User Story: Abdelkrim Rahmania
Fortinet Community
Recently active
Hi there, is there a way to authenticate an 831F to the switch port it connects to?We want to avoid that people connect laptops instead of the FortiAP.I haven't found any configuration guide or guide line so far, because everytime I us the keyword 802.1x I get articles related to the wireless clients. TIA, Alex
Hi Forum,I have configured "host negated" and added a group of countries (block_country) on vpn-ssl settings to avoid ssl failed login attacks but a user need to connect permanently from a country who is on the group mentioned above. Is there a trick to bypass the current config and allow a remote ip from a country forbidden ?Thank you for your help.Regards
Fortinet FGT61F has 2 IPSEC tunnels but only 1 remains up at a time I have 2 IPSEC tunnels towards a destination, one each over 2 WAN links towards same destination.But have been facing issue that only one IPSEC tunnel remains up at a time.Once I enable both the IPSEC tunnels, then they both start flapping.So I am forced to disable one IPSEC tunnel, only after which the other IPSEC tunnel remains UP and stable.Will share more details if needed.
How can i allow bitdefender from fortigate captive portal. Firmware version 7.2.6
A Win8.1 machine has a frequently reoccurring problem with connecting Forticlient to the remote endpoint. It will sit for a moment at 98%, then display the error: Unable to establish the VPN connection.(E=98,T70,M99,R-983070010)It goes away after a system reboot, but may show up again the next day and so on. I would like to find a solution to this. I see this in the debug logs:Debug VPN FortiSslvpn: 13308: Ras : dialing fortissl Debug VPN FortiSslvpn: 6952: rasfunc error: 0:633 Error VPN FortiSslvpn: 13308: Ras : connection to fortissl failed : 6:0:0:According to msdn docs 633 is ERROR_PORT_NOT_AVAILABLE which implies a port conflict, but the logs don't state which port.
Hello,I am currently facing an issue with my FortiAnalyzer when trying to view DNS logs from my FortiGate. Specifically, when I navigate to the FortiView > Traffic > DNS Logs section in FortiAnalyzer and search for DNS activity, the result always shows "No record found", even though DNS traffic is expected to be logged.Setup Details:Configuration:FortiGate is configured to forward logs to FortiAnalyzer.Other logs (e.g., traffic logs, event logs) are appearing correctly in FortiAnalyzer.
Hi there,I am about to implement geo blocking for SSL-VPN on our FortiGate FG 500E with FortiOS 7.4.6 under "VPN / SSL-VPN settings".The countries to be allowed access are within a group object and the rule ('Limit access to specific hosts') works fine dropping all access from all other countries. BUT - we have an employee working for us from one of the blocked countries and I do not want to 'allow' this whole country. So I tried to use the MAC address of his device and put it in the group object of allowed countries. It is then possible to select the group object but when you apply the changes, the group object disappears form the Host list!?Is there a way to solve this problem: blocking SSL-VPN for a country except defined client devices? Thanks to all of you and I whish you a happy new year :)
Can anyone recommend me a site where I can download Fortinet stencils for Smartdraw and Visio. Thanks.
Be fair warned, I am new to FortiGate, so I may be asking some trivial question. I have been tasked with implementation of new FortiGate equipment in a remote office that will VPN back to corporate. Due to the VIP status of the location we purchase two each – ISP Circuit, FortiGate 201E and FortiSwitch 248B. For the HQ location we purchased two FortiGate 301E. I contacted support and I have read about 195 pages of the Cookbook, but am getting a little short on time and still without a solid feeling about the implementation. So I thought I would try out the Forum for support.Remote office Design 1. Stack the switches using redundant logical interface with standby enabled (Primary link to sw1 standby link to last switch sw2) shown in FortiNet Support ("HA-mode FortiGate units managing a stack of several FortiSwitch units") ? 2. Setup FortiGates in HA Active-Passive or Active-Active? Most all documentation prefers Active-Passive.ISP Redundancy 3. Can the two ISP WAN links be brought in
Hi, I have gone through the handbook and various other downloaded manuals but I can' t get this to work. Here is my current setup: x) Users are authenticated using the FSAE. x) Three AD groups have been defined; Internet_Users, Internet_Managers and Internet_IT. x) Internet_Managers have access to everything except downloading executable files 24x7. x) Internet_IT has full access 24x7. x) Internet_Users have social media, downloading and other stuff blocked. I want Internet_Users to be able to use sites such as Facebook during lunch hours only. I have created a schedule " enableSM" that recurs from 1:00 PM to 2:00 PM everyday. I have created a UTM called " Normal" that blocks social media, porn, etc. And another UTM called " Enable social media" that enables social media while blocking everything else as defined in " Normal" . How can I enable the users of AD group Internet_Users to use UTM " Enable social media" during the timing defined in " enableSM" ? I have
New setup with a 60F on 7.4.6.With 3 interface: WAN (6.6.6.6),Vl10_Users(10.0.10.1/24),Vl20_Servers(10.0.20.1/24)I did a rule that allow traffic between Vl10 and Vl20 with no ''inspection profile''.When NAT is disable on this rule trafic doesn't work between a host in Vl10 to another host in Vl20.Has soon I enable the rule with NAT, the host in Vl20 see traffic originating from the host on Vl10 with it's NATed IP.I don't want to enable NAT on this rule in order to see the originated source IP on the host in Vl20.Both hosts have they gateway pointing to the corresponding interface on the FW.I should not have to Nat traffic when routing should only be involved. I can do some show or debug if needed.Rule in question:set name "Allow_All_To_DNS"set uuid ...........set srcintf "VL-10_OLD_LAN"...set dstintf "VL-20_SRV"set action acceptset srcaddr "all"set dstaddr "host_10.0.20.20_DNS-SRV"set schedule "always"set service "DNS" "ALL_ICMP"s
How can I enable DHCP options for a single host? For example, I need to assign a different gateway to a specific host.
Dear All,Can someone tell me why for internal traffic do we need to enable nat in the policies.Like example;I have the following network 192.168.1.0/24 on vlan x and network 10.64.28.0/24 on vlan y. Both vlan's are using firewall as gateway and a sub interface configured with trunk to allow both vlan's. The problem if i do not enable nat on the policies both subnet cannot communicate. Thanks
hiMy FortiGate 200F , OS version : 7.0.16setting use ssl vpn and dns suffix (my environment have mutiliple domain)config vpn ssl settings set dns-suffix “test1.com; test2.co.uk; test3.net” endmy internal web => https://www1.test1.com apple iphone forticlient vpn After connecting can connect https://www1.test1.com => OK input hostname www1 => OKbut android forticlient vpn version 7.4.1.0176 , not working only input Complete FQDN https://www1.test1.com OK , hostname not OK What is the reason for this?
i am getting error in installing vpn 6.0
Hello Expert, I would like to setup client server vpn, but would prefer to use a customize setup as instead of ADVPN (I have move control of the setup)I notice the option to use dialup user for customize setup can I use this option Instead of the ADVPN?I humbly request some guidance Thank youRegards
I have been experimenting with different sim card vendors in a Fortigate 60F-3G/4G. I have been trying to establish a remote access VPN connection to fortigate over 4G. So far I have been able to create a VPN connection locally so I know I understand the process and how it should work. I have also managed to get this working when the Fortigate is connected to the internet on it's WAN1 interface. I noticed when I insert a sim card, unlike the WAN 1 interface, the sim card interface (WWAN) receives a private IP address.I have tried:Vodafone: APN wap.vodafone.co.uk O2: APN payandgo.o2.co.uk3: automatically assign APN Vodaphone sim was a pay monthly, I tried with both pay monthly and pay as you go O2 sim and the 3 sim was pay as you go. On all sim's i can ping out to the internet from the Fortigate just fine. I've also tried using DDNS (use public IP) with no joy. Any help is greatly appreciated!
Hi FAP & FSW adminsIf I'm not misunderstanding, since managed FAP's and FSW's configs are pushed from FGT, then it should not be required to follow upgrade paths for FAP and FSW. Is this correct?
Hi I want to reorder SSL Cipher suites, is possible?For example>>
Hello everybody,We distribute device scep certificates via intune over a PKI instance to authenticate our devices via LAN and WiFi via a RADIUS server. However, our Fortigate does not serve as the RADIUS server. We use a Cloud Radius server and also a cloud provider as PKI for the scep certificates.Currently we use IPsec VPN via SAML login and pre shared key.Is it possible to use the already distributed devices certificates for remote login of the IPsec VPN instead of the pre shared key? However, I would still like to use SAML for user authentication. Or does this make no sense at all?Regardsfabs
I get this message when I click on an extension in the IP Extension section. Can you assist me with this matter
Hello FML admins FortiMail 7.6.1. We have an issue with one remote mail server of "somedomain.com". The issue is more about TLS than SMTP. When we send an e-mail to that domain they receive successfully.However when they send us an e-mail from the same mx of that domain then the session can't initiate TLS, and we see the following errors in the session logs. STARTTLS=server, error: accept failed=-1, reason=sslv3 alert unexpected message, SSL_error=1, errno=0, retry=-1, relay=mail.somedomain.com [1.2.3.4] I see the reason is "sslv3 unexpected message" which should mean the handshake was unsuccessful.When I check the remote mx (as server) with openssl command I see it supports TLSv1.3. So I find it strange that it is trying to initiate a SSLv3 session (error message is about SSLv3). Since I have no control on the remote side, any idea on how I can workaround this issue from my side?Can this be fixed by setting an AC policy with using TLS profile with minimum
first time working with FortiSwitches so this is probably an easy fix?Topology.FortiGate firewall connected to a FortiSwitch using the fortilink interfaces. Then the first switch connected to another Fortiswitch. From the FortiGate GUI, I can see the information on switch one, and in 'fortiswitch ports' it shows its connected to switch two by the S/N under the 'native vlan' field. But on switch two, I can see the port connecting to switch one is up, but no other information. Also in the 'managed switches' topology view it shows switch two as not connected.Switch one and two are connected via port22 on both, the switch port config is default and on switch two it created a trunk to switch one, it gets the created vlans from the ForiGate.Switch two, config switch trunkedit "SwitchOne"set mode lacp-activeset auto-isl 1set members "port22"nextAny help would be apprecicated.
we have two main switches configured in MC-LAG. Call it Fortiswitch A/B. In a spanning tree config would they both have identical priority? or would A be 4096 and B 8192 for example? What about if they are managed by the FortiGate. Does the FortiGate need to be the root? Can you set the spanning tree priority on the FortiGate itself? What is the best practices here? Thanks,
I configured trunks on my fortiswitch to structure the double port of my APs in LACP. on the access points I ran the same command:cfg -a FAP_ETHER_TRUNK=2but on a graphic level the trunk on the switch side remains red. I can see the switch through the firewall.only the first AP installed sees the green trunk, the others remain red.even the trunk to the firewall itself remains red despite all the ports connected in green. I don't understand why.the firewall is updated to the latest firmware version available and everything else is updated too.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.