Mark a Best Answer
Fortinet Community
Recently active
Hello everyone, Does anyone please know where I can find Fortinet products presentations individually on the Partner portal ? Best regards,
Hi,We have a Fortinet account, when we login in the support website, we never recieve the security code to e-mail. When we try the "Lost FortiToken" option we recieve the code but it doesn´t work either What can we do? Regards
Hello all, I have a problem with IPsec SAML under Windows 11 24H2 with FortiClientVPN 7.4.1.1736 free version. The connection is established, but I don't see any bytes for incoming traffic. Therefore the routing in the internal VLAN does not work, also the routing to the outside does not work. The same tunnel works perfectly with the FortiClientVPN 7.4.2.0151 and the same SAML user on the iOS iPhone 15 Pro. Except for the fact that I have to exclude the SAML application from my Microsoft CA compliant device policy. Here is the debug of the VPN connection. 100f_serverroom # diag debug reset 100f_serverroom # diag debug console timestamp en 100f_serverroom # diag vpn ike log filter name "XXXXXX IPsec" 100f_serverroom # diag debug application ike -1 Debug messages will be on for 30 minutes. 100f_serverroom # diag debug enable 100f_serverroom # 2024-12-10 11:36:43.276210 ike V=root:0: comes 34.199.9.216:500->xx.xx.xx.xx:500,ifindex=7,vrf=0,len=76.... 2024-12-1
I did follow the tech doc as belowhttps://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-configure-a-VIP-using-a-loopback-interface/ta-p/194521but when debug flow, i receive reverse path check fail, drop error when after the DNAT success FortiGate1. Loopback IP 192.168.1.2542. Port 1 (WAN) - 192.168.1.1/283. Port 2 (LAN) - 192.168.1.128/284. Site to Site VPN (S2S-DC)Route static10.1.1.0/24 via port 2172.16.30.0/24 via S2S-DCmy connection is come from site to site vpn DC 172.16.30.1 --> loopback 192.168.1.254 (DNAT - 10.1.1.1) --> Port 2 --> 10.1.1.1routing shouldnt be problem but debug flow still receive error reverse path check fail, drop, looking for 192.168.1.254 although is connected.I perform PCAP on S2S-DC , packet did reach to FW.PCAP on port 2 no source ip 172.16.30.1 found. the packet been drop in fw and not related to return routeupdate : i restart router engine still having such issue
Hi there, I have a problem with my FortiGate 100F, I have deployed a web application server with a certificate from digiCert and internally everything works, the certificate is well installed, but when external users connect to it there is a problem with the certificate because FortGate uses its default certificate and there is a warning, I have also imported my certificate but when I want to fix it on the FortiGate there is an error, I need help because most of the users will be external and I need there to be no warning associated with the certificate. Thanks,
Hi everyone,We've recently started migrating a few services behind a proxy address using FortiEMS tags. Most of these services are simply websites (HTTPS), and about 95% of the resources work as expected. Since we are also using FortiManager for global firewall management, I had the idea to implement a similar setup.On the EMS, I've created a few tags (such as Admin workstation, specific IP range/address, etc.). On the FortiGate, we set up a ZTNA server (HTTPS) with the FortiManager IP as the real server and created the corresponding ZTNA policy with tag filtering.So far, so good. Accessing the FortiManager works as expected—the login page displays correctly, and logging in with local or SAML credentials works seamlessly. However, once I enter any ADOM, while I can see the number of managed FortiGates, nothing is displayed. No FortiGates show up in the managed view, and there's no access to logs (separate FAZ).Interestingly, I can see our managed FAZ within the ADOM as a device. Am I m
I am using the FortiWeb 7.6.0 Web Application Firewall and have a question regarding the threshold-based profiles under the bot mitigation policy. Specifically, this pertains to features like: • Vulnerability Scanning Detection• Crawler Detection• Slow Attack Detection• Content Scraping Detection Currently, I do not see an option to set separate thresholds for single IPs versus shared or NATed IPs. This presents a challenge, as shared IPs naturally generate higher traffic and are more likely to exceed thresholds. The WAF then monitors and blocks such IPs for a default duration (e.g., 5 minutes), which could disrupt legitimate users behind those shared IPs. To address this, one solution could be increasing the thresholds to accommodate shared IP traffic. However, doing so risks giving excessive leeway to a single IP, which could be exploited by malicious users. Whitelisting shared IPs is not a viable option either, as it could lead to security risks if one of the users be
Exactly as the title says. I have searched the forums and havent found anything that does this. Its either "use the admin lockout settings" or blocks after the first failed attempt, which will create and excess number of trouble tickets from end users if that is the case. I need the automation to check if the ip address has multiple failed attempts before adding the address to the block list. We do not have a fortianalyzer at this time. Is this possible without one or is a FortiAnalyzer required for this type of automation.
Since FortiToken is OAUTH compliant, can we not use Google Authenticator instead? Anyone been able to work that out? thanks,
Hi Community, I've got a FortiMail cluster on customers side where a SPAM-Attack as Newsletterbombs running agains employees mailboxes. There are nearly thousand's of Newsletters (Nearly all from valid senders all over the world). So the mailboxes are full of non-sense mails day by day. What i've done so far is:* SPF, DKIM and DMARC Checks enabled* AntiSpam Profile with Newsletter and suspicious Newsletters in UserQaurantine* additionally add a content filter in mailheader based on dictionary "list-unsubscribe" Session settings:* Restrict numbers of conn/client/30min : 120* Restrict numbers of msg/client/30min: 150* Restrict numbers of recips/client/30min: 50* Max concurrent connections/client: 2* Timeout idle: 30---------* Sender reputiation: enabled* Throttle client: 0* Restrict number of mail/hour: 5* Restrice mail to 1 % of prev. hour* Temp. fail client: 50* Reject client: 80* FortiGuard IP reputation check: when client connects Did some has an idea to save the
I have created Installers but the link to download lists it as "Will start processing shortly" This has been like this over the weekend with no change. Is there any troubleshooting to see why it will not generate a download link.
Cannot apply default webfilter-profile to external Firewall policy. It fails with no error and I am not sure what I am doing wrong or how to correct this problem. I am following the guide below while using FortiManager Cloud: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-deep-inspection-and-import-a/ta-p/196840 I can apply the below settings:application-list - defaultav-profile - defaultips-sensor - defaultssl-ssh-profile - deep-inspection However, when I configure: webfilter-profile - default The policy fails to apply with no error, see log below: Starting log (Run on device) Start installingtestsr-fortigate $ config firewall policytestsr-fortigate (policy) $ edit 8testsr-fortigate (8) $ set ssl-ssh-profile "deep-inspection"testsr-fortigate (8) $ set webfilter-profile "default"testsr-fortigate (8) $ nexttestsr-fortigate (policy) $ end ---> generating verific
Hi there, I have an issue with an IPsec vpn sometimes it work and sometimes not.I have 2 users, sometimes one user is unable to receive trafic and sometimes both are unable to receive traficThe configuration is the same, here are two screenshot frome the same VPN and diffrent workstation Best Regards
Hi all are there any usable parameters / variables in CLI scripts? Like $HOSTNAME is there a list available?
Hello All,I have Fortinet Single Sign-On (FSSO) Agent installed in DC Agent mode on both of my domain controllers (DC01 and DC02).Observations:When a user logs into the network with DC01 as their logon server:The user appears in the Show Logon Users list on the FSSO agent.The collector forwards this information to FortiGate, and the user is also visible in the FSSO user list on FortiGate.When a user logs in with DC02 as their logon server:The user appears in the Show Logon Users list on the FSSO agent on DC02.However, this information is not forwarded to FortiGate.Troubleshooting Steps Taken:Verified that FortiGate can connect to both domain controllers on TCP/8000 without any issues.Confirmed that the registry path Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FSAE\DCAgent\CA contains the IP addresses of both DC01 and DC02 on both servers.Confirmed the IP address of DC02 as a secondary-server in the FortiGate configuration.Restarted FSSO services on both DC01 and DC02.De-authenticated
Good afternoon,I have just upgraded some of the company computers to FortiClient VPN 7.4.1.1736.We use SAML authentication to log in. On 90% of them everything seems fine, but on the remaining 10% they always get 'Credential or SSLVPN configuration is wrong. (-7200)'. I have tried to log in to the VPN on the affected machines and I get the same problem. On my machine, everything works fine, I have the same configuration as I deployed through Intune, and the affected machine's primary user can connect to the VPN from my machine. So it doesn't seem to be a problem with the credentials or the SSL configuration. One thing that seems strange to me is that the Fortinet SSL VPN Virtual Ethernet Adapter is missing from their network adapters. Despite our attempts to reinstall the Forticlient, the adapter won't appear. Could this be the problem? How can we solve this? Here are the few logs I was able to get from the client: 11/12/2024 11:33:28 info sslvpn date
Hi guys, We are starting to deploy 2x4 Clustered FortiADC redundancy on 2 Different locations, would like to ask if you have a reference configuration sample guide in which it indicates best practices, standard hardening configurations and HA Configurations. Thank you in advance.
Hello.FortiOS 7.4.5I have several IPsec tunnels, I need help with this problem.
Good day Folks! I just wanna ask what is the reason behind this extra logs when remote users is connecting using forticlient (IPSEC-VPN). As per checking the the forticlient ID (that is unique and cant be duplicated) and other info are the same with the user. see attached image (Fortigate 7.2.10)
Hello Guys, I hope you're all doing well.I'm fairly new to Fortinet's SD-WAN and recently tried to do a deep dive into it. So I set up a lab with fortimanger and 3 fortigate, one as a hub and the other two as spoke. The aim is to understand how it really works and to set up all the configuration using a CLI model without using “orchestration overlay” in order to understand all the steps. I've read a lot of different articles on Fortinet documentation and other websites and I've seen a lot of different configurations/design depending on the Forti OS version. I'm really struggling to understand the different designs and the best mode to use depending on the situation, and also how certain concepts work. So I hope to find my answers here... Since the 7.0.x version : => BGP on loopback + ADVPN 2.0 (RR-less) : => BGP on loopback + ADVPN 2.0 (RR) : Before the 7.0.x version : => BGP on overlay interface (VTI) +
I have a site to site vpn mounted with my private subnet (10.0.1.0/24) and Teltonika router RUT951 subnet (192.168.10.0/24) which is connected to internet through dial up (SIM Card Telcel). The site to site is up and successfully running on phase1 and phase2 selectors..... But I canNOT ping or telnet from server in private net to the router RUT951 itself nor any device behind the router.But I am able to do ping or telnet successfully from router RUT951 to server in private net. From Fortigate CLI tried to do ping on 192.168.10.1, but no luck.My guess is the issue should be on the firewall of the router RUT951, but I am new on this so I need help. I have both policies allowing all access from RUT951 -> PRIVATE NET and PRIVATE NET -> RUT951 like below: PRIVATE NET -> RUT951 Policy (This one does not work if doing ping or telnet disabling or enabling NAT, same result). RUT951 -> PRIVATE NET (This one works perfect i can do ping
I have two firewalls of 1101E fortinet. HA has syncronization issue. There are different 15 parameters which are not synchronized with primary how can I cope with this issue?. Same primary firewall when we enable IPsec VPN based policy give error in tunnel interface but via cli not issued
Hello Guys. We have two Fortigate 201F firewalls in HA setup. Recently, we upgraded the firmware to 7.6.0 and evrything has been working fine, lately, we have noted that the memory usage has been going up everyday and currently we are at 82% and soon we might start having the firewalls go to conserve mode. Is this a bug in the firmware? how do we make the memory usage to go down? Regards.
Question regarding some Hub and Spoke SD-WAN configuration thoughts.Hub - Single ISP, MPLS to remote spokes.Spokes - 2 ISP + MPLS to main Hub.Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.Question... is this possible?Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?So, with that out of the way I have the following scenario:Hub1 - Single Internet Connection, Single MPLS connection.Hub2 - Single Internet Connection, Single MPLS connection to Hub1.Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration. Is t
I'm playing with another VDOM setup. This time the Root vdom will hold the primary traffic while a sub vdom will only have an inbound IPSec VPN connection for remote clients to connect too via forticlient. I've got the root vdom setup and it's passing traffic correctly. The VPN terminates at VDOM-A.Here is a network mapI've got a VIP at the root vdom that's passing traffic through to the 10.2.2.2 IP. I've got the firewall rule at root that's allowing traffic inbound to the VIP. In VDOM-A, I've got VPN configured with the 10.2.2.2 interface (the intervdom link) so it should be all setup correctly. The "external" (this is all in a lab, no actual real IPs involved) IP for the IPSec VPN is 40.40.40.35. When I try to connect from a VPN client, the connection just times out and won't connect.If I run a "diagnose sniffer packet any 'host 40.40.40.35'" and run a ping 40.40.40.35 from the VPN client, I see traffic. However, when I actually try to connec
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.