Mark a Best Answer
Fortinet Community
Recently active
So I have a 501E and 301E at 2 different sites. I got the FMG well after having these two units in the wild so I was able to import them in hopes of managing them, however I'm hitting a problem after import. The configs at the actual units were changed (objects added, settings tweaked) after being added to FMG. FMG doesn't know about these additional settings so if I ever go to run the Install Wizard, the Install Preview shows that it would delete all of the items created at the units. I guess that makes sense since FMG will only install what it knows about. (The people who edited outside of FMG are to be restricted to the FMG only.) Question is, how do I ensure that FMG updates what it knows about a unit's objects (addresses, interfaces, etc.) if changes are ever made outside of FMG? In my labs, I've deleted the unit from FMG and re-added it to reflect such changes but I don't know if there'd be any weird side effects that might affect the FGT in a production environment. I'd lik
Hello everyone, connected access points via a switch:configured DHCP on FORTIAccess points received IPE50 successfully pings access points and sees their MACSSID createdBut when creating an AP profile, I get the status "not available". Whoever encountered a similar problem could not find a solution to the problem ? The article on advanced search does not help.  
Access denied when trying to start cap. Any ideas? Tried this route as well - https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-Disable-Hardware-Acceleration/ta-p/191256
Best Way to configure Fortinet 60f as per given topology. In this topology every Lan5 -Lan 7 is connected to L2 manageable switches. All client devices are connected through these L2 switches. What will be the best possible configuration?
Hello,I'm trying to implement an external captive portal. For this, I designed a React frontend and I'm using a RESTful service to send accessRequest and CoA requests over RADIUS on the firewall. I created a dedicated VLAN for the guest network and configured the external captive portal through Network > Interfaces. I also set up FreeRADIUS and performed connectivity and authentication tests, all of which worked smoothly as described in the documentation.After completing these steps, I connected to the Wi-Fi network with my mobile phone and obtained an IP address, but instead of being redirected to the captive portal login page, I was taken directly to the company’s homepage. To resolve this issue, I tried moving all the captive portal pages to the public cloud. I even created some static HTML pages to test the redirection, but unfortunately, I haven’t made any progress yet.  
Hello friends, could you help me with this question. To install the persistent agent on a MAC computer, what certificates are needed? I downloaded the agent from FORTINAC itself. But when I try to install it, it gives me a message that requires certificates The message is the following:Before authenticating on the server, you should examine the server certificate to make sure it is suitable for this network.To see the certificate, click on "show certificate".
Hi security adminsUsually when I integrate FML or FWB, I don't use IPS profile (or any other security profile) in the FGT firewall rule that forwards SMTP traffic to FML and HTTPS traffic to FWB.In my understanding, using security profiles at FGT level is probably useless since it will add more unnecessary load to my FGT, while FML & FWB should do the job much better than FGT.I'm I right?Does IPS profile (with deep inspection) at FGT level actually adds any additional layer of security that FML & FWB doesn't have?What does Fortinet, other constructors and other security experts recommend here?
Hello all, I humbly request your assistant. I configure the ADVPN on the hub but I would like to configure AES and sha 256 but I am not allowed to configure same . The screen shot below is only options I am see, not even the option to convert to full configure is displayed. Thank you Regards
FortiClient System Version: 7.2.6 build 1083We are trying to use ForticlientEMS to warn users when accessing Artificial Intelligence Technology category under General Instance Business. We have customised the warning message under System Settings>Custom Messages>WebFilter Custom Message. But it does not appear to be working, when users are accessing AI sites it does not show the warning message. Is there anything I am doing wrong?
Hello, I am able to run the "diagnose traffictest" command from the Fortigate to a Linux machine wihin my network, but I would like to test the throughput between two fortigate firewalls that are connected over SD-WAN. can I run this command on one fortigate as a server and the other as a client? Regards.
I can connect to the EMS but I'm unable to do any http request due to dns_probe_finished_bad_config. Does anyone now how to downgrade to the last stable version? Edit: I've found out how to downgrade and now it works. You can follow this steps:check the version on the repo by typing: apt-cache policy forticlient You'll see this: forticlient: Installed: 7.2.6.0872 Candidate: 7.2.6.0872 Version table: *** 7.2.6.0872 500 500 https://repo.fortinet.com/repo/forticlient/7.2/ubuntu /stable/multiverse amd64 Packages 100 /var/lib/dpkg/status 7.2.5.0854 500 500 https://repo.fortinet.com/repo/forticlient/7.2/ubuntu /stable/multiverse amd64 Packages 7.2.4.0809 500 500 https://repo.fortinet.com/repo/forticlient/7.2/ubuntu /stable/multiverse amd64 Packages 7.2.3.0790 500 500 https://repo.fortinet.com/repo/forticlient/7.2/ubuntu /stable/multiverse amd64 Packages 7.2.2.0753 500 500 https://repo.fortinet.com/
We have a Forticlient EMS and are using IP-Sec VPN with entra SAML to login to the VPN.I need to have a simple time limit that would disconnect users after 12 hours of being connected (active or not)How can this be accomplished?Post Connection script? Automation on Fortigate? Tagging Action in EMS?
Hallo,I get the following error when I provide a Forti Mobile Token to a user:"FTM provision error: problem with SSL comm layer: server connection failed: SSL session failed" nslookup fortitokenmobile.fortinet.comthe Authenticator can address the Fortimobile server.That's the only suggestion I can find for this error, but it works and is obviously not my problem!Any other hints to the error?AuAuthenticator Vesion:Firmware Version 6.6.2 build 1669 (GA) i tried different Mobile Tokenss, same error.Greetings Andree
Hi, I have Fortinet 30E. Recently I have noticed every few weeks it goes into Conserve mode and I am unable to access the internet till I restart the firewall. I am new to this so could someone tell me what would be the cause of the conserve mode. The # of sessions do increase during this time but we are not using any additional resources. Is there any way to get a log of these sessions? Thanks
Hello everyone, I would like to upgrade FortiAnalyzer from 10 Gb/day to 25 Gb/day, I know I have to purchase 3 x 5Gb/day. My question is when you register the licenses on Fortinet support will they automatically merge with the existing VM or do I need to open a ticket for that ? Best regards,
Greetings to everyone,I am experiencing an issue where the ifIndex values for interfaces on my FortiGate firewall change dynamically. This causes discrepancies in my SNMP monitoring setup, as it relies on static ifIndex values.Is there any command or configuration setting to make ifIndex values persistent on a FortiGate firewall?Thanks in advance for your support!
Hi, I setup a few automation filters under Security Fabric to send me messages with certain events (including admin login, etc). However I did a trial test to login and didn't get any messages. Does this require SMTP configuration? Thanks
hi all, I have a problem, i cant access my fortianalyzer by ssh and gui, but when i restart it can be accessed again. Do you guys have a way to find a culprit that make my fortigate bang, maybe any comment on cli would be helpfull to get any insight
Since yesterday, we are observing an alarming issue with FortiClient VPN. When connected to FortiClient VPN, users do not have access to Internet (access to company internal resources work fine). If user disconnects from VPN, access to Internet is back immediately. Affected users, when connected to VPN, can ping 8.8.8.8 but name resolution does not work, so they can't access google.com. We tried to modify the DNS settings on the affected devices, but even when using 8.8.8.8 as DNS server, users still cannot resolve FQDNs correctly! So far, we have observed this problem on one MacBook (issue noticed today) and all Android devices (issue noticed yesterday). Just wondering if anyone else has observed this problem recently? We have created ticket with Fortinet support but still waiting for a reply... FortiOS v7.0.15 build0632Different FortiClient VPN versions (Android - 7.4.1.0176, MacBook - 7.2.4.0850) No recent changes on our s
Hi Support, When migrating from 60e to 60f, do we need to change the conf ver file during backup push.#conf_file_ver=170387064977772676. Also firmware of our new fw 60f is on version 7.2.6 and old 60e is on 7.0.11.Can we directly upgrade 7.0.11 to 7.2.6 and take backup and push it to 60f?Because as per upgrade path it is showing h 7.0.11>7.0.12 >7.0.13 then all the way to 7.2.6f. It is very time consuming 10 firmware version are their between the two.
Hi All,I currently have an estate of 100F FortiGate firewalls managed by FortiManager with a root ADOM of 7.2.The 100Fs currently run on the 7.2.x firmware.Will the 200G run the 7.2.x firmware?Or do I need to run the firmware version that is currently supported for the 200G?Can the FortiManager manage the 200G or do I have to wait until the 200G is running a 7.2.x firmware before connecting it to FortiManager?
We purchased some FortiGate 60F, some were on 6.4.6 and some were on 7.2, except for one FortiGate that was upgraded to 7.4.5. We noticed that the Fortigate on 7.4.5 has its speed LED of LAN 1-4 turned off occasionally (happened twice in 2 months of the Fortigate in use). We tried rebooting the FortiGate and factory reset, but the speed LED did not turn back on. We shut down the Fortigate and replaced it with a spare device, and the next day when we turned on the Fortigate, the speed LED of LAN ports is on again. With the device's LAN speed ports back up when turned on, the hardware test will pass, and RMA will most likely be rejected. Anyone experienced in the same or other versions, and what are the solutions?
The IPSec ikev2 tunnel that employees dial into will be used by the Fortigate VPN Client application. Is it possible for each of them to receive a fixed IP from a predefined pool? For examlpe:pool: 10.10.100.10-10.10.100.50person 1: 10.10.100.10person 2: 10.10.100.11etc. I tried mode-config but without success.
Is there a cisco packet tracer equivelent for fortinet (fortiswitch & fortigate) ?I am trying to learn fortiswitch (cli) and fortigate. Anyone has any idea? thank you.
HiI'm trying to figure out why my transparent proxy policies are allowing traffic when they shouldn't. I have a transparent proxy policy restricted to a single IP and FSSO group for testing, yet when I disable the policy, the test device/user still has internet access when no other transparent proxy policy should apply. Fortigate 200E running 7.4.5 I've disabled fast-matching, and enabled WAD debug: diag deb resetdiag wad debug enable category policydiag wad deb enable level verbosediag wad filter src <redacted>diag deb ena With the policy enabled, I see proxy policy 8 matching: wad_http_req_check_policy :12911 start match policy vd=0(ses_ctx:t|Phx|Me|Hh|C|A1|O) (<redacted>:57019@19-><redacted>:80@20) absUrl=0wad_fast_match_is_enable :3702 fast matching is disabledwad_http_policy_get_cate_info :212 get category right awaywad_http_policy_match_one :454 fw_pol_id=8(pol_ctx:th|Acd|7|=p) pflag:H|W|U|Ac asyn_info=1wad_vwl_has_intf :329 logic/phy
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.