User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hello,I'm trying to dedicate one wan link to a server in my infrastructure. I'm using a cluster of 601F, 3 Vdoms (Root, Internal, housing). The wan i want to use for my server is already NATed (ISP router cannot be set in bridge mode....) So i created the wan interface, using a private IP (192.168.10.10/24) on one VLAN interface of my root Vdom. Firewall is able to ping the ISP router But then i can't understand how i'm supposed to route traffic to/from my server through the 2 vdoms ...Do i need to create a VIP on the root vdom, pointing to the IP address of the internal Vdom on the Vlnk and then another VIP on the internal Vdom pointing to the server ?Is there any other solutions ? Thank youMatthieu
Hello, I have two fortigate 200f computers configured in HA active-active, a few days ago the master entered an error, when trying to start again it got stuck in activating the ram, the case was escalated with fortinet and RMA was made, however , this continued to happen, to this day the devices have been changed twice by RMA and it continues to happen, the firmware is at version 7.2.3. Does this happen to anyone else? Do you know how it can be solved?Regards!
For MAC-based filtering, please ensure the below points What is the maximum limit of MAC addresses that can be added?If we utilize the maximum limit of MAC address entry, is it to be cause any performance-related issues on the wireless controller (FGT) and FAP?Is there any option to import bulk MAC addresses from FMG at once or to add multiple MAC addresses one by one?
i can't run more than one VPN ipsec remote access .as i have make two VPN (admin, sales )i cant access to tunnel sales from the forticlient . and when review the logg i see that any vpn match with admin tunnel , so it cant be up as its doesnt have the same preshared key if i want to join with sales i have to disable the Tunnel VPN (admin).does anyone know how to solve this
I hope this post finds you well. I'm reaching out to the community for some expert advice on a persistent issue we've been facing for the past year. Despite multiple tickets with Fortinet support, we haven't been able to identify the root cause or find a lasting solution.The Problem: Our Canon printers are experiencing frequent disconnections from Uniflow (Print Server). This issue seems to be particularly prevalent after power failures in our remote offices. Interestingly, the printers reconnect after a couple of days or when we change the printer's IP address.Here's a bit about our network setup: Branch Fortinet firewall is connected to the HQ Fortinet firewall via an IPsec VPN.The print server is located in the HQ.The Printers are in our remote officesBranch firewall we are using Fortigate101F,81E,61F(Firmware 7.2.4)HQ firewall Fortigate601E(Firmware 7.2.4)Branch and HQ firewall are connected over IPsec VPN
So been running 7.6.0 since it has come out on my home fortigate. In 56 days the memory usage rose to about 83-84% when I just happened to log in and notice the high usage. 8 WAD services using about 13.3% usage each. Restarted WAD and memory dropped back down. Wanted to let the community know what I came across, don't have support on the fortigate so not able to open a ticket with them to provide them any information to help them discover the cause.
Hello everyoneA few weeks ago I was looking for a solution with the following post.....https://community.fortinet.com/t5/Support-Forum/Fortigate-7-6-1-policy-with-timer-and-passwort-release/m-p/365986#M259639Unfortunately it's still not the solution I want.I'm still looking for a way to somehow create a "session timer" with my Fortigate.I'm looking for a way to limit my children's devices, which are all enabled with fixed IP addresses via policies, so that an IP session can only access the Internet for 1 hour per day.Again for information...I am NOT looking for a solution with the scheduler because the internet hour is NOT at the same time every day.I'm looking for a solution to run an IP session for 1 hour daily.The solution with the web filter is very laborious and cumbersome (post with URL above).Don't you have another idea how I could implement this?Thank youGreetingsSwiss daddy
Hello, I need to connect a #Fortigate with FortiOS 7.4.6 and SDWAN by FortiClient VPN (IPSECIs there a way to achieve this goal? This article is about Site to Site scenario, but about client to SDWAN? Configure IPsec VPN with SD-WAN - Fortinet Community Thank you
hello team i have uploaded VM licence but the status is Serial-Number: FGVM00UNLICENSEDLicense Status: No LicenseLicense Expiration Date: 2024-03-04VM Resources: 1 CPU/0 allowed, 985 MB RAM/0 MB allowedLog hard disk: Not available --- PLEASE HELP---
Hi there! Is it possible to install the same single policy to say 5 FGT Clusters from Forti Mrg, but each of the 5 Clusters has different interface names? The same single policy will be pushed to each Cluster as a Global FW policy not a VDOM.............or is the only way via a VDOM with normalized interfaces from the FM? later mapping INTERNAL interface to Port1 on Cluster-1 and INTERNAL3 on Cluster-2 etc.........
Hello Community, I have an issue with my SD-WAN configuration maybe, the traffic is being distributed unevenly between the two interfaces. I tried all available options manual, best quality and lowest cost, non of these options distributed my traffic evenly. You can find below the ports usage and configuration:
Can I use forticlient on linux servers ?is forticlient endpoint supported on linux servers ?
Hello i have a problem when i set ha-mgmt-status with port mgmt1 I set vdom root in fg vm v 7.0 in this port but i cant port with the ip i assigned to this pruporse. FortiGate-VM64-KVM # show system interface mgmt1config system interfaceedit "mgmt1"set ip 192.168.25.3 255.255.255.0set allowaccess ping ssh httpset type aggregateset lldp-transmission enableset snmp-index 25nextendFortiGate-VM64-KVM # FortiGate-VM64-KVM # execute ping 192.168.25.3PING 192.168.25.3 (192.168.25.3): 56 data bytes64 bytes from 192.168.25.3: icmp_seq=0 ttl=255 time=0.6 ms64 bytes from 192.168.25.3: icmp_seq=1 ttl=255 time=0.1 ms64 bytes from 192.168.25.3: icmp_seq=2 ttl=255 time=0.2 ms64 bytes from 192.168.25.3: icmp_seq=3 ttl=255 time=0.1 ms64 bytes from 192.168.25.3: icmp_seq=4 ttl=255 time=0.0 ms--- 192.168.25.3 ping statistics ---5 packets transmitted, 5 packets received, 0% packet lossround-trip min/avg/max = 0.0/0.2/0.6 ms ortiGate-VM64-KVM # show system haconfig system haset gr
Hi all! How to extend VPN connection events via Forticlient, I need to add the hostname field to the logs.
Hello team!!!Happy new year to everyone using gregorian calendar!! I have the following 3 questions about Fortigate:1) To block phishing I am using web filter, is there another Fortigate feature to add, to help blocking phishing attempts?2) Is there any place in the Fortigate where I can see security alerts for applications installed on computers? I dont think so, but I'm asking just in case3) You know another feature to block suspicious network activities in addition to DOS rules and IPS profiles?This is for all the traffic comming through the Fortigate, not for traffic between 2 computers in the same LAN, of course. Thanks in advance.Regards,Damián
delete this post. I figured it out
I have a FG 100F with multiple vlans and DHCP is currently configured as well. The IT person is stating that when he tries to search PC's via "Network" none of the PC's populate. On his old LAN which consisted of a Cisco ASA he was able to browse PC's.Any thoughts of what could be causing this?
When I do a config export from VMware and try to import to KVM, I get: "Failed to restore system configuration: Cannot restore system configuration backed-up from FACVM model to the current model (FACVMKVM)" Is there a conversion command ? Can't seem to find one.
Hello,I’m curious about the differences between Authentication and Access under IP Policy and Recipient Policy on FortiMail. When Authentication and Access is enabled under Recipient Policy, it ensures the necessary authentication when accessing emails in the personal quarantine. However, I don’t fully understand what it does under IP Policy. Has anyone used or inquired about this before?And i know this " For webmail login, select an appropriate Authentication type and Authentication profileunder Authentication and Access when configuring an inbound recipient-based policy" , "IP-based policy authentication does not support webmail login." ThanksFortiMail
I have a FortiGate firewall and 4 Forti Switches. I want to configure the switches in stack mode, with one switch acting as the primary and another as the backup (secondary). I do not want to manage the switches through the FortiGate firewall. I want to achieve stacking similar to how Cisco switch stacking works. If it is possible please post here.
Hi folks, I've found that SSL Certificate Inspection in the configuration below, applied to my LAN -> WAN policy is substituting the NordVPN certificate with my Fortigate certificate. NordVPN is detecting the change and terminating the connection. If I disable certificate inspection, NordVPN connects without issue. When SSL Certificate Inspection is selected, it is not possible to add exceptions. I tried choosing Full SSL Inspection instead and added the exceptions for the NordVPN addresses below, but that yielded the same result. I upgraded from 7.4.5 to 7.4.6 and still have the same issue. Any ideas? Thanks in advance! NordVPN addresses excepted:*.nordvpn.com*.nordcdn.com*.rsc.cdn77.org*.nordlayer.com*.nordlinks.com*.nordapi.com Here is the NordVPN error: Here is the default SSL Certificate Inspection policy I have applied: Here is the "exception" policy I tried:
Hi Fortinet Community, There are two sites (on-prem and Azure) interconnected via IPSec VPN tunnel.Each site has one domain controller.Remote users when connect to on-prem get authenticated against the on-prem domain controller.The future plan is decommission on-prem infrastructure. However, when I try to point FortiGate router to the Azure domain controller there is no connection to it. 1) Is it normal that FortiGate router itself doesn't see the other side of the VPN tunnel?2) Is it possible to make it communicate with resources running on the other side of the VPN tunnel? Thanks.
Hi, Below is the result from a recent nmap scan on all TCP ports.nmap -p 1-65535 -T4 -A -v x.x.x.xPORT STATE SERVICE VERSION113/tcp closed ident179/tcp open tcpwrapped443/tcp open ssl/https50805/tcp open unknown1 service unrecognized despite returning data.we use 443 for https, I understand the BGP port tcp179. But I cant find reference of port 50805 anywhere. "diag sys tcpsock " doesnt list 50805, and neither does "Policy & Objects -> Local In" via GUI dashboard.how can we confirm what is listening on tcp 50805?Following the article below:https://community.fortinet.com/t5/FortiGate/Technical-Tip-View-which-ports-are-actively-open-and-in-use-by/ta-p/191523Thank you :)
With a limit of 10 SLAs per zone I'm a bit stumped.I have roughly 80 remote sites all connectong to the same hub, with 2x dialup tunnels per site. So 160 IPSec tunnels in the overlay.While each remote site can have its own SLA up to the Hub I can only configure 10 SLAs from the Hub to remote sites https://19216801.onl/ .This causes some performance issues for traffic sourcing from the Hub as it's path selection isn't checking the quality of the tunnels for all the remote sites.So what now?
您好,客户的 foritgate 60f 防火墙已购买 ATP 和工业安全服务的许可证,并将在生产环境中以透明模式部署。我想了解一下在这个环境下如何完成防火墙部署,这个部署有哪些注意事项,以及如何使用工业安全服务特性库
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.