataset and run again with "all devices" option, it works. Any ideias what could be wrong?
I'm using the forticlient with Ubuntu 24.04.1 LTS. After running an apt upgrade the forticlient was also upgraded from version 7.2.5.0854 to 7.2.7.0905. Now I'm no longer able to connect to my VPN. I get the following error messages in the log file sslvpn.log: 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] nmtools:255 Command to set ipv4.ignore-auto-routes returned with status 256. 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] nmtools:1060 Failed to modify connection docker0 property ipv4.ignore-auto-routes 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] dns:1007 Failed to finish Network Manager configuration 20241217 17:58:10.901 TZ=+0100 [sslvpn:EROR] vpn_connection:2072 Config DNS failed I have already removed some docker interfaces, which occurred before in the log as error messages, but I cannot remove the docker0 interface, only to get the client running. I have also upgraded to the Version 7.4, but I get the same error messages. I tried
Hello, I'm new to FortiWeb and would like to monitor the overall in-and-out throughput on the dashboard, with a time interval of either one week or 24 hours. Could you please assist me with this?
I have configured SNMP V3 on Fortigate Firewall with proper steps. After adding the device to opmanager getting ERROR showing "Credentials Not configured : Add valid credentials to monitor the performance metrics of the device". I have also enabled snmp access on the interface.
Hello Everyone,I want to configure DKIM on our Fortimail unit to sign outgoing messages, but I have a lot of questions that I need your help with. First of all, our Fortimail unit is 200F unit, working in transparent mode. We have 2 protected domains configured inside this unit. The two domains are MS exchange serversFor my questions:Can I configure the DKIM signing in Transparent mode, or it should be in gateway or server mode for this to work?If it is applicable in transparent mode, and I successfully configured it, will this configuration be affected or stop working if I change the working mode of the fortimail unit to gateway mode?Do I have to make a record for the DKIM inside my exchange servers internal DNS, or it should be published only on the external DNS?Does the protected domains SSL certificates have to be imported inside the Fortimail, or the DKIM has nothing to do with the certificates?Is it better to configure the DKIM inside my exchange servers, or it's better to be con
Hello, I am working on cleaning up security vulnerabilities on users within the FortiClient EMS which typically lacks a DC connection and operates in a complex structure. There are over 100 computers with 7-Zip installed, and they want it removed. Is there a way to achieve this through EMS ?
Hello, we just put in 2 branches a FG 80 cluster with 7.4.5. Both connected to Arruba Switch with ISP A Internet Access and ISP B 5G Failover. Our ISP now comments that the 5G router are in dormant and they dont reveice the VRRP events. Since router and 5G backup are connected to the switch I dont see why we should configure multicast policy. Trying out with multicast policy we risk some strange behavior with the Fortigates? Thanks!
We are using a services name Endpoint Central, but oneday my Firewall aret condition about this services as malicious-url.i'm adding this to whitelist, web overrated, policy but not successful.Maybe the mistake, how can i remove this services from malicious-url.  
I'm trying to set up Wake on LAN (WOL) so that I can wake my work PC from home. I can wake my PC from within our local network, but not from my home computer. The company is not keen on setting up port forwarding to broadcast the Wake on LAN packet (magic packet) for security reasons, but they have given me SSL-VPN access to the company server. However, when I run the Wake on LAN program from home, it doesn't wake my computer. I did a search on the Internet, and apparently VPNs don't like doing broadcasts. Does anyone know if there is a setting in the FortiGate 400D that I can configure to allow it broadcast the magic packet via VPN access?
i have problem when i add fortigate to fortimamanger ver 7.6 this command config system global set fgfm-peercert-withoutsn enableendnot in fortimamanger 7.6
I have a FortiGate 101F that I just set up and I created a few policies like in the image below.Everything is working but can someone check if I've done it right. Internal LAN, is out network switch/Access point, Maxis-Internet is or internet line. Have I done the security profiles correctly?We're not subscribed to AntiVirus, so that's why its not in Internet policy, but somehow there's a basic one for Internal.
I have two FG61Fs running 7.4.6 with a Dial-Up IPSec VPN between them. I recently added a second WAN connection for failover purposes. I use the link monitor to kill the static route with higher priority when my primary goes down. That works great. For the VPN, I added a second tunnel bound to the backup WAN interface. Both IPSec interfaces are in a zone, and I use the zone in the policies. I cloned the static route from the original tunnel and changed the interface to the new backup tunnel and gave it a greater priority value than the original.The screenshot below shows the remote side. This is what I see when on my primary WAN. If I unplug the primary WAN at the home office, the HomeOfficeTMO (backup) tunnel Phase 2 comes up - but I can't pass any traffic over it. If I manually disable the Static Route for the primary WAN tunnel on the Home Office, it starts to work. I thought that if the primary WAN tunnel was down that woul
Hello everyone, We have a DNS record that currently points to one of our Public IP Addresses.With a VIP, the traffic is sent to our Big IP F5 where an irule is defined to redirect the traffic to an external public website (https). I would like to do the same but directly from the Fortigate and not use the our F5.Can this be done ?Thanks
Looked at the admin guide, and the example it shows, is www.google.com (As a subnet object???)Need to add a simple subnet object like "192.168.0.0/16". Is this possible?I have many address objects of type Subnet, that were created in a FortiGate before FortiManager came along. When trying to add in FortiManager, It clears the subnet address I try to add within IP/Netmask and then says "Invalid IP address"Does FortiManager have a different concept of a subnet address object than the FortiGate does?I know I can add an IP range (probably), but that means I have to go through and edit "all" of the exiting definitions. In the FortiGate, when adding a subnet object, I can name it something like "sn-bob" and it does (or at least did not previously) require that it resolve to anything. I'm hoping that I am missing something stupid.
I'm having an issue with Dual 5g mode on my FP231G APs. Radio 1 is offRadio 2 is the low 5g channelsRadio 3 is the high 5g channels Dense deployment (it's a school and every classroom has an AP) The issue is all clients are only connecting to radio 2. Radio 3 is propagating, I can see it with the fluke WIFI scanner. DAARP is working, the client experience is pretty good except I'm getting some very high channel utilization numbers due to the fact that the clients are all connected to just 4 channels on radio 2. I made a new connection profile with single radio 5g and that's working great, all the channels are utilized and my channel utilization issues are gone or very minimal. I made a test profile with dual 5g enabled, radios 1 and 2 off, and clients connect to radio 3 without a problem. My questions are:Is there a way in the config to encourage clients to connect to radio 3 when using dual 5g mode? Is this likely just a client issue and
"I have two FAZ devices at two different locations, and I want to configure HA between them. There is an MPLS link between the sites, and both FAZ devices are in different subnets. Can we create a VRRP cluster across two different subnets?"
We recently upgraded multiple FortiGates (60F through 2600F) to 7.2.8 the day after the latest release was made available. Last week, one of these (60F) stopped passing traffic. We could ping the management interface and could do a "tnc -p 443 <IP>" where we'd see the 3-way handshake in a packet capture, but the login page would time out. We tried to console in - there was no prompt, but it'd echo back what we typed in. I did try an "exec reload", but nothing happened. But then, we couldn't get authenticated. This firewall required a hard reboot to bring back online. The only significant things in the system logs were these two events: - Critical: Kernel enters memory conserve mode- Critical: Kernel enters extreme low memory mode This was just a few msec after an antivirus update, but I'm not certain if they are related. We had the exact same thing happen today on another FortiGate. We have an upgrade scheduled for the main hospital this Friday, but I'm very hesita
HelloAll "internal" Fortigates send logs to our Fortianalyzer's port1.We want a "dmz" Fortigate to send logs to Fortianalyzer's port2, this is because traffic from "dmz" to "internal" is not permited.How can i isolate traffic between Fortianalyzer's ports in order to safeguard the above policy?The dmz Fortigate is not hosted to us so we can not use a mgmt interface. Thanks
Hello,We have a customer currently using IPSEC VPN using a pre shared key. The users sign-in using their on-prem AD username and password. We have ADSync setup sync the accounts to Microsoft 365 and the PC’s are hybird joined. The customer would like to start using Microsoft MFA to authenticate the VPN. I can’t seem to find a step by step guide to set this up has anyone setup this that can provide information on how to set it up correctly? Ideally I want to keep the current IPSEC setup but just add Microsoft MFA to authenticate.
Hi all, I have a problem, Fortinet support have been less than useful. FortiGate We have a cloudflare Zero trust setup that stops any DNS requests to malicious sites. What I want to do is intercept these requests on the Fortigate before they get to Cloudflare.In the past I have been manually adding eachnew site that cloudflare makes me aware of, this is time consuming. I have been on leave and returned to over 100 URLs to add to the DNS filter on the Fortigate. I was hoping to just import a csv or text file of the URLs into the Fortigate DNS filter list. Apparently this is not possible. I have seen some talk of using a cloudflare API to do this but not sure how. Has anyone found a way to do this. The Stock Frotinet answer of "put in a new feature request" is laughable when solutions are needed quickly and when we all know, that feature will never get added. I don't know why they can't have a plain text input for the list. E.G. on our smoothwall
I can only add one, like I do to add 14 domains. I need it to be with Let's encrypts. Can you help me? thank you
Hello, Can we create a local user for SSL-VPN to change password after there 1st login?
Hello,Is there an option to extend the forticlient ems cloud session time? By default the time is very short.Thanks.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.