User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hello,I’m curious about the differences between Authentication and Access under IP Policy and Recipient Policy on FortiMail. When Authentication and Access is enabled under Recipient Policy, it ensures the necessary authentication when accessing emails in the personal quarantine. However, I don’t fully understand what it does under IP Policy. Has anyone used or inquired about this before?And i know this " For webmail login, select an appropriate Authentication type and Authentication profileunder Authentication and Access when configuring an inbound recipient-based policy" , "IP-based policy authentication does not support webmail login." ThanksFortiMail
I have a FortiGate firewall and 4 Forti Switches. I want to configure the switches in stack mode, with one switch acting as the primary and another as the backup (secondary). I do not want to manage the switches through the FortiGate firewall. I want to achieve stacking similar to how Cisco switch stacking works. If it is possible please post here.
Hi folks, I've found that SSL Certificate Inspection in the configuration below, applied to my LAN -> WAN policy is substituting the NordVPN certificate with my Fortigate certificate. NordVPN is detecting the change and terminating the connection. If I disable certificate inspection, NordVPN connects without issue. When SSL Certificate Inspection is selected, it is not possible to add exceptions. I tried choosing Full SSL Inspection instead and added the exceptions for the NordVPN addresses below, but that yielded the same result. I upgraded from 7.4.5 to 7.4.6 and still have the same issue. Any ideas? Thanks in advance! NordVPN addresses excepted:*.nordvpn.com*.nordcdn.com*.rsc.cdn77.org*.nordlayer.com*.nordlinks.com*.nordapi.com Here is the NordVPN error: Here is the default SSL Certificate Inspection policy I have applied: Here is the "exception" policy I tried:
Hi Fortinet Community, There are two sites (on-prem and Azure) interconnected via IPSec VPN tunnel.Each site has one domain controller.Remote users when connect to on-prem get authenticated against the on-prem domain controller.The future plan is decommission on-prem infrastructure. However, when I try to point FortiGate router to the Azure domain controller there is no connection to it. 1) Is it normal that FortiGate router itself doesn't see the other side of the VPN tunnel?2) Is it possible to make it communicate with resources running on the other side of the VPN tunnel? Thanks.
Hi, Below is the result from a recent nmap scan on all TCP ports.nmap -p 1-65535 -T4 -A -v x.x.x.xPORT STATE SERVICE VERSION113/tcp closed ident179/tcp open tcpwrapped443/tcp open ssl/https50805/tcp open unknown1 service unrecognized despite returning data.we use 443 for https, I understand the BGP port tcp179. But I cant find reference of port 50805 anywhere. "diag sys tcpsock " doesnt list 50805, and neither does "Policy & Objects -> Local In" via GUI dashboard.how can we confirm what is listening on tcp 50805?Following the article below:https://community.fortinet.com/t5/FortiGate/Technical-Tip-View-which-ports-are-actively-open-and-in-use-by/ta-p/191523Thank you :)
With a limit of 10 SLAs per zone I'm a bit stumped.I have roughly 80 remote sites all connectong to the same hub, with 2x dialup tunnels per site. So 160 IPSec tunnels in the overlay.While each remote site can have its own SLA up to the Hub I can only configure 10 SLAs from the Hub to remote sites https://19216801.onl/ .This causes some performance issues for traffic sourcing from the Hub as it's path selection isn't checking the quality of the tunnels for all the remote sites.So what now?
您好,客户的 foritgate 60f 防火墙已购买 ATP 和工业安全服务的许可证,并将在生产环境中以透明模式部署。我想了解一下在这个环境下如何完成防火墙部署,这个部署有哪些注意事项,以及如何使用工业安全服务特性库
hey i never even knew this existed but today my site refused to open and said 'fortinet didn't instal correctly' I didn't have any file related to fortinet. I've now installed it hoping to fix the problem but can anyone help me
Hi, I`m having problems with setting up IKEv2 IPSEC with remote site.What I`ve done:I`ve imported Certificate via GUI and whole Chain by which this certificate is signeg (Internal CA).I`ve setup Custom Site-to-Site tunnel.SA Policies do match.Hovewer I can see in logs message saying:ike 0:NVT_BIA:44590: reassembled fragmented messageike 0:NVT_BIA:44590: initiator received AUTH msgike 0:NVT_BIA:44590: received peer identifier DER_ASN1_DN 'CN = RemoteIP, OU = VPN, O = CompanyName, C = UK'ike 0:NVT_BIA:44590: Validating X.509 certificateike 0:NVT_BIA:44590: peer cert, subject='RemoteIP', issuer='IPSecCA'ike 0:NVT_BIA:44590: peer ID verifiedike 0:NVT_BIA:44590: building fnbam peer candidate listike 0:NVT_BIA:44590: FNBAM_GROUP_ANY candidate ''ike 0:NVT_BIA:44590: certificate validation pendingike 0:NVT_BIA:44590: certificate validation completeike 0:NVT_BIA:44590: certificate validation succeededike 0:NVT_BIA:44590: signature verification failed
Any one knows how to change the loginscreen title or name -> FortiAnalyzer-VM64-KVM to a different name ? I have tried the following config system globalset platform-name <new-name>endIT DIDN'T WORKED
Hey, we have a FG60F with 7.4.4 and 3 Interner Access (all of them >500/500MB). They called me yesterday and at 1700 they had no internet. I was OoO so I asked them to ping the firewall (OK) and check lights (check of FG and Switches) and everything inside seemed normal....but that all 3 accesses fail at the same time, that never ever happened. They rebooted FG and all routers and nothing. At the end after 1 hour I told them to reboot FG, wait 2 mins and only connect WAN1 and sudenly it worked. I am not sure that this process solved the problem but 5mins later I connected via Forticloud and in SD WAN all of them were OK. Today checking th logs at 1700 I only find "Member status changed" and "Member status changed. Member out-of-sla." At 18:27 I find "SDWAN SLA information warning" and Message "Service disabled caused by no outgoing path." I am not worried that this can happen soon, but maybe one of you had the same experience once? Thanks
Hey, I configured dot1x on FortiNAC with these and trying with Aruba AOS-CX Switch; (Winbind joined and Radius services running) When I try to connect, I see logs with the correct username but FortiNAC does not send reply packet. 10:38:54.579232 IP (tos 0x0, ttl 62, id 13822, offset 0, flags [DF], proto UDP (17), length 199) 10.8.4.4.35733 > trnacsr01.test.local.radius: RADIUS, length: 171 Access-Request (1), id: 0x30, Authenticator: 4be24ae1715b87beb75e8daa5fd19d8f User-Name Attribute (1), length: 23, Value: TEST\baris.yilmaz Calling-Station-Id Attribute (31), length: 19, Value: E8-80-88-E9-46-69 NAS-Port-Type Attribute (61), length: 6, Value: Ethernet NAS-Port-Id Attribute (87), length: 8, Value: 1/1/23 NAS-Port Attribute (5), length: 6, Value: 23 Service-Type Attribute (6), length: 6, Value: Framed EAP-Message Attribute (79), length: 28, Value: .. Message-A
I am trying to send Traffic Syslog encrypted from Fortigate firewall to Rsyslog on Ubuntu server.I have managed to do this for other Clients, however one of my latest Client gets an error saying"Decode error" in traffic dump and "No supported cipher suites have been found" in Rsyslog logs. The certificate is uploaded to the Fortigate firewall at System > Certificates > CA Certificate (rootCA_ip.pem+key.pem). Tcdump Decode Error from Ubuntu Server:RSYSLOG error logs on Ubuntu Server:rsyslogd: tcpsrv listener (inputname: 'imtcp') failed to process incoming connection with error -2083 gnutls returned error on handshake: No supported cipher suites have been found.tcpsrv listener (inputname: 'imtcp') failed to process incoming connection with error -2083 Generate Certificates:The Ubuntu server is hosted at Google Cloud and it generates root certificates during creation with a Startup Script: # -------- VARIABLES -----------------------------------------------------
I am using FortiEMS 7.2 on prem and whenever i try to create a new installer the download link shows a "installer creation failed" message.Why is this happening and how can i fix it?
One of our branch offices is facing a lot of brute force attempts via SSL-VPN.For some reason, all these (failed) attempts are also forwarded to our RADIUS server (only used for wireless / wired network authentication via a NAC solution). Other branch offices with the same setup do not forward these brute force attempts to the RADIUS server(s). We have tried to compare the full configuration with each other, however do not notice any differences. Are we missing something here? We are on FortiOS 7.2.10 on this specific branch office.
Internet and ADVPN interfaces are virtual on the firewall. When either the ISP or ADVPN goes down, the Firewall marks interfaces as DOWN on the GUI but in CLI, the interface appears up. Any suggestion on same, we are running FortiGate version 7.2.8
Hi, i'm looking for a way to sync the sso groups from AD. Now we manually import a group. But if the name changes for example, we need to import it manually again. I don't believe there is an option in the Authenticator environment itself to sync this? Running 6.5.5 btw.
Dear Community Team, We are running FortiWeb OS v7.2.7.I tried to create a new user with permission to change only another user's password, but it was unsuccessful as expected. Is it possible to do that? Please kindly share any ideas or solutions. Regards.
Fortinet changed the way local-in-policies are created when an interface is part of an SD-WAN zone. From 7.4.6 and 7.6.1, the local-in policy is assigned to the SD-WAN zone instead of the interface as explained in the article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Local-in-Policy-is-Missing-after-upgrading-to-v7-4/ta-p/367001 This is great, however I'm dealing with issues now when I change these local-in-policies on the FortiManager. We run FortiManager 7.4.6. FortiManager 7.4.6 appears to not understand this new behaviour. I get a warning that I can't assign a local-in-policy to an SD-WAN zone when I create a local-in-policy in a policy package that's only assigned to firewalls that run FortiOS 7.4.6. That's quite annoying when you manage all your local-in-policies from the FortiManager. Is this intended behaviour in FortiOS 7.4.6 and if so, is there a fix on the way to bring this in line with FortiOS 7.4.6?
Hi,I have a huge connection attempt to my firewall (SSL-VPN). I have reduced the geographic origin of authorized connections, and I would like to exclude certain address from this geographic area. I can't do it.Can you explain to me how to do it? Fortigate FGT60E, last firmwareSSL-VPN Settings:Restrict Access: Limit access to specific hostsHosts: my geographic alow zoneNegate source: disable Thanks for your help
Hello Everyone, plz could you help me to find out and fix the problem of the windows agent in fortisiem that is showed Critical in Event Status and what does it mean? I've attached a screenshot of the problem
Hello,We are trying to switch our EMS authentication server from LDAP to LDAPS. LDAP works fine.We have ports 389 and 636 open on our FortiGate firewall. After inputting our local CA certificate and clicking Test we get a Network error message at the top.We are using the local CA certificate from our Windows server 2019 domain controller/Certificate authority by exporting it in DER format. We have also tried that same domain controller server certificate, which is what EMS is syncing with today.Any thoughts about what could be doing wrong? Could it be the certificate export process or maybe something else?Screenshot below.
Hello everyone, I'm from Mexico.I have a big problem, recently I have problems accessing my fortinet because it sends an error that says "Authentication failure" and does not let me access. I have tried to access via forticloud, console cable and locally and I get the same problem.What I found is that we have suffered from a vulnerability called "FG-IR-23-475": FortiOS - SSLVPN session hijacking using SAML authenticationA session fixation vulnerability [CWE-384] in FortiOS may allow an unauthenticated attacker to hijack user session via a phishing SAML authentication link.So I don't have access in any way. Is there any way to access it?To update the firmware can I do it through the forticloud Premium subscription since I currently do not have it.Note: I currently have the OS version: 7.2.6
Happy new year everyone.I want to authenticate a user through the Forti API, after the user finishes to authenticate against a 3rd party captive portal.I figured the API command would be: https://FORTI-IP/api/v2/monitor/user/firewall/auth?vdom=root{"users": [{"ip": "10.235.1.50","ip_version": "ipv4","method": "firewall","user_type": "firewall","username": "test4"}]}But I'm getting 424 Failed Dependency.Unfortunately I don't know what parameter is missing and I do not have access to the developer portal to read the documentation.FYIDeauthentication works fine like this:https://FORTI-IP/api/v2/monitor/user/firewall/deauth?vdom=root{"users": [{"id": 0,"ip": "10.235.1.50","ip_version": "ip4","method": "firewall","user_type": "firewall"}]}
Hi All, is it possible to create a read only account that can run below command config global config system console set out standard end show null
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.