Mark a Best Answer
Fortinet Community
Recently active
Hi all¡¡ In short, we have a Server for softphones in our DMZ and internal ToIP Servers. All traffic between servers passes trought a Fortigate. All traffic I'm going to talk about is SIP UDP Traffic. There is some strange things I don't understand. There are differences if I capture traffic from firewall or from servers. I don't have a rule to allow that the internal server Initiates SIP connections to DMZ server. Internal-->DMZ:5060 but I have a rule to allow 5060 traffic from DMZ server to Internal server DMZ-->Internal:5060. 1)If I capture SIP traffic from the ToIP servers (internal or external) it seems that it's the internal server that connects to the DMZ server 5060 port. The Invite packets are from Internal server to external server:50602)If I capture SIP traffic from the firewall (pcap) or I check a debug, it seems that it's the DMZ server that connects to the internal server 5060 port. The invite messages are send from the DMZ server to Internal se
Hey all,Just noticed a bunch of vulnerabilties from low-high impacting 7.2.9. Most of them are resolved in 7.2.10, but two of them require 7.4.5. It appears to be a mature release, anyone have any odd issues with it where it should be avoided? If so, what release >7.4.5 to you recommend for stability?Thanks!
Hello, Could we allow copy/paste throught RDP and SSL-VPN service (using FortiClient, not Bookmark)? Thank you for your help,Chris
Hi Team, Today I found a user event log as below User daemon-admin restored the image from ha-daemon And my firewall automatically upgraded from 7.4.5 to 7.4.6. Kindly confirm whether it is genuine or not.
Hi guys,I'm seeing a log in my fortiproxy where the traffic is denied due to 403 and the category is cat=225. Any idea what is this cat=225? I don't see this category anywhere in the web filter. Could 225 be a customized category in my fortiproxy? FortiGuard web filter categories | FortiGate / FortiOS 7.6.1 | Fortinet Document LibraryThanks!
Hello and sorry for my english, I want to schedule backup of my fortigate to SFTP server. So i installed new SFTP server. From CLI on fortigate, if i try the command : execute backup config sftp "/global/backup-global.conf" 172.21.0.32 SFTPuser 123654 it works perfectly, the configuration is save on remote server.So after that a create action with this command and execute with super_admin profile.After that i created trigger to launch Daily at 23:01After i created stitch with first trigger and second action script. But the stitch doesn't work at all. It is enable, script is OK so i don't understand why at all...On my fortigate, i have vdom, the stitch is on globalthanks a lot
Hi, We have 1 hub and 2 branches in our setup. All these 3 location has one internet link and one MPLS link (Hybrid underlays) We are having BGP on loopback overlay setup We have requirement of ADVPN between Spoke 1 to Spoke2, with the help of SDWAN rule we are steering this ADVPN traffic through internet link (And MPLS as second member order) and could see child tunnel (inet_0) formed in Spoke 1 and Spoke2. Traffic originating from Spoke 1 to Spoke2. Everything works fine in normal scenario. We could see that Routes for spoke 2 (192.168.3.0/24) is learning through inet shortcut tunnel and MPLS parent tunnel tunnel in Spoke1. When Spoke 2 internet link goes down, this causes Inet child tunnel goes out of SLA, as per SDWAN rule member order next member MPLS parent tunnel is created and then child tunnel gets formed in MPLS (MPLS_0) at both branches Spoke 1 and spoke2. Until this point, its working fine. Till this point, at Spoke1 - spoke2 route will le
I saw some conversation about stopping auto-upgrade on FGTs before after 7.2.8. And, we're doing it manually for those FGTs that are NOT managed by FMG. Then when we tried the same for those managed by FMG, the change was rejected because it's managed by FMG.And solution is in this KB:https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-automatic-firmware-upgrades-on/ta-p/326998#:~:text=set%20allow-push-firmware%20disable%3A%20Disables%20the%20ability%20to%20push,firmware%20updates%20from%20being%20pushed%20to%20the%20devicesBut it's not totally clear about the behavior for those command:config system central-management set allow-push-firmware disable set allow-remote-firmware-upgrade disableendWhat we want to set up is:1. Stop FMG pushing auto-firmware upgrade to managed FGTs2. Also stop FGT upgrading firmware by itself3. We still want to upgrade those managed FGT firmware via FMG manuallyTo accomplish this,config system central-management
I'm new to Fortigate and I need to get MFA working for SSLVPN users from an LDAP Server. With other manufacturers, such as Sophos, I just need to enable MFA for users and have them read the QR code in their respective authentication app. With Fortigate, do I need to use Fortitoken mobile exclusively?Another question: is it true that to use MFA with Fortigate, I need to pay for a token?
Our setup is such that we're trying to get our FG1101E to act as both router and firewall with BGP routing. We have our ISP provided single fiber uplink at 10gbps (SFP+) which has a defined Point to Point IP /29 IP address that's used to peer with a BGP neighbour. The BGP side of things appears to work ok, with our prefix for public IPs are being advertised and received to our ISP, and they are sending at default route to us. What we're trying to achieve is to be able to egress to the web using an IP on the advertised prefix, these are public IPs assigned to us as an organisation. We're able to use them in the context of an outbound rule, for this to work we have to create an IP_Pool overload object and use that in the rule which shows to the world we're coming from an IP we own. If we don't do that, then our IP is shown as the BGP peer IP. We are trying to get to a place where we can use some sort of virtual interface with the IP loaded on fro
Hello, I want to limit the VPN connection of local or imported ldap user as data and time using usage profile on FortiAuthenticator. I am listening on 1646 radius acconting. 1646 port is open on FortiGate and FortiAuthenticator. When the user exceeds the specified limit, no warning and interruption is observed. Can anyone realize this application or have any suggestions? By the way, when the user connects, I cannot see any session in Monitor > Radius Session field. I have followed all the warnings in this document:https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Usage-Profiles-not-enforced-for-RADIUS/ta-p/198682
I have free trial license fortimanager and i want workaround to upgrade fortigate with it as when i try to upgrade give me error message (no valid FMWR license) so can anyone helps me?
Hello everyone,Since we did move to FortiClient EMS end of last year I do want to start diving into ZTNA now: I do have a VLAN that is not connected to my windows domain server (Domain Controller, File-Server, ...). This VLAN is for third party machines and computers (robotics, PLC, IOT devices, ...)Now there is a use case that some of our plc programmers want to work in this specific VLAN for the ease of access to the robotics but also need to access e.g. windows File-Server. What is the easiest way to set it up? Basically I was thinking about creating a policy that only allows FortiClient EMS managed devices. I do see the ZTNA Tags created from EMS in the FortiGate. Should I go for the "IP/MAC Based Access Control" in a "standard" FortiGate policy where I can secelt the ZTNA tags? Or do I need a full ZTNA policy?   ZTNA policies documentation seems to often point into a kind of webserver scenario - that is not really needed here. So do I need a ZTNA ser
My new 60F Wi-Fi will only do 5 or 2.4ghz which I think is normal.I am using 2.4ghz since one device is IoT and likes 2.4ghz only.Many devices are happy but the 16 Pro is not - I tried a few settings and channels (3 choices) and it wont connect.Any ideas please?
My aim is mainly blocking bad sites (malware, C2, phishing) not controlling certain types. Web filter and DNS make sense, though perhaps are a tad similar. ISDB seems to offer some IP blockers. Would ISDB cover my wish by blocking connections pre/post malware to malicous domains (IP behind)? Thank you
Private data encryption (PDE) protects encrypted passwords that are configured on Fortigates. PDE does this by ensuring that encrypted passwords cannot be decrypted by third parties. This is particularly important in ensuring that bad actors who manage to get their hands on a Fortigate configuration cannot decrypt the passwords that are in the configuration. PDE is applied by applying a 32 character hexadecimal "key" to a Fortigate.WARNING: Once you apply PDE key, you cannot change the key without first returning the Fortigate to a configuration that does not have PDE configured. So it is crucial to retain a backup of the Fortigate configuration just prior to applying PDE. Or otherwise, the Fortigate would have to be returned to default configuration, reconfiguring it, and then applying a new PDE key. This article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-private-data-encryption-feature-on-a/ta-p/339071 includes this important key piece of informatio
i have a fortiap 221e with an active license connected to a fortigate 70f with also a active license. ap version is 7.0.6 and the fg at 7.2.10. when i check in system, manage fabric, go to update for the ap, it says it is up to date and the "update from fortiguare" button is disabled. any way to fix this or it can only be done by manually downloading the firmware?thanks
We encountered an issue where we needed to enable SSL protection on our internal web server to provide connections for external visitors. After enabling SSL protection, the browser displayed ERR_CONNECTION_RESET. When checking with openssl s_client -connect, we found that TLS1.3 was not supported, but TLS1.2 was supported. We also confirmed that the backend server originally supported TLS1.3, but when we switched the firewall mode to proxy mode, it could support TLS1.3 and the browser could access the website normally.
Hello, I have an FortiGate with an implicit allow all policy:ANY srcintf to ANY dstintf with ALL sources to ALL dest and ALL services.I am looking for a way to leverage FortiAnalyzer to extract unique connections, and based on that create explicit firewall policies above.Any ideas on how to use the reporting feature in FAZ? Thank you!Cosmin
Can Fortinet achieve IPv4 and IPv6 routing diversion within and outside the Chinese wall?DNS resolution for China and international is separate, similar to dnsmasq?model:201E。Are there any performance bottlenecks?
Hello Everyone,I have a question regarding DNS forwarding. Unfortunately, I have little experience with DNS on the FortiGate, so please be patient with me.At the moment, I have a Jump Host VLAN that needs to access the DNS servers of two different networks. The goal is that, for example, when I query the domain NetworkA.local, the request is forwarded to the DNS server in Network A, and when I query NetworkB.local, the request is forwarded to the DNS server in Network B.Network A is configured on the same FortiGate as the Jump Host VLAN, while Network B is located on a second FortiGate connected via an IPSec tunnel. I have configured the DNS server on the Jump Host VLAN as recursive and set up the DNS database accordingly as a forwarder.Now, here’s the problem: DNS forwarding works for Network A, but not for Network B. I suspect the issue is that the FortiGate does not use the interface IP of the Jump Host VLAN to forward DNS queries, which is why the requests are not being passed thro
Hi, I was wondering if someone can help me on this. I am very new to networking and would like to check if I can do IP address translation on a layer 2 device with address 192.168.199.2 on my VLAN2 going to VLAN 1 with subnet 10.156.116.0/22. My intended translated address is 10.156.119.2 for this layer 2 device and will be using a kepserver ex v6 device from the vlan 1. Hope someone can assist me. Thanks
Running a 91G on 7.4.6 and trying to add a secondary HA member in A/P mode. I did the initial config for HA before connecting the heartbeat interfaces (matches the primary, except for priority). After connecting, the secondary unit is seen but the config synch fails. config system ha set group-id 1 set group-name "my91G" set mode a-p set password xxx set hbdev "wan1" 10 "wan2" 20 set session-pickup enable set override disableset priority 56 Here are the errors I am getting. Does this mean I have to manually go into the secondary and make config changes for all of these ? Table 91g_pri_8383 (Primary) 91g_sec_7940 (Secondary)system.global 6c7457c867d70b31b0b1b40ea0b64933 b414354e704f6c2ba1f2cc32d253443bsystem.accprofile 516896996422b4ffb0bc35db970ca064 1339bc428f719fd8dff15e69ec6a229asystem.interface 6b73b9a398a09ecfd00e5b9bb45ae039 a759cd4772291b04c2501119836354afsystem.
We installed two FortiSwitchs in stand alone mode at a new small facility last year. A 448E-POE in main network closet connected to Metro-E and a 124F-FPOE in a network cabinet to link the back to closet with Fiber. Recently we added a FortiGate 60F to manage some planed IoT devices. After reviewing network settings we though the best method to move forward was to utilize Private VLANs to isolate the IoT devices in a single subnet behind the FortiGate. We tested on the 448E-POE switch and then discovered that the 124F-FPOE doesn't support them. Does anyone know if I convert the 124F-FPOE to be managed by the FortiGate, if it will then be able to support Private VLANs? Trying to decide if I need to replace it, or convert it to managed without doing it first since its in a manufacturing facility with the only extended downtime window from 1-4am on Sundays. I really don't want to come in to do the migration if its not going to work only to have to come back in a few weeks
I would like to know if it is possible to update the Firewall firmware of 2 Firewalls that are configured in HA in a way different from the current best practices. What the customer I am working with would like to do is update them as 2 separate firewalls instead of the current configuration that has them basically update at the same time. I believe this is wanted to combat a bad update being applied to both firewalls. Is the only option for an HA solution to have the primary download the Firmware to both devices and apply it all in one go or is there a way to do it as 2 independent updates?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.