Mark a Best Answer
Fortinet Community
Recently active
Hello FML admins FortiMail 7.6.1. We have an issue with one remote mail server of "somedomain.com". The issue is more about TLS than SMTP. When we send an e-mail to that domain they receive successfully.However when they send us an e-mail from the same mx of that domain then the session can't initiate TLS, and we see the following errors in the session logs. STARTTLS=server, error: accept failed=-1, reason=sslv3 alert unexpected message, SSL_error=1, errno=0, retry=-1, relay=mail.somedomain.com [1.2.3.4] I see the reason is "sslv3 unexpected message" which should mean the handshake was unsuccessful.When I check the remote mx (as server) with openssl command I see it supports TLSv1.3. So I find it strange that it is trying to initiate a SSLv3 session (error message is about SSLv3). Since I have no control on the remote side, any idea on how I can workaround this issue from my side?Can this be fixed by setting an AC policy with using TLS profile with minimum
first time working with FortiSwitches so this is probably an easy fix?Topology.FortiGate firewall connected to a FortiSwitch using the fortilink interfaces. Then the first switch connected to another Fortiswitch. From the FortiGate GUI, I can see the information on switch one, and in 'fortiswitch ports' it shows its connected to switch two by the S/N under the 'native vlan' field. But on switch two, I can see the port connecting to switch one is up, but no other information. Also in the 'managed switches' topology view it shows switch two as not connected.Switch one and two are connected via port22 on both, the switch port config is default and on switch two it created a trunk to switch one, it gets the created vlans from the ForiGate.Switch two, config switch trunkedit "SwitchOne"set mode lacp-activeset auto-isl 1set members "port22"nextAny help would be apprecicated.
we have two main switches configured in MC-LAG. Call it Fortiswitch A/B. In a spanning tree config would they both have identical priority? or would A be 4096 and B 8192 for example? What about if they are managed by the FortiGate. Does the FortiGate need to be the root? Can you set the spanning tree priority on the FortiGate itself? What is the best practices here? Thanks,
I configured trunks on my fortiswitch to structure the double port of my APs in LACP. on the access points I ran the same command:cfg -a FAP_ETHER_TRUNK=2but on a graphic level the trunk on the switch side remains red. I can see the switch through the firewall.only the first AP installed sees the green trunk, the others remain red.even the trunk to the firewall itself remains red despite all the ports connected in green. I don't understand why.the firewall is updated to the latest firmware version available and everything else is updated too.
Hi Fortinet Community, My address object is edit "Wifi-address"set type interface-subnetset subnet 192.168.0.0 255.255.255.0set interface "Wifi-interface"next how ever my interface status is unused/disable/down edit "Wifi-interface"set vdom "root"set ip 192.168.0.1 255.255.255.0set allowaccess ping fabricset status downset device-identification enableset role lanset snmp-index 8set interface "port4"set vlanid 888next ... however, I am use the same Address Object to use in new Firewall Policy but using different interface in source/destination like source is port9 destination is wan1. the policy can created. i ask ChatGPT, is this possible? Behavior with Disabled Interface:When you disable an interface, FortiGate may interpret that the address object no longer has a valid binding, effectively treating it as "unbound." This could allow the address object to appear in policies for different source/destination interfaces.This behavior can be se
Hello, By customer request, we have installed 7.2.8 on a FortiSwtich 424E-Fiber and a few FSR-112D-POE Rugged Switches. I did not factory reset when the software was updated. We have no issue with using the following command on the 424E:config switch interface edit "portx" set auto-discovery-fortilink disable However, we can not issue this command on a FSR-112D-POE switch. Why? How can we disable "auto-discovery-fortinet"? The command is requesting a "integer" (3-300), not "enable/disable". I have read through countless documentation and now I am confused about this. One document says to disable "auto-isl", yet I have this option disabled per interface. Is this all I need to do?Another document says that ports 9-11 are automatically set to "auto-discover-fortinet". Does this mean ONLY these ports? How can I disable this function then?I am looking for a clear and concise answer and method to disable "auto-discovery-fortinet" for the
Dear all i have FortiVOice 100 F and i have Cisco CUCM in another Branch , my two sites connect via MPLS and the two side see each other , now i need to connect FortiVoice with Cisco CUCM , so any one can call from FortiVOice to CUCM voice ...
How can we protect foritgate against a huge number of attempts to establish an IPsec tunnel, secured by a certificate with a bad certificate in request? That fact strongly imposes a huge load on one of the CPUs.
Hi, Is it possible for FortiGate to have a multiple router ID? My plan is to set up BGP over IPSEC tunnel. Thank you!
I registered more than 25 devices in my Fortianalyzer without problems, but I am not able to keep two of them 100% connected. I can see the logs and they have registered correctly in the analyzer and I can see the logs in real time, but if I do a filter for a longer period of time, it does not show data. Both the equipment and the Fortyanalyzer are in the latest version, both have policies allowing communication to be released for everything, like the others that worked. Can anyone help me with the demand?
Dear Community, We have received a directive from our cybersecurity department to block all third-party VPN applications (such as Hotspot, SuperVPN, SpeedVPN, etc.) on Android and iPhone devices used by end users.After reviewing the article https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-third-party-VPN/ta-p/220170, we implemented the recommended settings. While we can confirm that ISAKMP traffic is being blocked, we have encountered an issue where the SuperVPN app on an Android device is still able to establish a connection.Furthermore, we are unable to implement deep inspection for VPN traffic, as our cybersecurity team has explicitly denied this approach due to privacy concerns. As per the policy, no administrator is permitted to view unencrypted traffic.We kindly request your assistance in resolving this issue and ensuring that all third-party VPN applications are effectively blocked, without the need for deep inspection.Thank you for your support
Some of our users are confronted with this problem pretty randomly while trying to establish a SSLVPN connection. Usually, 2nd or 3rd attempt are working. The reference tells noting about error -20105 related to connection problems (other than log upload failed, which is disabled).I could not find anything related to error code 20105 in this forum so far - any suggestions? A typical log file pattern looks like this: 30.03.2021 15:54:14 Error VPN FortiSslvpn: 16144: error: poll_recv_ssl -> SSL_get_error(): 5 30.03.2021 15:54:14 Error VPN FortiSslvpn: 16144: error: poll_recv_ssl -> WSAGetLastError():2746 30.03.2021 15:58:05 Error VPN id=96603 user=SYSTEM@NT-AUTORITÄT msg="SSLVPN tunnel connection failed (Error=-20105)." remotegw=extranet.xxx.xx vpnstate=connected vpntunnel="SSL VPN" vpntype=ssl vpnuser=xxxxx
I am working on a project that involves creating a SDWAN in a complicated situation. (See picture below). As you can see, I need to create another ADVPN.Would it be possible for someone to assist me? Thank you
i have problem with fortivoice i have pc and phone connect to fortiswitch , i put the pc vlan as native vlan and voice as allowed vlan the problem is pc and phone take ip from native vlan (PC) , and when i put the voice in native and pc in allowed (pc and phone also take ip from Native vlan ) >> (Voice ) i mean allowed vlan not working
WebFilter is blocking a lot of traffic to the following URL.It looks like it's Microsoft traffic, but the category is (Uncategorized).Is this a feature that FortiGate is designed to block? http://48.210.69.87/filestreamingservice/files/xxxxxxxxxxxxxxxxxxx==&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com ("xxxxxxxxxxxxxxxxxxx" is a random string) FortiOS 7.0.15
Hello, why does the browser display a blank page when opening the switch web page? I tried switching to Google Chrome and Edge Browser, but it still works the same way
FSSO Collector Agent showing 'unprocessed logon event' in debug file (log level warning) Scenario: Fortigate FG600E cluster v.6.4.7. 3 Microsoft Windows Domain Controller servers (W2016), 2 Microsoft Windows Collector Agent servers (W2012): DC Agent and Collector Agent in Advanced Mode. From time to time, specially when DCs or CA servers goes down and up, 'unprocessed logon event' messages appear continuously in both Collector Agent servers. Some logon events are missing in Collector Agent, and therefore missing in Fortigate. Therefore, Internet access problem for several users arise. There isn't any specific procedure to recover to normal operation. Even restarting Collector Agents do not solve the problem. Sometimes, it seems to be recovered when modifying some part of the Collector Agents configuration, or when modifying some part of the DC FSSO configurtation and then restarting the Collector Agents... Any help is really appreciated.Many thanks in advanced. 
Hello, I was trying to set up a new subnet and DHCP scope on my LAN. I noticed on my DHCP server that BAD_ADDRESS placeholders were filling in many off the addresses in the range. I looked on my core switch and there was no corresponding ARP entry. I did a port scan on NMAP of the IP and got the following output: Starting Nmap 7.70 ( [link]https://nmap.org[/link] ) at 2018-08-27 14:10 Central Daylight Time Nmap scan report for 192.168.73.105 Host is up (0.0019s latency). Not shown: 65524 filtered ports PORT STATE SERVICE VERSION 21/tcp open ftp? 25/tcp open smtp? 80/tcp open http? 110/tcp open pop3? 113/tcp closed ident 135/tcp open msrpc? 143/tcp open imap? 443/tcp open https? 8008/tcp open http 8010/tcp open ssl/http-proxy FortiGate Web Filtering Service 8020/tcp open http-proxy FortiGate Web Filtering Service Browsing to ports 8008, 8010, or 8020 takes me to a page titled "Web Filter Block Override" with the message in the title.
Hello everyone, I would like to know if there is a way to look for a specific email address on "Email group" to prevent from creating the same address in two different groups (Duplicate addresses). Best regards,
fnsysctl is frequently helpful in troubleshooting Fortigates, and while its options are mentioned in the Forums here and there, no single article lists them, and not all options are mentioned, so I wrote a post to summarize the info.Originally posted on https://yurisk.info/2024/10/23/fortigate-fnsysctl-command-options-with-examples/ Important facts about fnsysctl command:You have to log in with a user having super_admin profile.For VM Fortigate, it has to have a regular license - not free evaluation one. On free evaluation VM FGT you will get an error Unknown action 0.It is CLI-only command, with no GUI equivalent.The command runs locally on the Fortigate you are logged in, so to run the same command on a passive member of HA cluster, you will need to log in into the passive member first.The Tab completion does NOT work with this command (therefore this post).We CAN use these commands in automation stitches as set action-type cli-script.fns
So I have a 501E and 301E at 2 different sites. I got the FMG well after having these two units in the wild so I was able to import them in hopes of managing them, however I'm hitting a problem after import. The configs at the actual units were changed (objects added, settings tweaked) after being added to FMG. FMG doesn't know about these additional settings so if I ever go to run the Install Wizard, the Install Preview shows that it would delete all of the items created at the units. I guess that makes sense since FMG will only install what it knows about. (The people who edited outside of FMG are to be restricted to the FMG only.) Question is, how do I ensure that FMG updates what it knows about a unit's objects (addresses, interfaces, etc.) if changes are ever made outside of FMG? In my labs, I've deleted the unit from FMG and re-added it to reflect such changes but I don't know if there'd be any weird side effects that might affect the FGT in a production environment. I'd lik
Hello everyone, connected access points via a switch:configured DHCP on FORTIAccess points received IPE50 successfully pings access points and sees their MACSSID createdBut when creating an AP profile, I get the status "not available". Whoever encountered a similar problem could not find a solution to the problem ? The article on advanced search does not help.  
Access denied when trying to start cap. Any ideas? Tried this route as well - https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Disable-Hardware-Acceleration/ta-p/191256
Best Way to configure Fortinet 60f as per given topology. In this topology every Lan5 -Lan 7 is connected to L2 manageable switches. All client devices are connected through these L2 switches. What will be the best possible configuration?
Hello,I'm trying to implement an external captive portal. For this, I designed a React frontend and I'm using a RESTful service to send accessRequest and CoA requests over RADIUS on the firewall. I created a dedicated VLAN for the guest network and configured the external captive portal through Network > Interfaces. I also set up FreeRADIUS and performed connectivity and authentication tests, all of which worked smoothly as described in the documentation.After completing these steps, I connected to the Wi-Fi network with my mobile phone and obtained an IP address, but instead of being redirected to the captive portal login page, I was taken directly to the company’s homepage. To resolve this issue, I tried moving all the captive portal pages to the public cloud. I even created some static HTML pages to test the redirection, but unfortunately, I haven’t made any progress yet.  
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.