Mark a Best Answer
Fortinet Community
Recently active
Hi, we have a FG200F on our main headquarter and a new office in Brasil with FG60F. We configured a VPN connection between the FGs (IKE V2, AES256-SHA256. AES256-SHA256). Both sides have 1GB internet access (well on the other side we are not so sure but some tests gave us very high bandwith). Now the problem, users from Brasil connect to our office with RDP and sometimes they complain about preformance. So it is not everyday but sometimes they cant even refresh a RDP screen. We have like 195ms latency. Has anyone experience and any ideas what we can do to check and improve? Thanks
I have setup Deep inspection on the FortiGate and the traffic is matching the correct policy.I have taken the pcap on the FGT while the client is accessing the server and from the pcap how we can know the device doing decrypting/encrypting the packet to ensure ssl inspection working properly or not.I want to understand from the packet capture level only.
I'm now on day 2 trying to fix this. This is just such a waste of my time; I'm going to have to scrap the VMs and start again soon. This is what seems to be required every time I need to renew the licence on these. am I hitting a BUG ?Multi VDOM setup in a lab, the LAB has its own NAT and firewall to access the internet.Any out rule. I'm Assuming the VM is using the "root" VDOM for the licencing. LAB-XXX-FW-A (root) # execute ping service.fortiguard.netPING guard.fortinet.net (208.184.237.61): 56 data bytes64 bytes from 208.184.237.61: icmp_seq=0 ttl=43 time=156.5 ms64 bytes from 208.184.237.61: icmp_seq=1 ttl=43 time=156.6 ms^C--- guard.fortinet.net ping statistics ---2 packets transmitted, 2 packets received, 0% packet lossround-trip min/avg/max = 156.5/156.5/156.6 msLAB-XXX-FW-A (root) # endLAB-XXX-FW-A # config globalLAB-XXX-FW-A (global) # execute vm-license XXXXXXXXXXXXXXXXThis operation will reboot the system !Do you want to continue? (y/n)yRequesting FortiCare li
I am having an issue when I transfer a call directly to another extension, after the call is transferred there is a busy tone. The call is successfully transferred, but the phone that did the transfer is getting a busy tone. Can anyone help with that
Hello everyone, I'm writing to ask you something. If you look at Fortigate's Forword Traffic -> deviceSome logs show the device name correctlySome other logs do not display the device name properly.I posted something similar before, but I don't think it worked out well, so I'm writing it again. https://community.fortinet.com/t5/Support-Forum/About-automatically-collected-device-information/td-p/356012 Please let me know what items I should check. And I'm guessing, but I'd like to ask if it's related to the issue that you didn't activate the device detect function. Thank you
Hi, Our WebDevs have been having issues with getting hit with bots, and have determined that the bots never access a certain directory URL. All regular users hit this page with each page they load, I'm told. Is there a method, possibly with user management, to mark a user as valid and allow me to block the rest?Thanks!
hello expertsi have a serious problem with removing an aggregated interface in an almost empty VDOM.recently i take a backup from a VDOM in a fortigate 600c 5.2.8 and restore it on a fortigate600d 5.2.8 and it runs in a company with strict SLA so i can't reboot it even!in this VDOM only there are 2 elements.one: an aggregated interface named "port-agg"two: an interface vlan that is assigned to the aggregation interface, named "Vlan-400".there are no reference to the Vlan-400, but in GUI it shows number 1 in the references column! but when i click on it ... there is nothing !i restored a default factory backup to that VDOM, but the interfaces still are remained.the command "diagnose sys checkused system.interface.name" does not give a proper information.is this a serious BUG in fortigate or it has a plain solution?can i force the fortigate to remove that VDOM whitout removing those fake references? regards.
Fortigate 81FFortiOS 7.0.16 Hi all, I'll see if I can explain this clearly. We have an external DNS A record webserver.com that points to one of our public IP addresses 1.2.3.4. On the Fortigate we have a Virtual IP that points to an FQDN internal DNS A record webserver.internal. webserver.internal has a private IP address 192.168.1.1. On the Fortigate we have a firewall rule that permits access to the Virtual IP on port 443. Internally we have a Windows failover cluster service that can change the IP address of webserver.internal to another private IP on a different subnet 192.168.2.1. Issue: when webserver.internal is pointing to 192.168.1.1 everything works fine. When webserver.internal is pointing to 192.168.2.1, there is no longer any external access. Internal access continues to work fine. After the IP address of webserver.internal changes, this change is successfully reflected on the Fortigate. On the Fortigate if I go to Addresses, the w
hi,can someone confirm if the workflow new "session list" only applies under "policy & object" section in FMG?i don't see the "session list" option under "device manager" section.
core switch working as layer 3 routing per vlans and the two fortigate working as HA A-P i need two know how the connection works the design also , if there more the idea please need to know all possible solutions and if there any topology diagram the clarify the solution
Wildcard FQDN address objects do not instantly resolve the names like non-wildcard objects. Instead, for wildcard objects, the Fortigate watches DNS queries as they pass through the firewall and it sniffs the IP addresses that are returned from DNS servers. The address objects will cache the IP for the length of the DNS TTL and then flush the IP from the address record (though that can be manipulated to a static TTL in the CLI).The problem we see quite frequently is that if devices have DNS servers at a main hub site and check their DNS from the hub across an IPSEC tunnel, the Fortigate does not see that traffic and the address objects are never populated with IP addresses. The Fortigate at the hub site sees the traffic because the DNS server forwards the request to a public DNS server and gets a response, so the hub Fortigate is always up to date. But the branch Fortigates do not see that traffic, I'm assuming because they don't watch IPSEC VPN tunnels to sniff
Hi all, To support my problem description, please see attached diagram below, which is a simplified overview of my network. I am entirely new to Fortinet firewalls. I've always worked with Cisco firewalls but recently the company has decided to move away from Cisco and switch to Fortinet devices. I am setting up a FortiGate 70F on the latest firmware 7.6.2. By default out of the box the Fortinet was configured with WAN1, WAN2 and DMZ ports configured as "Physical Interfaces". Port 1 through 5 were setup in VLAN Switch Mode, with VLAN 0 configured on the default 192.168.1.0/24 network.My office network is on VLAN 70, subnet 10.70.70.0/24.I broke up the VLAN Switch and removed port 2 through 5 from it so that they would turn into physical interfaces again. Only port 1 is still in the VLAN Switch mode. See below: Port 5 is currently my initial admin access port while I configure the firewall (that's why its called "Initial"). Whenever I connect this interface to
Hello, I have more than 10 fortigate firewalls. i use 2-factor authentication in the center. i want to use it in other locations but i need to enter a separate token on my phone for each firewall. how can i do this with a single token without cloud?
Hi, noticed something unexpected today. Internet access for specific host is blocked based on app filter. When checking the UTM blocked rule i see it's actually blocked because of : However, when viewing the APP_FILTER cloud.IT is only set to monitor : Could be blocked on one of the overrides, but i see no further info in the Analyzer logs on which override.Is there any way to debug this further?
FortiGate-VM64-KVM v7.0.10 LAB-SDB-FW-A (mgmt-vdom) # execute ping service.fortiguard.netPING guard.fortinet.net (173.243.138.91): 56 data bytes64 bytes from 173.243.138.91: icmp_seq=0 ttl=43 time=159.2 ms64 bytes from 173.243.138.91: icmp_seq=1 ttl=43 time=158.5 ms LAB-SDB-FW-A (global) # execute vm-license XXXXXXXXXXXXXXXXXXXThis operation will reboot the system !Do you want to continue? (y/n)yRequesting FortiCare license token:XXXXXXXXXXXXXXXXXX proxy:(null)dns resolve errordns resolve error Any help appreciated thank
HiI have VM Forti Analyzer in private cloud.I set automatic backup to public IP behind QNAP nas, specific port etc.FTP worksSFTP doesn't work, have someone ever run this configuration? Thank youMarco
Hi FML adminsOn my new FML 7.6.0 I cant get CLI working from the GUI.Each tim I try run it I get this message:I try Ctrl-C, Enter, right-click, Ctrl-d or whatever but doesn't change anything.Updated to 7.6.1 but the issue still the same.While ssh connection works just fine.Has anyone observed the same issue or found a solution?
I know that you can have like VDOM-A and VDOM-B that both have the same IP space, such as 10.10.0.0/16 when Root is just passing traffic to physical interfaces. However, can you have Root have the same IP space as VDOM-A if all traffic runs through root without having any 'leakage' between VDOMs? For example, you've got 1 port to the internet that all VDOM traffic (including root) runs through and 1 port that all traffic runs too for the VM stack. So all traffic runs through the Root vdom but VDOM-A would share the same IP space without leakage?
Our firewall is like blocking the connection for our printer when doing a scan to email. What policy can i add on our Fortigate 300d for this issue to be resolved...Below is the config our our printer scanner...please see attached image
Hello please how to block this site? <links redacted> <links redacted> <links redacted> or all sites start with * adjaranet * normal ru
Hello everyone,strange issue here: I do have a FortiGate 120G with a bunch of FortiAPs. Since last week, one of our devices (Microsoft Surface) does not work any more on one specific AP.The FortiAP 231F is mounted in our assembly hall. The surface does connect to the Wifi (WPA2 enterprise) but it seems it does not receive an IP adress (dhcp via windows server). The IP get set to 169.254.14.38. If I move to another access point (e.g. the one providing wifi on my desk -> FortiAP 231G) with the same settings and providing the same Wif works without any issues.As soon as I move back to the maintenance hall and the surface connects to the FortiAP 231F networking does not work any more. Windows showing "connected but no connection to internet". Any ideas? All other devices work without problems and the Surface did too until last week (nothing on the Forti configuration changed)
Introduction: Streamlining Software Deployment with AWS Marketplace Image Builder AWS Marketplace has introduced an innovative feature to simplify software deployment for customers and sellers alike: the AWS Marketplace EC2 Image Builder. This feature allows customers to discover, purchase, and deploy third-party software directly through the EC2 Image Builder console and Image Builder APIs. With a straightforward console-driven onboarding process, customers can access security tools, OS hardening scripts, and analytics applications to create optimized, secure, and compliant images—referred to as “golden images”—tailored to their needs. Whether you’re a seller looking to expand reach or a customer seeking a streamlined way to integrate third-party applications, this blog post is for you. In the previous blog post, we described what EC2 Image Builder is at a high level, and how it can alleviate the operational overhead of deploying software such as
Hello, I'm trying to get ZTNA up and running and have the following:EMS and FortiClients running 7.2.4FGT600F running 7.0.14, linked to EMS and 'seeing' the configured ZTNA tags I have successfully set up ZTNA tags and policies on EMS and I can see these on the FortiClients. The clients are showing the tags that I expect. I have a ZTNA profile configured on the EMS as follows (IPs are made up but principle is the same):Destination Host: 10.1.1.1:443 (real IP and port of the server)Proxy Gateway: 111.112.113.114:9443 (external IP and port configured in ZTNA server on 600F) I have configured the ZTNA server on the 600F as follows:External IP: 111.112.113.114External port: 9443Certificate: <valid wildcard cert>Server Mapping: - Type: IPv4 - Service: HTTPS - Virtual Host: Any - Match path by: Substring - Path: / - Server type: IP - Server IP: 10.1.1.1 - Server Port: 443 - Server Status: Active I have a ZTNA ru
Hello, I would like to know how to use FortiAuthenticator to configure saml SSO login for Fortigate administrators, and how to specify a FAC group for Fortigate administrator login
When we configure the fortigate as Active-Active this mean we will have :2 cable from both fortinet to the internet2 cable from both fortinet to the LAN1 cable for heartbeat.Now i want to focus 2 cable from fortinet to the LAN. Should the LAN ip address on the fortigate side have different ip or same ip? If use same ip address, what should we configure on the core switch port? Should 2 ports on the core switch configured as L3 LACP, or should we configure as L3 but using VLAN?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.