Mark a Best Answer
Fortinet Community
Recently active
Hello Team, In my network with fortigate firewall with fortios 7.2.7 I am having an issue that I cant find a resolution when inverstigating my firewall logs.all access logs are stored no problems with action accept/deny, when that is according to a policy role.But when ever I try to connect to server to a non opened port then we supposed to rejected by the server but the log still logged with the action accept or Deny when is not happening.how to find these logs that was not successful "from my destination" but allowed from the side of the firewall it self.knowing that I am running my firewall in policy-based mode.And, when checking the logs, what does policy Name "Default" means that I see in the logs received alot? TIA.
Forticlient 7.2.7.0905Ubuntu 22.04 I am getting this error when i try to establish a ssl-vpn connection.I'm not quite sure what it could be. 20241215 21:18:42.763 TZ=-0300 [sslvpn:DEBG] vpn_connection:1422 Login process end on status: 020241215 21:18:42.763 TZ=-0300 [sslvpn:INFO] sslvpn:834 Login successful20241215 21:18:42.785 TZ=-0300 [sslvpn:INFO] main:1483 State: Configuring tunnel20241215 21:18:42.786 TZ=-0300 [sslvpn:INFO] nettools:1758 More than one device with index 3 can be found20241215 21:18:42.786 TZ=-0300 [sslvpn:INFO] nettools:1758 Device address details: local_address 192.168.100.15, device_index 3, device name wlp0s20f3 (read from netlink)20241215 21:18:42.786 TZ=-0300 [sslvpn:INFO] nettools:1758 Device address details: local_address fe80::7194:85de:d7a:c897, device_index 3, device name wlp0s20f3 (read from netlink)20241215 21:18:42.808 TZ=-0300 [sslvpn:DEBG] vpn_util:275 Get connection name: TLC_HERNANDEZ_fe20241215 21:18:42.809 TZ=-0300 [sslvpn:DEBG] vif:126
Hello colleagues, Does anyone here have a method to manage all rules from several firewalls to ensure that we have some condition enabled or disabled? For example - Running a script to all rules and enabling Security Groups Profiles.I tried via Fortimanager and without sucess so far. There is not possibility as well directly via CLI on Fortigate to manage than a single policy.Does anyone has any idea?
I have 4 real DNS servers behind a common Virtual Server using UDP forwarding on port 53 on our FortiGate that has been working for several years. I now have the requirement for the client IP to be preserved for the DNS servers so they can apply their own policies to the client traffic based on source IP. It is currently being replaced by the FortiGate's IP. Any suggestions on how to achieve this? Cheers - Mike SOLVED: it was easier than NAT(which was not on) it was the flow/proxy setting - oops
Hi,we have a VLAN on a 40F that is being provided through some 3rd party access points. We enabled the disclaimer portal for that VLAN for guest access. We don't want them to type in an E-Mail or provide guest accounts.The disclaimer portal works well but we need to extend the (idle) timeout to more than 300 seconds.Where can I do that? None of the settings seem to alter that value. I tried:config user setting > set auth-timeout Xconfig wireless-controller timers > set client-idle-timeout Xconfig system settings > set auth-timeout X In this article using a mail collection portal, it is somehow set to 10 days (864000) by defaultRetail environment guest access | FortiGate / FortiOS 7.6.0 | Fortinet Document Library But mine always looks like this:192.168.3.17 src_mac: 98:69:8a:XX:XX:XX type: disclaimer, id: 14, duration: 368, idled: 210 expire: 90, allow-idle: 300
I am working at a SOC where we receive traffic from Fortinet firewalls.One of my contacts has configured syslog to my Ubuntu server, but I only see the following data: <11>Dec 5 13:32:16 ti110211101x110 RT_IDS <14>Dec 5 13:32:16 ti110211101x110 RT_FLOW I would think that I should have this type of data: <45>date=2024-07-03 time=09:29:01 devname="alpha-fortigate" devid="FGT40FTK2209B06Q" eventtime=1719991739997635239 tz="+0200" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" srcip=192.168.1.110 srcport=55178 srcintf="lan" srcintfrole="lan" dstip=1.1.1.1 dstport=53 dstintf="wan" dstintfrole="wan" srcuuid="f8eef6a8-718a-51ee-c800-48fa677761f7" dstuuid="f8eef6a8-718a-51ee-c800-48fa677761f7" srccountry="Reserved" dstcountry="Australia" sessionid=79980663 proto=6 action="close" policyid=1 policytype="policy" poluuid="feafac0e-718a-51ee-3d8f-17868e4a5bab" policyname="Default test" service="DNS" trandisp="snat" transip=192.168
I have a fortigate 60f connected to a fortiswitch 108F-FPOE (full power switch), then connected to a fortiap 231f and a 441k. I have created an ssid that only supports wifi6e using 6ghz, is enabled, has wpa3 sae for security, shows that it is enabled in the dashboard. however it is not broadcasting... one small issues I noticed I set the channels to only allow uni5 and uni6 however it still says it is using channel 1. any support would be great thanks.
Hi everyone,I do have a web filter profile on FortiClient EMS which requires FortiClient Browser Add-On to be installed. The web-filter profile is only required when off-fabric. I did notice that the Browser Add-On is missing on edge after it was installed, on firefox it stays installed but users can remove it manually. In both ways FortiClient brings up a pop up notification "browser anomaly detected". I think the browser add-on stayed installed some weeks ago.(Currently running FortiClient 7.2.6) and only needed to be installed once. If the web filter was active or not had not any impact on the installation status.Is this a new bug or some configuration error?
Hello everyone,I did enable web filter on our FortiClients when outside company LAN. Some users notified me that they get a lot of pop up notifications from FortiClient: It seems like FortiClient does block some IPs that belong to Microsoft teams (according to ioc.fortiguard.com). These IPs get blocked over several clients.Any ideas how to fix this? As far as I know normally there is the URL shown in these logs, seems like Microsoft Teams accesses to IP directly without DNS?
need to understand how to manage device group related policies using ssh to forti manager device.like in device we can configure policy using Example: ##config firewall policyedit < Policy ID> set srcaddr < source IP> set dstaddr <destination IP> set service < <Service name>set schedule <always or define schedule> nextendsame thing need to apply using FortiManager.
Support closed my 2 day old ticket by accident, their only solution is to make a new ticket with the same priority, so add another 2 days to my response time. I can call in to escalate it but I am not in a spot to be able to call for about 48h and chat support can't escalate beyond P3. Why can they not reopen a ticket that was closed by mistake less than 20 minutes prior? It's absolutely ridiculous. Fortinet has to be the worst support I've received all year aside from Bell
Hi everyone I'm having an IPSec connection problem. This issue occurs after my router shuts down. Below is the debug log. I want to know where the problem is and how to fix it. TCTPK-FG100F-12F-02 # ike 0:IPSec1viaPANET:5396: negotiation timeout, deletingike 0:IPSec1viaPANET: connection expiring due to phase1 downike 0:IPSec1viaPANET: deletingike 0:IPSec1viaPANET: deletedike 0:IPSec1viaPANET: schedule auto-negotiateike 0:IPSec1viaPANET:IPSec1viaPANET: IPsec SA connect 7 61.47.81.6->203.104.128.66:0ike 0:IPSec1viaPANET:IPSec1viaPANET: config foundike 0:IPSec1viaPANET: created connection: 0x89da900 7 61.47.81.6->203.104.128.66:500.ike 0:IPSec1viaPANET: IPsec SA connect 7 61.47.81.6->203.104.128.66:500 negotiatingike 0:IPSec1viaPANET: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiationike 0:IPSec1viaPANET:5397: out 2B1093AB74FCEA5500000000000000002120220800000000000001D8220000880200002C010100040300000C0100000C800E010003000008020000050300000803
We're currently experiencing issues with the FortiClient VPN with Azure SSO connection.We have around 150 users for who it works perfectly fine, but for two users it doesn't work, they instead get the message "You've signed out of your account", followed by a 'Session ended' screen from FortiGate.I've done some research online and have tried the following fixes and tests:> The Forticlient on the specific users laptop works when signing in with a different account> Their account doesn't work on my laptop, where my accounts do workThis basically concludes it's an account issue and not a device issue.Next i've checked/done the following this:> Made sure they are members of the SSO group with access for the FortiClient SSO> Reset their Refresh Tokens in Azure> The Enterprise application shows a successful login for the user with issues> The user sign-in history shows only successful logins as wellResetting the RefreshToken in Azure did solve the problem for one user, but
Hi FGT adminsI have one FGT 101F with FOS 7.2.10.I found the following config error.FGT # get system startup-error-log >>> "set" "gui-endpoint-control-advanced" "enable" @ root.system.settings:command parse error (error -61)The error is "probably" due to someone who did a firmware update without following the right update path.I know this error should not have any major impact on the Gate, but is there any method to correct this error without doing backup, correct the config, and then restore?For info, the parameter "gui-endpoint-control-advanced" is not valid anymore on 7.2.10.
Hello!I testing offline license validation for my closed network installation and meet some troubles.I have FortiAnalyzer 7.2.5 with evaluation license and while it is connected to Forti validation servers it`s OK, but when I disconnect it from internet the license drops to Duplicate License" status, and I have log messages like:"License validation state changes from Trial License Init to Found disconnecting because of Server No Response"and after that:"License validation abnormal: state Expired Grace Period on disconnecting, event Server No Response"and FAZ ask for internet connection to validate license or upload .lic file.Uploading lic file resolve this problem for about a 1 hour and then I get license issue again. I tried "Method 2" as described there: https://community.fortinet.com/t5/FortiManager/Technical-Tip-FortiManager-FortiAnalyzer-VM-License-Validation/ta-p/309894Add FAZ mgmt ip to support portal and download new license file, but problem still there.som
I am trying to activate a Trial license for a 7.2.1 Fortigate VM - I have an active Fortinet account with FGT's under current contracts. When I try and activate the evaluation license I get the error below. Gui error: From the CLI I see this. Requesting FortiCare Trial license, proxy:(null) The unit has unrestricted access to the internet (DNS etc) here is the port config for the interface I am using config system interface edit "port3" set vdom "root" set mode dhcp set allowaccess ping https ssh http fgfm speed-test set type physical set snmp-index 3 next end
Good day to all,I am new to FortiGate and I was wondering if I have two WAN interfaces, can I redirect TikTok traffic to WAN1 and everything else to WAN2?Thanks in Advance!
I would ask you for a hint in reference to the scheme that I send below. Is it possible to achieve the full redundancy of IPSec tunnels, not only between the classic site to site between Wan 1 Site A to Wan1 Site B and Wan2 Site A and to Wan2 Site B but also in the variant of the cross link connection if the failures have been connected at the same time alternating at the same time For example, with WAN 1 Site A to WAN 2 Site B and vice versa? From my opinion, the scheme shows that 8 IPSec site tunnels are needed, but how to set it so that regardless of the WAN connection failure there was always traffic between site a and site b, whether it goes use maybe with routing on OSPF, or SD WAN or Link monitor? Best regards,
Dear all I recently updated EMS Server to 7.2.7 build 1125. And somehow is the ZTNA Destinations configuration / view completly different as before. I have now a big list with all ZTNA settings i made, but none are somehow editable.I can only add or delete something. I this now a feature or a bug? I also cannot upload csv files for the configuration as before.The ZTNA configuration was on the version 7.2.4.0983 much more easier and more clear. I found out that I can add an Alias under ZTNA Applications Catalog. So I did that for all entries. But when I go to the ZTNA Destinations menu. The fabric connector name is n/a for all items in the list.So how can I edit all my hundreds of items? OR maybe I do not understand the new way the configuration works :) Cheers hoschi
Hi all, we're using Forticlient 7.0.13 along with Endpoint Management Server 7.0.13. When the Forticlient has no direct connection to the EMS, the user cannot enter his credentials when directly trying to connect via Forticlient Console, the entries disappear within a second. However, connecting will work on the Windows Sign-in Screen (Show VPN before logon). But we have users that have to sign into a - lets say hotel wlan - first and then try to connect via Forticlient Console directly. As our EMS server is not publicly accessible, this way obviously won't work anymore. Before, with version 7.0.12, we haven't had this issue. What is the solution to this? Or is there a workaround so our users can connect via Forticlient Console, when the EMS Server is not visible? Kind regards!
Please can someone urgently assis.t I have upgrade to os 7.4 on my 200E. Created virtual servers for my internal setups. The Virtual Server for Microsoft Exchange / Email connectivity (HTTPS) works perfectly on mobile (IOS, Android)But refuses to work on Outlook ? No errors in logs etc. Any ideas?
Hello, We have a new FG-60F connected to FortiAPs. We're using FortiOS 7.2.3 (latest We have created a standard corporate SSID for staff, which works fine.We want to also host a "Guests" SSID which uses a captive portal with email collection. We have followed the guide at How to create a Guest SSID Network on FortiAP/FortiGate with Captive Portal+Email Collection - YouTube, including the changes on the CLI and creating a firewall policy.We have also created a custom captive portal page (at this point we just changed the logo) We can get to the stage where a client joins the SSID, is presented with the captive portal page, can tick the disclaimer and enter their email address, but then when they submit the page, the web browser just redirects back to the captive portal.We've tried rebooting the FortiGate, the client machine, "forgetting" the SSID and re-joining from fresh, but this keeps happening. Has anyone seen this before? What might be going on he
Hi, we use FortiClient and IPSEC vpn to connect from home to work. We can access the resources on 192.168.100.0 (main office lan) but we also require access to resources on 192.168.200.0 and 192.168.2.0 There is a site-to-site VPN connecting 192.168.100.0 and 192.168.200.0 and 192.168.100.0 and 192.168.2.0
Hello everybody, I'm working in a ZTNA environment. we have a simple ZTNA Firewall Policy rule that is working perfectly for each single Windows user.All the users (windows or macos) have the same tags. I have these tags too (I'm a macOS user):when a macOS user tries to access ZTNA, we can see on Fortigate an error like this:date=2024-10-09 time=16:14:43 id=7423779172176101376 itime="2024-10-09 16:14:43" euid=3 epid=101 dsteuid=3 dstepid=1053 logflag=3 logver=702101706 type="traffic" subtype="ztna" level="notice" action="deny" policyid=15 sessionid=10994158 srcip=xxx dstip=10.1.0.214 srcport=52177 dstport=3389 duration=19603 proto=6 sentbyte=10454368 rcvdbyte=31622617 logid=0005000024 service="RDP" app="RDP" appcat="unscanned" srcintfrole="wan" dstintfrole="lan" policytype="proxy-policy" eventtime=1728483282890140384 wanin=31622617 wanout=7184424 lanin=10454368 lanout=32300828 crscore=30 craction=131072 crlevel="high" poluuid="7f1a8a84-dfd7-51ee-4200-2edb944b93d3" srccountry=
Hello everyone, Does anyone please know where I can find Fortinet products presentations individually on the Partner portal ? Best regards,
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.