Mark a Best Answer
Fortinet Community
Recently active
Hello everyone, I am looking to add a disclaimer on the fortimail only for outbound emails, that every mail the user sends is under his responsability, I want the disclaimer to be only visible for the end user and not the recepient. When I configured the disclaimer to only be for outgoing, the message was sent to the recipient . If anyone knows how to do it that would be appreciated Best regards,
FortiSOAR 7.6.1 is Here! Your SOC Just Got Smarter and Faster SOC operators, analysts, and cyber warriors—get ready for a big boost! FortiSOAR 7.6.1 has arrived, and it's packing a punch stronger than your morning coffee. Check out what's new: FortiFlex Licensing Support Reduced Downtime for HA Clusters Disk Encryption Support Improved Solution Pack Upgradability Optimized Playbook Log Management UI/UX Enhancements Enhanced Outbreak Response Improved Indicator Extraction Voice Dictation with FortiAI Assistant Integration and Connector Enhancements ...and so much more! Dive into the full details here: Release Notes. Upgrade to FortiSOAR 7.6.1 Already on version 7.6.0? Upgrading is a breeze! Visit support.fortinet.com and navigate to: Downloads > Firmware Images > FortiSOAR > 7.0.0 > 7.6 > 7.6.1 What's Fresh Since Our Last Announcement? The following table summarizes the progress we have made with respect to solutions since the last ann
Hi guys,I am trying to get all forward traffic logs from the last 7 days via the Rest-API, filtered by specific policy IDs, but I only get the logs of a specific policy ID from the current second as a result (for example 2 logentries instead of over 1000). Does anyone have a solution to this problem?I use the following path in the Webbrowser:https://<ip fortigate>/api/v2/log/disk/traffic/forward/system?access_token=...&filter=policyid==...I also tried to use a timestamp in the path, but it didnt solved my problem.thanks
Hi, I want to manage fortigate from multiple fortimanager. On the central management settings screen we can add second fortimanager ip address. But when I add a second fortimanager, do the fortigate config settings sync in both fortimanagers? Does the config change I make in one fortimanager also sync in the other fortimanager?If so, we want to manage from two fortimanagers and not lose config when one of them fails.Best Regards
Hi guys, Some years ago I bought a pre-owned iPad from a guy which have won it from Fortinet at an event.Now, as I wanted to reset the iPad I'm getting the prompt, this iPad is remote managed by Fortinet Inc.Is maybe someone having contact to an MDM-team of Fortinet, who could help me out?As I have checked, the iPad has to be removed on the remote managing server through Fortinet Inc.I was not able to contact anyone yet.   
Hi I have the below requirement just looking for thoughts on the best way to do it....I need to do outbound blocking only for now. The site has a /16 assigned to it, carved up into many small subnets.....Most of the subnets will have the same banned countries, however, there are 3 subnets (scattered all round the /16) that require no restrictions. What is the cleanest way to tackle this? Couple of options that came to mind are 1. Create an address group for the /16, and use address exclude for the 3 subnets. Then in the rule block access to the restricted countries. Never used this feature before but it seems appropriate here. 2. Do the internet rules for the 3 VLAN's first, then block the countries for the rest, then do the normal rules for the rest any other ideas? thanks
Hey,One of my computeer with IP 10.10.11.152 got ping timeout to its gateway fortigate firewall internal interface with IP 10.10.11.1. How ever other servers on the subnet like 10.10.11.150 can ping 10.10.11.1. When I did ping capture on the firewall, I can see the following outputs. The replied packets are not going through internal inteface, but from root interface, but I have never created any interface called root. It's so confusing. Anyone has ever seen this crazy behavior before. Any solution to fix this issue? thank you # diagnose sniffer packet any "host 10.10.11.1 and icmp" 45.779616 internal in 10.10.11.152 -> 10.10.11.1: icmp: echo request5.779668 root out 10.10.11.1 -> 10.10.11.152: icmp: echo reply5.779678 root in 10.10.11.1 -> 10.10.11.152: icmp: echo reply
Is it just ME... or is auto-update the most dangerous and asinine thing I have ever heard? Me (for one) working in ICS/OT security, shiver at the thought of anything auto-updating. My compliance officers would shoot me in the f4ce if I ever suggested it. With the bugs in new releases, there is no way on earth I would consider this. Is there anyone out there that would actually enable this (or not disable it)? I'm interested in hearing more opinions than what my own paranoid brain is willing to offer. #fortigate #fortimanager #fortinet
My VPN configuration works fine, but when I configure the user's credential in the AD to LogonTo so that he can only logon to his assigned computer when he is in the company physically, his VPN connection when he is at home is affected and he cannot connect to the company, I have to revert the logon to all in the AD so that he can connect successfully. Fortigate V7.2.7
Hello, when the shared configuration file is configured with a maximum bandwidth of 100Mbps, low priority, and a maximum bandwidth of 30Mbps per IP configuration file, and the traffic shaping policy calls both the shared and each IP configuration file, is the traffic priority still low priority? Will other high priority traffic be forwarded first when passing through the firewall
Hi guys, I am not able to pull off a DNAT to access from external internet access to my web service hosted in the server in private subnet managed by fortigate. I am new into this networking area, could you guys help me out ?This is what I have been trying. I am accessing with web browser like http://<FGT-Public-Ip>:3002 and also doing telnet <FGT-Public-Ip> 3002.... both time out. Traffic is reaching my fortigate, verified with diagnose sniffer packet port1 'tcp and port 3002' results below:-----------------------------------------------------------------------------------------------XXXXXXXX # diagnose sniffer packet port1 'tcp and port 3002'Using Original Sniffing Modeinterfaces=[port1]filters=[tcp and port 3002]3.351276 XXX.XXX.9.57.59128 -> 10.0.0.10.3002: syn 34725990313.351345 XXX.XXX.9.57.59128 -> 10.0.0.10.3002: syn 89282952 Redirects to interface port1 private ip address port 3002--------------------------------------
Hello over in Admin -Setup- Organizationthe Error appeared when I tried to delete an organization, one of our clients who has terminated service. Any ideas on what this is due to? or how I can fix? is this the Database being confused somehow? Thanks in advance.
I have a 200F FortiFirewall device running FortiOS version 7.2.9 at the location. On the Forti SSL VPN tunnel side, we are using domain adcheck by examining the user's registry. If the machine is not part of the domain, it cannot establish an SSL VPN connection.On Windows 11 machines, FortiClient version 7.4.1 works without any issues. However, on a machine running Windows 10 (LTSC 1809), after installing FortiClient 7.4.1, SSL VPN connection fails. After entering the username and password, it throws me back to the login screen, showing empty fields for the username and password, and does not connect.The only difference between the machine that works and the one that does not is the operating system. I couldn't find anything related to this issue on the Forti side.What could be causing this issue?
Hello everyone, I was given an old FortiGate that was being used at a lab environment and noticed the device was not booting up.Upon trying to check the status on the CLI, noticed the device is booting on BMR-RX Boot Loader as shown in the bellow image. Now I am kind of stuck to get out of this boot menu and wondering if someone has any idea on how to do it. Some way to set up a TFTP from here or any other option.  I was able to login and the menu does not have any useful commands, tried running the "maintenance factoryreset" but always end up on the same place.  Appreciate any help! Regards FortiGate
Hello CommunityFortinet,I have a question, I want to integrate the Fortinet EMS console with a SIEM via Syslog to monitor events, I want to know how it is done and what kind of events I could visualize, apart from that I want to know if it is necessary to have some Fortyanalizer in the middle or any additional product to have all the security information I need to go through my security manager as I do not have it, finally I would like to know if from the EMS console I can what kind of logs would be sent, thanks for your help. Greetings
We are having problems with WiFi after upgrade to 7.4.5 and 7.4.4. for FAP.We are also running this on Fortinet switches, so misconfiguration of Vlans is highly unlikely. Also the vlan test on the AP is working fine. There are a few symptoms: - after restart, APs get their IP from DHCP on Fortigate, but later they disappear from DHCP table- One SSID in bridge mode authenticates clients, they also get DHCP lease, but they can not even ping the gateway on Fortigate (Yes the Ping is ON on the interface) This state is not permanent, and it looks like some of the APs are working even when this happens to others. I'm posting the problem here because Fortinet support starts with: "Did you switch it off and then on again?"
HelloI have FortiMail in front of my mail server.I have a second mail gateway receiving e-mails from internet and forwards them to my FortiMail.By default my FortiMail sends all these received e-mails to quarantine, since they fail SPF check (all mails from external domains are received on behalf of my 2nd SMTP gateway's public IP).So my workaround was to add on my FML an IP policy without SPF check, dedicated to the second SMTP gateway's IP.However I guess there should be a formal and clean method to tell my FortiMail that the second SMTP gateway is actually a legitimate SMTP gateway, so that my FML considers it as SMTP gateway and does the job properly.Thanks in advance.
The FortiClient VPN is not working on Window 10 PC. No response after entering the sign in info. No error message. Tried to sign in on another laptop, it is fine and working normally. Tried to reinstall the software, but no hope.Current version is 7.4.2.1737installed the Microsoft Visual C++
Hello,I am currently using Kerio Connect as my mail server, with all users stored in a local database.I have now installed Exchange Server 2019, and it is functioning properly for sending and receiving emails. Both servers use the same domain: @XXXX.xx.Currently, FortiMail is configured to point to the Kerio server's IP address, and everything works as expected. However, when I change the IP address in FortiMail to point to the Exchange server, the Exchange-side mail flow operates normally. Is it possible to configure FortiMail to recognize and forward emails to both servers based on recipient email addresses? For example: Emails sent to user1@xxxx.xx and user2@xxxx.xx should be forwarded to the Kerio server. Emails sent to test1@xxxx.xx and test2@xxxx.xx should be forwarded to the Exchange server. If such a setup is possible, could you guide me on how to configure it? Specifically: 1. Can this be achieved using FortiMail policies? 2. Shou
Recently ran into an issue where the Fortigate was providing incorrect IP addresses for requests to Microsoft domains. This led to certificate errors in outlook and browser connections to portal.azure.com. There appears to be some Reddit evidence of other users also seeing this issue:https://www.reddit.com/r/fortinet/comments/yuu50t/dns_issues_while_using_fortinet_dns_servers/ Looks like the same IP that we saw (93.174.121.39) and Certificate (SubName = gaia.iphost.gr) As a work-around you can change your FW DNS settings to point to a 3rd party DNS provider, but curious if other people are seeing this and/or how to keep it from happening while using FortiGuard services for DNS. (I believe this is a requirement to leverage DNS filtering)
Dear Gurus,Anyone could share their expertise on how to achieve this goal. We have a working email using single domain (abc.com). Now our company introduce new domain (xyz.com) which resides on different public add. mail.abc.com domain is intended for corporate users while mail.xyz.com domain is intended for outsource personnel. Please see diagram as reference.FML settings are the ff. Mail settings hostname is pointed to mail domain: abc.com email users uses email server private ip/fqdn as smtp server for abc.com domain. I am aware that I need to have 2 VIPs in my FGs pointing to FML IP, but on the FMl settings im bit skeptical on what to do. What would be my hostname looks like since i have 2 domains already? Does it resolved to correct ip if i ping or do nslookup mail.abc.com or mail.xyz.com Can I simply add xyz.com under Domain settings and point the host to my existing email server? What would be the smtp server settings of my email user resides on xyz.com domai
Hello, I firmware upgraded my Fortinet 60F firewall from v. 7.4.2 to 7.4.4 today and since then the firewall has restarted endlessly. I've tried resetting the firewall with a pin on the back, but it doesn't help at all. What do I do to get my firewall going again?
Hey all... I've been tasked with finding a solution that will send us alerts in real-time when any Fortinet fabric components (firewalls, switches, WAPs, etc) are offline or unreachable. We manage several sites in different geographical locations, and each site is isolated from one another. Therefore, we don't have an on-prem data center solution that we can utilize for alerting. The solution will have to be cloud-based and intelligent enough to scan each site LAN and report back any outages. I was hoping that Fortinet had a built-in solution with either FortiAnalyzer or FortiManager, but it doesn't appear that either product can do real-time alerting.Any ideas or suggestions on what we could use? Thanks in advance.
I'm getting this at the time of creating Radius
hi,i'm trying to create a FW policy in FMG to block "bogon" ipv4.i just saw RFC1918 address FW address object but there's none for "bogon".does fortinet considering to add these address space in a group/address object in future upgrade?can someone also confirm these are true bogon IP ranges? just want to ensure i don't block "legit" traffic/range. IPv4 Bogon RangesNetblock Description0.0.0.0/8 "This" network10.0.0.0/8 Private-use networks100.64.0.0/10 Carrier-grade NAT127.0.0.0/8 Loopback127.0.53.53 Name collision occurrence169.254.0.0/16 Link local172.16.0.0/12 Private-use networks192.0.0.0/24 IETF protocol assignments192.0.2.0/24 TEST-NET-1192.168.0.0/16 Private-use networks198.18.0.0/15 Network interconnect device benchmark testing198.51.100.0/24 TEST-NET-2203.0.113.0/24 TEST-NET-3224.0.0.0/4 Multicast
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.