Mark a Best Answer
Fortinet Community
Recently active
I am using the FortiWeb 7.6.0 Web Application Firewall and have a question regarding the threshold-based profiles under the bot mitigation policy. Specifically, this pertains to features like: • Vulnerability Scanning Detection• Crawler Detection• Slow Attack Detection• Content Scraping Detection Currently, I do not see an option to set separate thresholds for single IPs versus shared or NATed IPs. This presents a challenge, as shared IPs naturally generate higher traffic and are more likely to exceed thresholds. The WAF then monitors and blocks such IPs for a default duration (e.g., 5 minutes), which could disrupt legitimate users behind those shared IPs. To address this, one solution could be increasing the thresholds to accommodate shared IP traffic. However, doing so risks giving excessive leeway to a single IP, which could be exploited by malicious users. Whitelisting shared IPs is not a viable option either, as it could lead to security risks if one of the users be
Exactly as the title says. I have searched the forums and havent found anything that does this. Its either "use the admin lockout settings" or blocks after the first failed attempt, which will create and excess number of trouble tickets from end users if that is the case. I need the automation to check if the ip address has multiple failed attempts before adding the address to the block list. We do not have a fortianalyzer at this time. Is this possible without one or is a FortiAnalyzer required for this type of automation.
Since FortiToken is OAUTH compliant, can we not use Google Authenticator instead? Anyone been able to work that out? thanks,
Hi Community, I've got a FortiMail cluster on customers side where a SPAM-Attack as Newsletterbombs running agains employees mailboxes. There are nearly thousand's of Newsletters (Nearly all from valid senders all over the world). So the mailboxes are full of non-sense mails day by day. What i've done so far is:* SPF, DKIM and DMARC Checks enabled* AntiSpam Profile with Newsletter and suspicious Newsletters in UserQaurantine* additionally add a content filter in mailheader based on dictionary "list-unsubscribe" Session settings:* Restrict numbers of conn/client/30min : 120* Restrict numbers of msg/client/30min: 150* Restrict numbers of recips/client/30min: 50* Max concurrent connections/client: 2* Timeout idle: 30---------* Sender reputiation: enabled* Throttle client: 0* Restrict number of mail/hour: 5* Restrice mail to 1 % of prev. hour* Temp. fail client: 50* Reject client: 80* FortiGuard IP reputation check: when client connects Did some has an idea to save the
I have created Installers but the link to download lists it as "Will start processing shortly" This has been like this over the weekend with no change. Is there any troubleshooting to see why it will not generate a download link.
Cannot apply default webfilter-profile to external Firewall policy. It fails with no error and I am not sure what I am doing wrong or how to correct this problem. I am following the guide below while using FortiManager Cloud: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-deep-inspection-and-import-a/ta-p/196840 I can apply the below settings:application-list - defaultav-profile - defaultips-sensor - defaultssl-ssh-profile - deep-inspection However, when I configure: webfilter-profile - default The policy fails to apply with no error, see log below: Starting log (Run on device) Start installingtestsr-fortigate $ config firewall policytestsr-fortigate (policy) $ edit 8testsr-fortigate (8) $ set ssl-ssh-profile "deep-inspection"testsr-fortigate (8) $ set webfilter-profile "default"testsr-fortigate (8) $ nexttestsr-fortigate (policy) $ end ---> generating verific
Hi there, I have an issue with an IPsec vpn sometimes it work and sometimes not.I have 2 users, sometimes one user is unable to receive trafic and sometimes both are unable to receive traficThe configuration is the same, here are two screenshot frome the same VPN and diffrent workstation Best Regards
Hi all are there any usable parameters / variables in CLI scripts? Like $HOSTNAME is there a list available?
Hello All,I have Fortinet Single Sign-On (FSSO) Agent installed in DC Agent mode on both of my domain controllers (DC01 and DC02).Observations:When a user logs into the network with DC01 as their logon server:The user appears in the Show Logon Users list on the FSSO agent.The collector forwards this information to FortiGate, and the user is also visible in the FSSO user list on FortiGate.When a user logs in with DC02 as their logon server:The user appears in the Show Logon Users list on the FSSO agent on DC02.However, this information is not forwarded to FortiGate.Troubleshooting Steps Taken:Verified that FortiGate can connect to both domain controllers on TCP/8000 without any issues.Confirmed that the registry path Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FSAE\DCAgent\CA contains the IP addresses of both DC01 and DC02 on both servers.Confirmed the IP address of DC02 as a secondary-server in the FortiGate configuration.Restarted FSSO services on both DC01 and DC02.De-authenticated
Good afternoon,I have just upgraded some of the company computers to FortiClient VPN 7.4.1.1736.We use SAML authentication to log in. On 90% of them everything seems fine, but on the remaining 10% they always get 'Credential or SSLVPN configuration is wrong. (-7200)'. I have tried to log in to the VPN on the affected machines and I get the same problem. On my machine, everything works fine, I have the same configuration as I deployed through Intune, and the affected machine's primary user can connect to the VPN from my machine. So it doesn't seem to be a problem with the credentials or the SSL configuration. One thing that seems strange to me is that the Fortinet SSL VPN Virtual Ethernet Adapter is missing from their network adapters. Despite our attempts to reinstall the Forticlient, the adapter won't appear. Could this be the problem? How can we solve this? Here are the few logs I was able to get from the client: 11/12/2024 11:33:28 info sslvpn date
Hi guys, We are starting to deploy 2x4 Clustered FortiADC redundancy on 2 Different locations, would like to ask if you have a reference configuration sample guide in which it indicates best practices, standard hardening configurations and HA Configurations. Thank you in advance.
Hello.FortiOS 7.4.5I have several IPsec tunnels, I need help with this problem.
Good day Folks! I just wanna ask what is the reason behind this extra logs when remote users is connecting using forticlient (IPSEC-VPN). As per checking the the forticlient ID (that is unique and cant be duplicated) and other info are the same with the user. see attached image (Fortigate 7.2.10)
Hello Guys, I hope you're all doing well.I'm fairly new to Fortinet's SD-WAN and recently tried to do a deep dive into it. So I set up a lab with fortimanger and 3 fortigate, one as a hub and the other two as spoke. The aim is to understand how it really works and to set up all the configuration using a CLI model without using “orchestration overlay” in order to understand all the steps. I've read a lot of different articles on Fortinet documentation and other websites and I've seen a lot of different configurations/design depending on the Forti OS version. I'm really struggling to understand the different designs and the best mode to use depending on the situation, and also how certain concepts work. So I hope to find my answers here... Since the 7.0.x version : => BGP on loopback + ADVPN 2.0 (RR-less) : => BGP on loopback + ADVPN 2.0 (RR) : Before the 7.0.x version : => BGP on overlay interface (VTI) +
I have a site to site vpn mounted with my private subnet (10.0.1.0/24) and Teltonika router RUT951 subnet (192.168.10.0/24) which is connected to internet through dial up (SIM Card Telcel). The site to site is up and successfully running on phase1 and phase2 selectors..... But I canNOT ping or telnet from server in private net to the router RUT951 itself nor any device behind the router.But I am able to do ping or telnet successfully from router RUT951 to server in private net. From Fortigate CLI tried to do ping on 192.168.10.1, but no luck.My guess is the issue should be on the firewall of the router RUT951, but I am new on this so I need help. I have both policies allowing all access from RUT951 -> PRIVATE NET and PRIVATE NET -> RUT951 like below: PRIVATE NET -> RUT951 Policy (This one does not work if doing ping or telnet disabling or enabling NAT, same result). RUT951 -> PRIVATE NET (This one works perfect i can do ping
I have two firewalls of 1101E fortinet. HA has syncronization issue. There are different 15 parameters which are not synchronized with primary how can I cope with this issue?. Same primary firewall when we enable IPsec VPN based policy give error in tunnel interface but via cli not issued
Hello Guys. We have two Fortigate 201F firewalls in HA setup. Recently, we upgraded the firmware to 7.6.0 and evrything has been working fine, lately, we have noted that the memory usage has been going up everyday and currently we are at 82% and soon we might start having the firewalls go to conserve mode. Is this a bug in the firmware? how do we make the memory usage to go down? Regards.
Question regarding some Hub and Spoke SD-WAN configuration thoughts.Hub - Single ISP, MPLS to remote spokes.Spokes - 2 ISP + MPLS to main Hub.Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.Question... is this possible?Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?So, with that out of the way I have the following scenario:Hub1 - Single Internet Connection, Single MPLS connection.Hub2 - Single Internet Connection, Single MPLS connection to Hub1.Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration. Is t
I'm playing with another VDOM setup. This time the Root vdom will hold the primary traffic while a sub vdom will only have an inbound IPSec VPN connection for remote clients to connect too via forticlient. I've got the root vdom setup and it's passing traffic correctly. The VPN terminates at VDOM-A.Here is a network mapI've got a VIP at the root vdom that's passing traffic through to the 10.2.2.2 IP. I've got the firewall rule at root that's allowing traffic inbound to the VIP. In VDOM-A, I've got VPN configured with the 10.2.2.2 interface (the intervdom link) so it should be all setup correctly. The "external" (this is all in a lab, no actual real IPs involved) IP for the IPSec VPN is 40.40.40.35. When I try to connect from a VPN client, the connection just times out and won't connect.If I run a "diagnose sniffer packet any 'host 40.40.40.35'" and run a ping 40.40.40.35 from the VPN client, I see traffic. However, when I actually try to connec
I need some assistance with finishing up getting the FortiTokens working. Newbie at this, so bare with me please. I have loaded all the FortiTokens up, and see them all on the 100F. I have created a RADIUS group in AD and can validate that the 100F is talking to the RADIUS server. When testing, The VPN client (the free version) does prompt the test user but asks for the FortiToken number - does not push the Mobile display 6 digit code. Then it disconnects. I have not done the following yet for the command line: config system ftm-pushset server-ip XXX.XXX.XXX.XXXset status enableend Where XXX.XXX.XXX.XXX is the public IP of our 100F device - correct?Then I would need to contine to doing this:Go to Network > Interfaces.Edit the wan1 interface.Under Administrative Access > IPv4, select FTM.Click OKIs this all I would need to do to get the FortiToken push working? BTW - runn
Hello, I need a working example of setting two firewall shaping-policies to match DSCP EF and AF43 respectively. I don't understand how to use the commands set tos-mask and set tos as explained in CLI ref. for 6.2 (the examples and the documentation is pure crap IMHO). I'm thinking of using set tos-mask 0xc0 and set tos 0xb8 for EF and set tos 0x98. Do you think this is correct or should I use different values? ThanksAndreas
I have inherited a few Fortigates on on network and dont work with them much and need to check the SD WAN side of things.Both have 2 x 1gbps circuits, but the configs are slightly different under SD-Wan.Is there a way to check that they are load balancing over both circuits ?
Firewall_Robot # exec telnet 10.69.73.2 8000Trying 10.69.76.2...Timeout!Failed to connect to specified unit.Console line is in use. Clear it before next try. Can i change the port anybody with solution please send
Hi all,I try to understand how to access Fortiauthenticator via cli for troubleshoot dns resolution.I check via putty the port is open, but I don't have permission to access with full permission user.I need to execute a simple dns lookup and ping to reach push.fortinet.com and ftc.fortinet.com .Thank you Vincenzo
Good morning, After upgrading to Android 15 (phone One Plus 12), the Forticlient VPN stopped working.When I tap connect, like usual,the gray dots start becoming green, but at about 60% they start over and no error is shown. It does the same result even putting wrong credentials, seems that it never reaches the portal.The portal homepage is correctly displayed with a common browser.VPNs (of course) are working for other android/ios/windows devices.Tried varoius version of the client: 7.0.x, 7.2.x 7.4.x all with the same behaviour.Before upgrading android, all worked fine. Some configuration details:Device: One Plus 12 (CPH2581_15.0.0.204(EX01))Client: Forticlient VPN 7.4.1.0176Firewall: Fortigate 100F 7.0.15Portal port: 10433 What I can else do? Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.