Mark a Best Answer
Fortinet Community
Recently active
I have a site to site vpn mounted with my private subnet (10.0.1.0/24) and Teltonika router RUT951 subnet (192.168.10.0/24) which is connected to internet through dial up (SIM Card Telcel). The site to site is up and successfully running on phase1 and phase2 selectors..... But I canNOT ping or telnet from server in private net to the router RUT951 itself nor any device behind the router.But I am able to do ping or telnet successfully from router RUT951 to server in private net. From Fortigate CLI tried to do ping on 192.168.10.1, but no luck.My guess is the issue should be on the firewall of the router RUT951, but I am new on this so I need help. I have both policies allowing all access from RUT951 -> PRIVATE NET and PRIVATE NET -> RUT951 like below: PRIVATE NET -> RUT951 Policy (This one does not work if doing ping or telnet disabling or enabling NAT, same result). RUT951 -> PRIVATE NET (This one works perfect i can do ping
I have two firewalls of 1101E fortinet. HA has syncronization issue. There are different 15 parameters which are not synchronized with primary how can I cope with this issue?. Same primary firewall when we enable IPsec VPN based policy give error in tunnel interface but via cli not issued
Hello Guys. We have two Fortigate 201F firewalls in HA setup. Recently, we upgraded the firmware to 7.6.0 and evrything has been working fine, lately, we have noted that the memory usage has been going up everyday and currently we are at 82% and soon we might start having the firewalls go to conserve mode. Is this a bug in the firmware? how do we make the memory usage to go down? Regards.
Question regarding some Hub and Spoke SD-WAN configuration thoughts.Hub - Single ISP, MPLS to remote spokes.Spokes - 2 ISP + MPLS to main Hub.Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.Question... is this possible?Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?So, with that out of the way I have the following scenario:Hub1 - Single Internet Connection, Single MPLS connection.Hub2 - Single Internet Connection, Single MPLS connection to Hub1.Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration. Is t
I'm playing with another VDOM setup. This time the Root vdom will hold the primary traffic while a sub vdom will only have an inbound IPSec VPN connection for remote clients to connect too via forticlient. I've got the root vdom setup and it's passing traffic correctly. The VPN terminates at VDOM-A.Here is a network mapI've got a VIP at the root vdom that's passing traffic through to the 10.2.2.2 IP. I've got the firewall rule at root that's allowing traffic inbound to the VIP. In VDOM-A, I've got VPN configured with the 10.2.2.2 interface (the intervdom link) so it should be all setup correctly. The "external" (this is all in a lab, no actual real IPs involved) IP for the IPSec VPN is 40.40.40.35. When I try to connect from a VPN client, the connection just times out and won't connect.If I run a "diagnose sniffer packet any 'host 40.40.40.35'" and run a ping 40.40.40.35 from the VPN client, I see traffic. However, when I actually try to connec
I need some assistance with finishing up getting the FortiTokens working. Newbie at this, so bare with me please. I have loaded all the FortiTokens up, and see them all on the 100F. I have created a RADIUS group in AD and can validate that the 100F is talking to the RADIUS server. When testing, The VPN client (the free version) does prompt the test user but asks for the FortiToken number - does not push the Mobile display 6 digit code. Then it disconnects. I have not done the following yet for the command line: config system ftm-pushset server-ip XXX.XXX.XXX.XXXset status enableend Where XXX.XXX.XXX.XXX is the public IP of our 100F device - correct?Then I would need to contine to doing this:Go to Network > Interfaces.Edit the wan1 interface.Under Administrative Access > IPv4, select FTM.Click OKIs this all I would need to do to get the FortiToken push working? BTW - runn
Hello, I need a working example of setting two firewall shaping-policies to match DSCP EF and AF43 respectively. I don't understand how to use the commands set tos-mask and set tos as explained in CLI ref. for 6.2 (the examples and the documentation is pure crap IMHO). I'm thinking of using set tos-mask 0xc0 and set tos 0xb8 for EF and set tos 0x98. Do you think this is correct or should I use different values? ThanksAndreas
I have inherited a few Fortigates on on network and dont work with them much and need to check the SD WAN side of things.Both have 2 x 1gbps circuits, but the configs are slightly different under SD-Wan.Is there a way to check that they are load balancing over both circuits ?
Firewall_Robot # exec telnet 10.69.73.2 8000Trying 10.69.76.2...Timeout!Failed to connect to specified unit.Console line is in use. Clear it before next try. Can i change the port anybody with solution please send
Hi all,I try to understand how to access Fortiauthenticator via cli for troubleshoot dns resolution.I check via putty the port is open, but I don't have permission to access with full permission user.I need to execute a simple dns lookup and ping to reach push.fortinet.com and ftc.fortinet.com .Thank you Vincenzo
Good morning, After upgrading to Android 15 (phone One Plus 12), the Forticlient VPN stopped working.When I tap connect, like usual,the gray dots start becoming green, but at about 60% they start over and no error is shown. It does the same result even putting wrong credentials, seems that it never reaches the portal.The portal homepage is correctly displayed with a common browser.VPNs (of course) are working for other android/ios/windows devices.Tried varoius version of the client: 7.0.x, 7.2.x 7.4.x all with the same behaviour.Before upgrading android, all worked fine. Some configuration details:Device: One Plus 12 (CPH2581_15.0.0.204(EX01))Client: Forticlient VPN 7.4.1.0176Firewall: Fortigate 100F 7.0.15Portal port: 10433 What I can else do? Thanks
Hi everyone, FortiEMS v7.2.2 build 0879Fortigate v7.0.14 build0601 I encounter a problem when I try to download a PDF file like this exemple : dummy.pdfI did not receive any message about the download.I can bypass using private navigation on firefox I don't know if it is about a plugin, the web filter or other Have someone already face this issue? Thanks in advanceKaci
Hello FAC adminsI'm working on FAC 6.6.2.I noticed that FAC's local LDAP can be used only for local user DB.So far I mainly used it as RADIUS server (Corp LDAP as back-end) in order to add MFA.But now following our new requirement I didn't find a way to use it as LDAP server for accounts that are imported from Corp LDAP.Is it me or this feature is not available?
Hello, Recently, I upgraded all my FortiGates from FortiOS 7.2.6 to 7.4.5. After several weeks with no issues, I took a closer look at my configuration and noticed an unusual increase in IPSec VPN errors. Specifically, the TX error counter on the IPSec VPN interface has been steadily increasing on all FortiGates with a PPPoE WAN interface. stat: rxp=6099751 txp=4612589 rxb=3619539840 txb=1263016689 rxe=0 txe=3928 I thoroughly reviewed my configuration and conducted several tests. While I can replicate the TX errors, they don’t appear to impact traffic or data transfer. Given this, I decided to open a support case. After several weeks of investigation, no specific issues related to FortiOS have been identified. I’ve also attempted to adjust the MTU and TCP-MSS settings in my firewall policies, but these changes haven’t resolved the issue. I already tried to edit these values to lower size but nothing change. Here’s the relevant part of my configuration:conf
Hey Guys ! HELP ME OUT or Drop some suggestions. So I need to convert Azure Firewall config which is is JSON to Fortigate CLI config. What will be the best approach? Or is there any tools out there https://tutuapp.uno/ ? Or I will have to do it manually.
I intend to configure FortiGate such that users are required to re-authenticate every 10 hours, regardless of whether user session are active or inactive. I have applied the following commands, but the session timer seems to refresh instead of decreasing. Could advise if this configuration is correct? config user settingset auth-cert "Fortinet_Factory"set auth-timeout 600set auth-timeout-type hard-timeoutend Remark: i suspect it refreshing because of allow-idle
Can someone please explain why this keeps happening?Here is the AntiSpam Profile: Session Profile:
I am currently using Fortinet's managed rule (version: Main_1.0_20211210) on AWS WAF. I would like to confirm if there have been any updates or changes regarding this rule in November 2024.I understand that this managed rule has expired, but I would appreciate any additional information you can provide.Thank you for your assistance, and I look forward to your response.Best regards,
Can someone explain to me how to show the object installed in the Remote FGT or Local FGT.Example 1Create addressName Local-SubnetIP/Netmask: 192.168.1.0/24Mapped DeviceLocal-FGT 192.168.1.0/28Which IP/netmask is shown on FortiManager for this firewall address object for devices without a Per-Device Mapping set? Example 2Create addressName LocationIP/Netmask: 192.168.1.0/24Mapped DeviceRemote-FGT 172.168.1.0/24Which IP/Netmask will be installed on Remote-FortiGate, for the Local firewall address object?
getting send anyway error when using fortigate captive portal with http port.though it works post clicking on send anyway but I need to understand why I'm getting that aler
I am using FortiClient VPN-only version on macOS Sequoia 15.1.1. I configured the VPN, and during the connection process, I entered my password followed by the dynamic token generated by FortiToken. However, I receive the following error:"Login failed. Permission denied."I have followed the steps in the official documentation (https://docs.fortinet.com/document/forticlient/7.4.1/administration-guide/903183/macos), including:Activating system extensionsEnabling full disk accessEnabling notificationsI restarted my Mac after applying these settings and double-checked that they are correctly configured. Despite this, the error persists.Has anyone else encountered this issue? Are there additional configurations or troubleshooting steps I can try?Btw, The same vpn configuration works fine on Windows 11.
Despite the following, we are still getting a barrage of brute force login attempts on our SSL VPN.- disabled web mode- using non 443 port- edited to the HTML page to hide login fields- created local-in policy to narrow sources, etc- tweaked the login attempt-limit, block-time, and login-timeout I am wondering if forcing the user to present a client certificate would reduce these attempts. In other words, does the enforcement of a client side certificate happen before a username/password attempt is made ? Any other ideas ? Don
I have couple of Linux Desktops(Ubuntu 22.04 LTS and Linux Mint LTS versions) that need to use SSO for internet access and other networks. On Fortigate static ip based rules are used for these Linux desktops. These linux desktops are joined to Windows AD thru "sssd" and domain based user login is enabled. However these systems do not show up in FSSO Agent when logged in with AD user name. FSSO agent mode = DC Agent mode.On AD, the users are in correct OU and Group.Are Linux clients supported on FSSO ?.What are my options to resolve this with other than RSSO or any other Fortinet Products?. Thanks in Advance,
when enter the username and password . this is the error . please help someone
Hi, I search how to do a "show" in the ADOM policy package. Is there a way to do that ? #!proc do_db {package cmd} { puts [exec_ondb "/adom/LAB_LBA/pkg/$package" "$cmd\n" "# "] } do_db "default" " show firewall policy " -> output : DEBUG INFO: TCL command exec_ondb: target = /adom/LAB_LBA/pkg/default # the goal is to show all policy in a policy package.. Thanks in advance for your help ! Lucas
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.