User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hi Everyone, I'm having 10 years of experience with Palo Alto's. We make heavy use of their URL filtering and Application Detection.In our environment it's not possible to decrypt any traffic, yet the Palo could block all URL's (based on SNI, certificate names etc) but here with the Fortigate Eval License it even refuses to block any webpage using the URL filtering - I've tried "youtube.com", whatsapp.com, facebook.com and none of these work and I'm refusing to believe that this isn't possible with a Forti without decryption. What I've done:1. Security Profiles -> Web Filter -> Create New -> Checked URL Filter (Static URL Filter) and I've choosen Wildcard, Block, Enable for *facebook.com* / *whatsapp.com* and "*youtube.com*"2. I've made sure the Filter is set in "Flow Mode" and hit OK.3. Created a "Firewall Policy" under "Policy & Objects" that includes this Filter:Accept, All, All, All, Flow-Based, Web-Filter checked and choosen, SSL-Inspection left on "no-inspe
hey, I'm having issue with a specific user trying to connect. when trying to connect to the software, doesn't matter what address is being placed, after entering password and pressing enter, the password gets longer and the application is stuck on connecting. i tried a few things, of course uninstalling and reinstalling, including restarts, i tried connecting via diffrent wifi network, and i tried even Full uninstall, registry and program data, does anyone know what else i can do to fix that problem? Thanks a lot.
Hello Forum,MacOS version 15 SequoiaFCT version 7.2.6 GAIn our organization we are deploying a MDM profile for FortiClient. I am wondering if the Full Disk Access is properly granted for the application. I cannot see the fctservctl2 and FortiClient in the GUI Full Disk Access System Settings. Also from the command " /usr/bin/sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db 'select * from access' | awk -F'|' ' { print $2 } ' | grep -Ev "com.apple|System" | sed 's/\/Library\/Application Support\///g' " I still cannot retrieve the information that the application has full disk access. In conclusion I am not sure if the Full Disk access is properly granted. If I check the "Device Management" settings and click on the "Configuration Profile for FortiClient" there I can see""" Access All Application Data """ : "com[.]fortinet.forticlient.macos.antivirus- Allowed" "com[.]fortinet.FortiClient - Allowed" "/Library/Application Support/Fortinet/FortiClient/bin/fctservctl2 - Allowed
hi,i'm trying to create a FW policy (top most rule) to exempt/bypass selected public IP host/subnet for FW policy inspection. this for troubleshooting/logging purpose and to quickly react if a client escalated a complex issue.can someone confirm if below logic is correct? do i use the same source address ("extempted-subnet" address group) for both inbound and outbound rule? Rule #NameSource InterfaceDestination InterfaceSource AddressDestination AddressServiceAction Exemption Traffic - Inbound/Outbound 1Allow Exempted Subnet Inboundinternet (egress interface)anyTo add customer public IP subnet in "extempted-subnet" Address GroupallN/AAccept2Allow Exempted Subnet Outboundanyinternet (egress interface)To add customer Public IP subnet in "extempted-subnet" Address GroupallN/AAccept
Please help me configure a policy for one connection. FG-60E (firmware v.7.2.10) works in transparent mode between optical modem (also in transparent mode) and main router for LAN. External IP address is on router, not on modem. When Inspection Mode works in Proxy-based (Firewall Policy), one of the devices in LAN cannot communicate with its server where it sends measurement data (blitzortung.org). Policy in Flow-base mode does not block the connection. It blocks only in Proxy-base. Is it possible to set Flow-based policy for selected remote server? Or add some exclusion in current policy? I know the addresses of servers to which data is sent.
Hello.I am currently using an ARM-powered computer (Snapdragon X Plus) and I couldn't install Forticlient 7.4 normally. Then I installed Forticlient from the Windows Store and added a new VPN connection in the VPN tab under Settings. But I can't access any pages while connected to the VPN, I can't connect to SSH. The connection is successful but I can't do anything. Do I need another setting?
Hello, I have download the Vm image for vmWare ESXi 7.6.1 and I have set ip static for the first port but when i am trying to access via browser it's appear there is a problem in license (vm is not licensed or licensed invalid for current vm configuration upload a new license or reconfigure the vm) and i have tired to download the license via cli but there is problem (failed to download vm license) although I am sure that insert the right username and password
Hi All, Can we register fortiswitch to forticloud without internet connectivity like we do in fortigate using upload license method.
Hello colleagues! I am a bit got lost within mp-bgp and vrfs on fortigates, let me explain in a nutshell.Let's imagine the schema when we have a "core" multi role switch and several appliances connected as a star topology (or like a leafe spine , but let's skip the redundancy part for now). Links between the core and leafs all L3 and use mp-bgp with VRFs and address family ipv4 vrf plus the rt community. So nothing extra, everything works. It's not the vxlan+evpn example, just a simple campus. Then I would like to connect this core to a Fortigate by the same way for propagating the default gw route and providing some advanced traffic inspection. The FG can be considered also as a point of route leaking. The confusion is that I couldn't find any examples of this design and how to configure the mp-bgp. It might be the limitation that we can use only an "interface" for each vrf and can use only vrf-lite connection. In some sources I found that it should be organized via vdoms , but
Hello Fortinet Team, Could you please change my community nickname to Gohan? If it is already used, you can change to GohanC or GohanFC. Thanks in advanced.
Hi!I'm trying to list spesific host types usig API;curl -k --location --request GET 'https://x.x.x.x:8443/api/v2/host?filter=iconType==camera' --header 'Authorization: Bearer XXXXXXX' (just using at this example icon type, that is one differentiator between host types in our case) This filter doesn't work. Am I doing something wrong? Also one interesting thing is, that only 25 hosts are shown, when no filter is used...Although the last line tells:..."filtered":4865,"total":4865} NAC version 7.4.0 BR, A
Need to know best/efficient practice to implement HA active-active setup using 2 independent DIA links and 2 firewalls FGT61F.Also I need to use both links at the same time to share the traffic.
Hello All, I am trying to gather as much information as I can prior to making a change to my firewall. I was attempting last week to create an automation stitch. This would place IP addresses associated with SSL VPN brute force attempts, onto a blocked IP address list. I found that this apparently cant be done if your SSL VPN is bound to your WAN interface. I began researching this but cant find a clear answer as to why this is required. I would also like to make sure I understand all of the steps involved in doing this as well as any implications it might have on functionality (pro or con). From what I can tell, it is a matter of creating the interface, assigning some random IP to the interface then creating a VIP that forwards traffic incoming on the SSL VPN IP and port, to the loopback interface. Are you required to change the actual policies that permit the traffic since the interface is addressed as sslvpnroot and not as an IP? Any information/assistance is greatly appr
Dears, Can I change the FortiVoice time format from 24hrs to 12hrs? BR,
I'm not sure why my license suddenly shows as not being validated, with the error shown below. Could you please let me know what caused this and how to resolve it?upd_fds_load_default_server6[1046]-Resolve and add fds update.fortiguard.net ipv6 address failed.upd_comm_connect_fds[457]-Trying FDS 208.184.237.66:443[116] __ssl_cert_ctx_load: Added cert /etc/cert/factory/root_Fortinet_Factory.cer, root ca Fortinet_CA, idx 0 (default)[116] __ssl_cert_ctx_load: Added cert /etc/cert/factory/root_Fortinet_Factory_Backup.cer, root ca Fortinet_CA_Backup, idx 1[497] ssl_ctx_use_builtin_store: Loaded Fortinet Trusted Certs[517] ssl_ctx_use_builtin_store: Enable CRL checking.[524] ssl_ctx_use_builtin_store: Enable OCSP Stapling.[835] ssl_ctx_create_new: SSL CTX is created[862] ssl_new: SSL object is created[212] ssl_add_ftgd_hostname_check: Add hostname checking 'update.fortiguard.net'...[929] ssl_set_hostname: Set hostname 'fortinet-ca2.fortinet.com'[720] __ssl_info_callback: before SSL initializ
Hello, I read carefully topics here, but could not find working solution. I have a FG-40F test unit, made a vlan on it (99) with pool 192.168.200.0/24 FG has 192.168.200.1 addressOn this vlan I set up captive portal like this:If I set as excempt DNS service here, it disappears on next interface openingOn this stage I use internal users, created on FG unit.DNS is set = Same as interface IP, so I assume it is 192.168.200.1I also added a policy for DNS to go outside for unauthorized users (src=vlan, dst = wan): Also I made a letsencrypt certificate for this domain and made a static dns entry:The problem is that on different types of devices it operates different way, but works only on iPhone - when I can by opening some websites trigger appearance of login window in browser to authenticate. On Mac it is also sometimes working through browser. But on Android I usually see:1) Message: ERR_NAME_NOT_RESOLVED2) In case if I disable https authentication I even see
Hello community, I am thinking about implementing a FortiGate device in my network. However, due to the topology of the network, I have questioned whether or not to replace my Core Router directly with a FortiGate. What has been your experience? Regards.
Hello there, I try to to slim down our Stack by getting those things mentioned in the Subject directly from FortiManager instead of all the Fortigates directly. Is that possible ? - Haven't found anything in the API Docs. API or Mail Event would be prefered. Thanks!
Hello everyone; I currently have the NSE 1 and NSE 2, but I want to take the NS4 and I have some questions: 1- Is the NS3 necessary to take the NS4, even having experience with team deployment? 2-Where can I take the NS3? I have searched and have not found it. If anyone has a direct link, I would appreciate it! 3-From what I have researched, the NS4 is presented in Person VUE. Is this correct? 4-When I pass the NSE4 exam, do I get the FCP Security Network certification or do I have to take another exam? Thank you very much for your support.
which action must be performed to return the FortiManager HA 1 manual mode to a working state?
I got a weired scenario where two post deployed fortiswitches are showing offline on my fortigate.When I run both exec switch-controller debug commands, they show me everything is OK literally. Fortilink OK, NTP OK.. but still the CAPWAP interface doesn't get an IP.The fortilink is allowing security fabric thru, but still CAPWAP ain't forming.What other troubleshooting could I perform? I've checked so many posts and the solutions rely on the diagnostic commands telling you what's wrong, in my case, nothing shows otherwise.
i have a created a new trunk group on the fortiswitcchmc-lag enabled, STP Enable , Edge portlacp active port 48,port48CiscoLACP mode activePort channel 13Cisco switch is running MST spanning tree mode (same as fortiswitch) when i try to enable to port-channel i get STP error on the cisco side and the cisco ports go into err-disabeld state any idea what going on?does anyone have a working configuration of a similar environment?
Hello, I have integrated FSSO and there is no issue, I even installed the DC agent. However, in the SSL VPN policy, I cannot select the FSSO groups under the authentication portal mapping in the SSL VPN settings, as they are not shown, only LDAP is displayed. What could be the issue? I want to configure the SSL VPN rules with FSSO, not LDAP. Where am I making a mistake or is this possible?
Hi there, is there a way to authenticate an 831F to the switch port it connects to?We want to avoid that people connect laptops instead of the FortiAP.I haven't found any configuration guide or guide line so far, because everytime I us the keyword 802.1x I get articles related to the wireless clients. TIA, Alex
Hi Forum,I have configured "host negated" and added a group of countries (block_country) on vpn-ssl settings to avoid ssl failed login attacks but a user need to connect permanently from a country who is on the group mentioned above. Is there a trick to bypass the current config and allow a remote ip from a country forbidden ?Thank you for your help.Regards
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.