Mark a Best Answer
Fortinet Community
Recently active
Hi all, My situation:I run SDWAN use ADVPN BGP on loopback between HQ and 4 branches, HQ is Hub and Branches is spokes.When Branch 1 talk to Branch 2. Spoke - Spoke tunnel is established successfully, I set up tunnel idle timeout, and tunnel is down after 10 minutes, if no traffic, it's good.But, I have Br03 and Br04, they always talk each others, so Spoke-Spoke tunnel will not down after 10 minutes (it's correct). I set Lifetime phase 1 :1days and Lifetime phase 2: 12 Hours. And I saw trouble here: - After 1 days. spoke-spoke tunnel between Br03 and Br04 is re-established but it has trouble, I saw in logs, it's stucked at action: delete_phase1_sa , around 5 minutes. And after around 5 minutes, tunnel spoke - spoke is not iusse, it working fine. And I saw log, after 5 minutes, Sopke-spoke only down. During 5 minutes, the trouble make loss connection between Br03-Br04. My connections: each BR has 2 ISP lines, BR03 tunnel of ISP1 conn
Hello! I've two ISP link configured on two separate SD WAN rules. When my primary ISP link is activated, the DNS and FortiGuard works only with the "source-ip" configured: Everything OK! My problem is when the secondary ISP is activate. The DNS and Fortiguard stop to work(dns unreachable)! In this case, i needed "unset" the "source-ip" to get it working again. My question:Is there any configuration so that DNS and Fortiguard continue to work on both links? Without having to make these "source-ip" settings manually.
I would like to forward all Google-related services to a specific IP in the internal network. Can this be implemented in the SD-WAN rules? thanks.
G'day, This is for those working in ICS/OT: I have set up and tested alerts in FAZ. The email notifications for the alerts via handlers and notification profiles, etc... are sending BCSI information. I have tried to work with support, but they are saying that there is no way to remove the information that is sent in the emails. NERC requirements are clear about this. I can't send hostnames and IP's in the same info resource. Privacy Masking is an option, but it also disables it i FortiView and Log View. Has anyone else come across this and found a solution? Its bad that I can't send the alerts I need in FAZ without the need of another product (SIEM) to do it. If someone has a best practice comment and its condescending in nature, just I know I love you still and happy holidays. Oh... I submitted a NFR for this already.
Hi!We want to implement a monthly change of Guest SSID password change via API automatically. The environment is managed with FortiManager. What would be best practice in this case?- Change the password via CLI Script on every device from FortiManager, push the CLI script via FMG API- Change the password in SSID profile and provision via API - Anything else?With the first approach, I guess we will see conflicts and FMG tries to override the password during a following provisioning?Thanks & Happy Holidays,Tobi
We are running FortiManager 7.2 on Hyper-V. Over the weekend the host installed updates and rebooted and now on FortiManager it states the Fortigates are unauthorised. I have read that having dynamic Mac addresses could cause this issue, but I have now set to static in Hyper-V and the issue persists after reboot - the FMG asks for its hostname, then the 2 x Fortigates say unauthorised despite being authorised prior to the reboot. Any ideas?
Hi,we have two /29 IP blocks from our ISP. IPs from the first block are used for SNAT and a few VIPs. There are two default routes, one for each gateway because both subnets have different gateways. We didn't want ECMP, so we increased the distance for the default route to the gateway of block 2.We also run VIPs on IPs of the second block. I was wondering why this is even working because the default route for block 2 is not installed in the routing table because of the higher distance. Therefore, return traffic for VIPs of block 2 must flow through the gateway of block 1. Asymmetric routing is disabled, I checked it.We are also using port forwarding on the VIPs, so it shouldn't automatically use the VIP's public IP for return traffic. Edit: I checked the session table and it looks like Fortigate SNATs the reply traffic. But I don't know why, the documentation says that it sould only be doing this when One-to-One NAT is applied without port-forwarding. Or does this rule only apply
Hi,I set a wifi guest with self-registration and otp sent via sms using Fortisms license using Fortiauthenticator.There is a method to send an alert when Fortisms license is about to end? For example send an email?.Thank you all in advance. Vincenzo
Dear AllWe have deployed FortiNAC 7.6 latest version and using it for 802.1X authentication using Cisco switches and AD authentication through WinBind, authentication was working well for some customers but its not stable , now we are facing that cisco showing authentication successful but on FortiNAC its showing "unauthenticated" and remain in Isolation/authentication VLAN means VLAN change is not happening , this product is strange sometimes becomes very slow. We are using Peap MSCHAPv2 with user authenticationplease suggest
Problem:I have a FortiGate 90G, and I have created a cluster. The management IP for this cluster is currently set to 192.168.1.1. However, I also want to assign a secondary management IP of 192.168.1.2 to the secondary unit in the cluster, specifically for monitoring purposes.Request:How can I configure this secondary management IP for monitoring? Are there any potential issues or problems that might arise from this setup?Please provide the correct steps and guidance, as I do not have enough information about this process.
Hello all, I would like to change or disable VPN Idle-Timeout for only two users or, if it is not possible to change for user, can it be changed for specific profile in which certan users are added. I'm using 7.2.10 firmware version.
hi, I am checking the upgrade path of fortimail from version 7.2.2 to 7.2.7 but I check the documentation of fortimail 7.2.7 (https://docs.fortinet.com/document/fortimail/7.2.7/release-notes/569892/firmware-upgrade-and-downgrade) they inform that you have to jump directly from version 7.0.6 and it doesn't say anything about version 7.2.2 can you confirm me that the upgrade is direct from version 7.2.2 to 7.2.7 Kind regards
I'm trying to bring up a trunk over a port-channel between a pair of 1048E's and a pair of Cisco 9504's that are configured using vPC. One fibre connects one 1048 to one 9504, and the other fibre connects the other 1048 to the other 9504. The VPC on the Cisco side fails, saying "vpc port channel mis-config due to vpc links in the 2 switches connected to different partners". I am working with support and Cisco support, but I wanted to ask if others have gotten this working. We're looking at possible spanning-tree issues, but also best practice guides on the Cisco side for VPC's. I want to trunk my Fortinet distribution switches to my Cisco infrastructure so I can leverage other vlans in my Fortinet firewalls. Any thoughts?
We're pleased to announce the FortiSOAR 7.6.1 release. This new release provides the following key features: FortiFlex licensing Reduced downtime when upgrading HA clusters from 7.6.1 onwards Support for disk encryption Improved solution pack upgradability to preserve custom playbooks Improved management of playbook logs to optimize storage Various UI/UX enhancements Significant improvements to the Outbreak Response feature Improved indicator extraction Voice dictation into the FortiAI assistant Various integration and connector enhancements ...and more! see the release notes below for full details. Release notes:FortiSOAR 7.6.1 Release Notes (opens in new page) Availability and Upgrade:Customers with valid support contracts can upgrade from FortiSOAR 7.6.0 to version 7.6.1. FortiSOAR 7.6.1 can be downloaded from support.fortinet.com
Hi!KB "Keep the flash partition without it being overwritten (For rollback purposes)" seems useful, except, I think it's problematic. It basically, says, we can manipulate which into partition the new firmware image will be stored to keep (original firmware image in) the other partition from being overwritten during upgrade.However, upgrade is not only about images, it's also about FortiOS configuration migration!!As per KB, the partition into which the new firmware is one with "Active" is "No", but... (as I understand) the configuration used for FortiOS configuration migration will be sourced from partition with "Active" is "Yes".So, in KB's step "Upgrade the firmware from 7.0.13 B0566 to 7.2.6 B1575:", the FortiOS configuration will be sourced from partition with the original "6.4.6" configuration, not the upgraded "7.0.13" configuration. And since that original FortiOS configuration was not migrated as per approved "Upgrade Path", we would end up with supposedly incorrect Forti
Hi All,Recently we've been encountering an error in one of our environments where any submission to the Live URL Rating support gives the message "Thank you for your submission, your request will be reviewed in 24 hours." instead of going through the regular live rating process. Has anyone else been experiencing this or noted similar behavior?Thanks,Mark
Hello, I have some traffic hitting Implicit Deny, even tho the Allow Policy seems to be correct:Logs: Rule: Found this: Traffic dropped by 'implicit deny pol... - Fortinet Community, but everything shown is ok here.This might be relevant: I recently changed my FortiGate from standalone to Fabric Root. Could you please help diagnose this? Thanks in advance.
I am unable to launch Forticlient with MAC OS Monterey. Whenever I try to connect I get the prompt, open security & privacy settings and allow system software from Fortitray. When I go there there isn't anything for me to allow fortitray.
Hi, Customer is having FAP231F and they are having ISP with 500mbps bandwidth.On wired network is gives speed more than 400mbps but on wifi getting speed upto 225-250mbps.For testing purpose connected AP directly on Fortigate interface with single user connected on wifi, getting speed upto 225-250mbps only.Channel width is 40mhz and client system is connected on 5ghz band.Same time TP Link wifi router is providing speed upto 400mbps.Can someone suggest to get more speed on FAP wifi.
Hello! I installed FortiAnalyzer (Trial) on a VM, but some panels (FortiView -> Traffic Analysis or Treats, for example) return the error:Server error: DB::Exception: Table siem.fv_fgt_t_threat_5min_sp1 does not exist Already tried:#execute sql-local rebuild-db#diag test application fazcfgd 85 Did I miss some config., or any suggestions on how to fix it?Thx
Hello, we use Fortigate v7.2.10 with FortiClient v7.4.1.We import a .conf-file with this value:<prompt_username>0</prompt_username> So: HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\Sslvpn\Tunnels\VPN Profile\promptusername=0That's ok. But in HKEY_CURRENT_USER not, it's promptusername=1.So if I start FortiClient, the username-input is blank. If I set promptusername=0 manually, it sets the username I saved in the Profile.But after I connect to VPN, Forti sets promptusername=1 again. How can I change the behavior so that promptusername is always 0? GreetsMarco
Hello Normally when I configure a FortiGate (which isn't too often anyway) I create VLANs with VLAN IDs and then work from there (assign specific ports in the switch to the desired VLAN ID respectively assign specific SSIDs in the access points to the desired VLAN ID). Now I "inherited" a network with a FortiGate that has been set up by a previous IT guy. They used a method that I didn't even knew that it existed. They assigned one port on the FortiGate to one VLAN and the other ports to another VLAN. Now this lead to the problem that the "Guest WiFi" actually wasn't separated from the "Office WiFi" because the access points of course were connected to one port (or rather: a switch that is connected to a port on the FortiGate) - and since everything that comes through this port is determined to be in the same VLAN, everything that comes from the access point is in the same VLAN as well. So my question is:Can we somehow "combine" the two methods of VLAN management, s
Hi all, I am a new user of FortiManager. Previously on my Fortigate I had an Admin Profile which allowed read/write access to User & Device only so Admins could create and assign VPN tokens but nothing else. Now we have implemented FortiManager they are no longer able to log in locally, so I have tried to create them an account in FortiManager with the correct access. Unfortunately I cannot see clearly the corresponding areas in FortiManager to be able to create a profile for this access only. Please could somebody help? Thanks
I have had many site-to-site IPsec tunnels working fine for several years until I upgraded to FortiOS 7.4.2. Shortly afterward, my tunnels began dropping connections on random Phase 2 connections. I have had to bring down the phases or entire tunnel to get traffic flowing again many times. I opened a ticket with Fortinet and had three technicians working with me at various times but none found a solution. I finally downgraded to 7.4.1 and all my problems went away. There is obviously a bug in 7.4.2 and I hope Fortinet finds and acknowledges it and fixes it for the next release.
Hello everyone, I am looking to add a disclaimer on the fortimail only for outbound emails, that every mail the user sends is under his responsability, I want the disclaimer to be only visible for the end user and not the recepient. When I configured the disclaimer to only be for outgoing, the message was sent to the recipient . If anyone knows how to do it that would be appreciated Best regards,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.