Mark a Best Answer
Fortinet Community
Recently active
I'm getting this at the time of creating Radius
hi,i'm trying to create a FW policy in FMG to block "bogon" ipv4.i just saw RFC1918 address FW address object but there's none for "bogon".does fortinet considering to add these address space in a group/address object in future upgrade?can someone also confirm these are true bogon IP ranges? just want to ensure i don't block "legit" traffic/range. IPv4 Bogon RangesNetblock Description0.0.0.0/8 "This" network10.0.0.0/8 Private-use networks100.64.0.0/10 Carrier-grade NAT127.0.0.0/8 Loopback127.0.53.53 Name collision occurrence169.254.0.0/16 Link local172.16.0.0/12 Private-use networks192.0.0.0/24 IETF protocol assignments192.0.2.0/24 TEST-NET-1192.168.0.0/16 Private-use networks198.18.0.0/15 Network interconnect device benchmark testing198.51.100.0/24 TEST-NET-2203.0.113.0/24 TEST-NET-3224.0.0.0/4 Multicast
I am facing Site to site vpn issue since last one week between FortiGate 100F and FGVM00 . VPN tunnel status is up but network connectivity is down. noticed that all the network connectivity and VPN will restore and work few hours if i restart firewall. how to trace the root cause of the issue and fix it permanently.
We had a user report that they were getting an error when trying to install the Forticlient VPN client on their Windows 11 machine. I reviewed the FortiClient00000.log (found in the user temp folder) and found a line saying 1: [08:42:24]: FCSetupWx: Failed to load C:\WINDOWS\system32\difxapi.dll This is a DLL from the Driver Install Frameworks (DIFx) tools. These tools have been deprecated since Windows 10 version 1607, so I have no idea what the FortiFolks are doing using it in 2024. It's also a file that the installer is supposed to provide if it's not present, but the Forticlient installer appears to assume it is already on the system, hence the error. Anyway, you can work around the issue by copying the difxapi.dll file from another machine into the C:\Windows\System32 folder. Hope this helps someone.
Hi, How to use sbl.spamhaus.org block list IP at Threat Feeds external connectors? Best Regards, Jackson Ku
Hello Expert, New some guidance I notice the Next Scheduled Trigger is showing 15 Dec 2024 and the backup was transfer via tftp on the 16 Dec 2024. The backups and subsequent transfer to tftp server keep looping unsure if this date issue is responsible for the backup attempting to run multiple time during the day. Include two screen shot for guidance Can any one please assist. Regards
Hi,I've been trying to get a vm (on vmware Esxi) for analysis up and running for a week now, but I keep getting a duplicate license error.I have already tried the solutions found in the community, but they did not work.I would like to point out that I created a new account and installed only one vm, so it is not possible that there is a duplicate.Fortinet support told me to write here.I report the info of the vm when is start: ConnectedFortilog diag debug vminfoVM license is valid.fds_code: 0Type: TrialLicensed GB/Day: 1Max devices: 3Management IP: 0.0.0.0Serial Number: FAZ-VMTM24015036VM UUID: f0af2342-5836-ee19-1d02-a27e876d21e6 and this after 5 minutes: Fortilog diag debug vminfoVM license is valid.fds_code: 0Validation: Duplicate LicenseExpired in : 6 days 23 hours 52 minutesType: TrialLicensed GB/Day: 1Max devices: 3Management IP: 0.0.0.0Serial Number: FAZ-VMTM24015036VM UUID: f0af2342-5836-ee19-1d02-a27e876d21e6Fortilog Can someone help me?Th
Hi, We are using Aruba as wireless controller and FortiNAC is acting as Local Radius Server, EAP type is TLS and TTLS.We wanted to enable certificate base authentication for the users who will try to connect wifi.For Wired users its working perfectly fine but for Wireless Users we seen that the without certificate users are able to connect.. In Radius Logs we seen that the Authentication method is MSCHAPV2, that should not work as its disabled in Radius Default Config. Please guide.
Hello, A company has registered their FortiGate device under their own FortiGate Cloud account. If I change it to my own FortiCloud account, will I lose my Forti license? Best regards.
I am reaching out to request immediate assistance with an urgent issue we are encountering on one of our AWS instances. we stopped the server and restarted the server for maintenance purposes, it is stuck on the boot screen and does not proceed further.The system is displaying the message:"System is starting...Serial number is FGUMSLTM20004409This is a private computer system. Unauthorized access or use is prohibited and subject to prosecution and/or disciplinary action...(Press 'a' to accept)"
We have several FortiGate and need to find SD cards for each that are compatible with 40F's, 70F's and 100F models. Has anyone purchased a particular brand that works well with these units? Thank you,Elaine Jaeger
Hello, on my VPN IPSEC ike2 I can access with the Iphone APP, but I can't access my VPN with the Android app. I want to use pre-share key with SSO but the menu doesn't appear... the option only appears when I select certificate. But I don't want to use certificate. I think this will be a BUG in the application.
I have Fortigate FG120GI want to create many Authen page for many SSID #Example-SSID 1 : Office > Authen office-SSID 2 : Guest > Authen GuestI'm not sure fortigate can to do this Please tell about this, Thank you so much.
Hi Guys.Hope yo can help me. I have a fortisiem deployment with one supervisor, one worker and one collector, with a hot tier disk of 200GB and a warm tier disk of 300GB. Both disks are attached to the supervisor and worker respectively.The clickhouse deployment: Two node clickhouse keeper cluster: 1 supervisor, 1 workerTwo node clickhouse cluster: 1 shard > Replica 1 : Supervisor (Data and Query) Replica 2 : Worker (Data)Yesterday hot tier disk on worker got full (100%) and no more events have been stored and the queue is almost 1100 (1.1GB).On the supervisor hot tier disk is 82% (163GB). In it´s Warm Tier is just 47GB.On the worker hot tier disk is 100%(200GB) .In it´s warm Tier is just 1% (2.2GB)Why did the event moving did not work properly? is there
I got two fortigate at diffirent locations. Both have a single wan ip. Site 1 wan ip: x.x.x.xSite 2 wan ip: y.y.y.yOther interfaces on fortigates will be used for internal network.I want to configure ha these two fortigates over wan interfaces. How can i do this?
I have two firewalls, lan and wan. Lan firewall has DHCP. The users on the LAN go to the internet through the wan firewall. The logs from the lan firewall to the wan firewall show the user's mac address. However, in the logs from the wan firewall to the internet, the interface mac address of the wan firewall appears. Why can this happen?
Hello,I have a problem with the Radius connection my Fortigate and my fortiauthenticator.Last night the security team updated Fortigate to version 7.4.5 since users can no longer connect via VPN.When I go to configuration I get this message I checked the secret carefully and they are identical so I don't understand. The fortigate and the fortiauthenticator communicate well with each other however.Do you have any ideas?Thanks
Hello all, I have a question regarding a design like this. Suppose CheckPoint A is the Master unit for its cluster, while Forgate A and B are in Active-Active HA. Fortigate A or B comes with one virtual wire and the VW1 is connected between the Checkpoint and Core switch. No switch is between Fortigate and Checkpoint. I wonder if Fortigate B receives traffic from a user, can the user stillbe able to use CheckPoint A to access to the internet?
Hi all,I'm trying to uninstall FortiClient on macbook with M1/M2 processor using a script from this article: https://community.fortinet.com/t5/FortiClient/Technical-Tip-Uninstall-FortiClient-using-a-script-on-macOS/ta-p/277070I only added two lines to change flags. Here is my script: #!/bin/sh # Uninstall FortiClient.sh pkill FortiClient launchctl unload /Library/LaunchDaemons/com.fortinet* chflags -hv noschg /Applications/FortiClient.app chflags -hv noschg /Applications/FortiClientUninstaller.app rm -Rfv /Applications/FortiClient.app rm -Rfv /Applications/FortiClientUninstaller.app rm -Rfv /Library/Application\ Support/Fortinet rm -Rfv /Library/Internet\ Plug-Ins FortiClient_SSLVPN_Plugin.bundle rm -Rfv '/Library/LaunchDaemons/com.fortinet.forticlient.vpn.plist' rm -Rfv '/Library/LaunchDaemons/com.fortinet.forticlient.wf.plist' rm -Rfv '/Library/LaunchDaemons/com.fortinet.forticlient.fmon.plist' rm -Rfv '/Library/LaunchDaemons/com.fortinet.forticlient.epctrl.plist' rm -Rfv
Modern applications are the backbone of digital transformation but protecting them has become a daunting challenge. Organizations are grappling with the complexity of multi-cloud environments, evolving architectures, agile development practices, and emerging threats. These factors, coupled with a shortage of skilled professionals, expand the attack surface and create significant visibility gaps. The distributed nature of data across these environments further increases the likelihood of misconfigurations, inconsistencies, and human errors, all of which can lead to data breaches, service disruptions, and enforcement challenges. The Growing Complexity of Application Security Multi-Cloud Environments: Enterprises now operate across multiple cloud providers, each with unique security controls and configurations. This diversity can lead to inconsistencies and potential vulnerabilities. Evolving Architectures: The adoption of microservices, containerization, and serverless com
Is there a way to use FortiManager to build Windows Client Native IPSec tunnels? I know I can do it directly on the device, but wasn't sure if there was a way to centralize it using FMG instead. FMG 7.2.8 (updating to 7.2.9 when the vm image is available)FGT 60F - 7.2.10 I know I can do it directly on the FGT, but was hoping there was a way to do it via VPN Manager in FMG to keep everything consistent.
We are using Sonifi to install ipTV at our property. They have a head end that we connect into our core and they utilize 2 dry vlans for iptv and chromecast. We had some initial speed bumps but have seemingly resolved any issues for multicast, free to guest channels and our custom menu. Documentation requierd us to not be an igmp querier and I have disabled igmp snooping on all edge switches/APs, whitelisted the querier, which is outside our network, and whitelisted it on the Virtual Smart Zone for APs. we are almost a pure Fortinet environment, just with Ruckus H550 APs in guest rooms, utilizing a Virtual Smart Zone. H550s have uplink port to AP and port1 for the tv connection ingress/egress igmp snooping disabled as well. As we're getting closer to completing the install, we've noticed pixelization on channels, though you can hear in real time. This is not widespread and only affects our most recent TVs. Any help would be greatly appreciated and I can provide more information a
HiMy GRE tunel connection is not working after upgrade FortiOS from 7.4.1 > 7.4.3.Forti shows, that connection is UP but I have no access to network. Checked policies, diagnosed connection and everything looks fine.Any idea what to check next? How to monitor? Best regards,Rafal
Hello Team, In my network with fortigate firewall with fortios 7.2.7 I am having an issue that I cant find a resolution when inverstigating my firewall logs.all access logs are stored no problems with action accept/deny, when that is according to a policy role.But when ever I try to connect to server to a non opened port then we supposed to rejected by the server but the log still logged with the action accept or Deny when is not happening.how to find these logs that was not successful "from my destination" but allowed from the side of the firewall it self.knowing that I am running my firewall in policy-based mode.And, when checking the logs, what does policy Name "Default" means that I see in the logs received alot? TIA.
Forticlient 7.2.7.0905Ubuntu 22.04 I am getting this error when i try to establish a ssl-vpn connection.I'm not quite sure what it could be. 20241215 21:18:42.763 TZ=-0300 [sslvpn:DEBG] vpn_connection:1422 Login process end on status: 020241215 21:18:42.763 TZ=-0300 [sslvpn:INFO] sslvpn:834 Login successful20241215 21:18:42.785 TZ=-0300 [sslvpn:INFO] main:1483 State: Configuring tunnel20241215 21:18:42.786 TZ=-0300 [sslvpn:INFO] nettools:1758 More than one device with index 3 can be found20241215 21:18:42.786 TZ=-0300 [sslvpn:INFO] nettools:1758 Device address details: local_address 192.168.100.15, device_index 3, device name wlp0s20f3 (read from netlink)20241215 21:18:42.786 TZ=-0300 [sslvpn:INFO] nettools:1758 Device address details: local_address fe80::7194:85de:d7a:c897, device_index 3, device name wlp0s20f3 (read from netlink)20241215 21:18:42.808 TZ=-0300 [sslvpn:DEBG] vpn_util:275 Get connection name: TLC_HERNANDEZ_fe20241215 21:18:42.809 TZ=-0300 [sslvpn:DEBG] vif:126
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.