Mark a Best Answer
Fortinet Community
Recently active
When we configure the fortigate as Active-Active this mean we will have :2 cable from both fortinet to the internet2 cable from both fortinet to the LAN1 cable for heartbeat.Now i want to focus 2 cable from fortinet to the LAN. Should the LAN ip address on the fortigate side have different ip or same ip? If use same ip address, what should we configure on the core switch port? Should 2 ports on the core switch configured as L3 LACP, or should we configure as L3 but using VLAN?
Hello,The problem concerns the vpn.certificate.local object on devices in the HA A-P cluster based on FortiOS 7.2.10. The object is not synchronized in the cluster, which causes out of sync. What was done? 1. Manual recalculation and re-execution of synchronization on both devices does not bring results. 2. Restarting the devices on both sides does not bring results. 3. Disconnecting the cluster, hard resetting the secondary device, editing the configuration downloaded from the primary device and uploading the configuration to the secondary device so that the configurations are identical 1:1 and reconnecting the cluster, also does not bring results 4. Using the technical tip from the link below was done and also does not bring results:https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-HA-out-of-sync-issue-due-to-vpn-certificate/ta-p/192198 All of the above methods help only for 3 minutes, then the same object stops being synchronized aga
Hi, I am currently configuring SNMP and would want to see how the actual result/output looks like for these OIDs:OID: 1.3.6.1.4.1.12356.101.2.0.402OID: 1.3.6.1.4.1.12356.101.2.0.401Ref: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setup-FortiGate-HA-failover-alert-on-SNMP-managers/ta-p/216711 I need to configure an email alert to myself once the trap has been triggered. Thank you!
Hi guys, I am running a HA-AP cluster of two FortADC nodes (7.4.5) on a Vmware Cluster (Version 8). The NIC configuration for all VLANs allows promiscuous mode, MAC address change and forged MACs. I have these interfaces configured: port1 - Managementport2 - [ empty - no VLAN]port3 - LANport4 - Heartbeat/Data Portport5 - DMZ2 When switching between nodes (reboot the active machine) the IP on port 5 was no longer pingable on the second FortiADC. I rebooted again and got answers from port5. I was able to ping the LAN-IP on port3 and the heartbeat also worked !! Then I checked the interfaces in vsphere client and port 1 to port4 look like this: Active Maschine: Port unblocked, Mac is 00:09:0f:... (the virtual MAC)Passive Maschine: Port unblocked: Mac is 00:50:56 (the "physical" MAC) When the cluster nodes are switched the virtual MAC switches to the then active node. But in the VLAN DMZ2 (assigned to port5) the ports look
Hi,I've been recently looking into Fortinet's GuardDuty integration with AWShttps://github.com/fortinet/aws-lambda-guardduty However it looks as if the lambda function is using a version of nodejs no longer supported by AWShttps://github.com/fortinet/aws-lambda-guardduty/issues/18 nodejs16 went end of life at around July this yearhttps://aws.amazon.com/blogs/developer/announcing-the-end-of-support-for-node-js-16-x-in-the-aws-sdk-for-javascript-v3/According to the latest 7.6.0 docs it's still listed as working thoughhttps://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/aws-administration-guide/585081/creating-the-lambda-functionhttps://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/63a2a759-3f9b-11ef-bfe5-fa163e15d75b/FortiOS_7.6_AWS_Administration_Guide.pdf Last update was around 5 years ago in the repo, do you have any ideas on how to get this working?If it needs redoing it might be an idea to do it in python instead due to the rapid changes nod
Hello Fortinet Community, I have a network environment consisting of a FortiGate , Windows Active Directory 2019, Huawei iMaster NAC, and a newly purchased FortiAuthenticator . Both the FortiGate firewall and Huawei NAC are configured to authenticate users from Windows Active Directory using LDAP.Here’s the current workflow: When a user device connects to a switchport, the iMaster NAC detects the user and identifies their organizational unit (OU) (e.g., HR, Technical, etc.).Based on the detected OU, the switch assigns an IP address to the user from the corresponding VLAN (e.g., VLAN 10 for HR, VLAN 20 for Technical).After successful NAC authentication, the FortiGate firewall presents a captive portal when the user attempts to access the internet or DMZ. Upon successful authentication via the firewall portal, the appropriate policies are applied based on the user.The issue arises because users are required to enter their credentials twice: once for NAC auth
Hi, a previous employer install Forticlient on my mac. I now do not have the password or the ability to make changes to the password. Can someone help me with the process of completing a password reset in order to uninstall? Thanks, Sam
Dear Community, every few years we replace our FortiGates with the most recent ones. Now we have some devices left over that we don't need anymore. What shall we do with it? As they are still working fine I don't want to trash them.Of course the subscription ran out... Any one interested in buying them? I am talking about:4x 200D3x 300D3x 60D Best wishes from Berlin,Scorpion
Hi EMS/FGT adminsWhen creating ZTNA proxy rule (in Policy & Object > Proxy Policy) for clients that are off-fabric, is there anything valid that we can put in "Source" field other than "all"?Trying to put the public source address of the client, or even the client's private source address behind its router, but nothing seem to match, only "all" works. It seems srcaddr in ZTNA proxy rules means something different than in standard rules, but can't find what.Any idea?
Hi, How can I integrate Radius authentication in Fortinac to validate credentials via LDAP in an AD? We don't have NPS, so I need, if possible, that Fortinac validate the user and pass directly. It's possible? Thanks
Need to upgrade Forticlient EPM from 7.2.4 to at least 7.2.6 If I do this - will this disconnect all my users from the Forticlient VPN?If so - will they all need to be upgraded before they can reconnect? Thanks
hi,i just created a new VDOM in FMG and installed/pushed to a newly added FG but i can't see the new VDOM.i only see the 2x VDOM that i initially created locally in FG before i onboard it to FMG.tried to logout/login in FMG but still the same. i can see the new VDOM locally in FG.is do i need to add/apply the FMG-VM-10-UG license in FMG to see the new VDOM?
I've been testing the Forticlient EMS and have recently upgraded to version 7.2.6 on Windows.Since doing so I can no longer quarantine hosts. the option simply isn't there under 'Action'.I've tried using multiple hosts (laptop/PC/VM) etc. And I've even installed EMS on two different servers. Everything else works fine. Scans, filtering etc. It just will not give me the option to quarantine a host like it used to.I've made sure application firewall is enabled but still no luck. Running out of ideas as to what else could be causing the option to quarantine to be removed. thanks
When connecting the Fortigate to the Cisco switch, I noticed that the LAG port on the Fortigate is consistently down.Do you know how to resolve this issue? Thank you.Below are the Fortigate detailsconfig system interfaceedit "to-Cisco"set vdom "root"set ip 192.168.192.2 255.255.255.0set allowaccess ping fabricset type aggregateset member "port5" "port6"set device-identification enableset device-user-identification disableset role lanset snmp-index 12nextenddiag netlink aggregate listList of 802.3ad link aggregation interfaces:1 name fortilink status down algorithm L4 lacp-mode active2 name to-Cisco status down algorithm L4 lacp-mode activediag netlink interface list to-Ciscoif=to-Cisco family=00 type=1 index=19 mtu=1500 link=0 master=0ref=21 state=start present no_carrier fw_flags=8800 flags=up broadcast master multicastQdisc=noqueue hw_addr=00:15:5d:bd:9a:08 broadcast_addr=ff:ff:ff:ff:ff:ffstat: rxp=92092 txp=5264 rxb=24443268 txb=635935 rxe=0 txe=0 rxd=0 txd=0 mc=92092 collision=0 @
helloI need to restrict IPSEC VPN I need to connect only from UAE if anyone try to connect from outside UAE he ca notthanks
SAML based SSO VPN is not working
I have setup fortinet DPI but im getting untrusted cert error
How can I setup SWG on fortisase
helloI need to restrict Any Desk Or TeamViewerI need to connect only from UAE if anyone try to connect from outside UAE he can notthanks
Hi, When is not possible to have an Windows NPS for corporate VLAN authentication, Winbind can be a good solution? Thanks. Regards
We currently use Geoblocking to block access to external web servers from "unfriendly countries." This works quite well. However, we still receive a lot of malicious attacks from IPs from "friendly countries." The majority of these IPs originate from private VPN providers. Is there a way to block access from these IPs? Thanks.
When registering with zero trust fabric. I enter the invitation code and I receive the Error:FCT version is not supported.Client works on OSX and IOS with the same Invitation code.forticlient version 7.4.1.1736 help.
Hi Guys, I am using Fortigate SFP module on Fortigate firewall & using brocade & extreme SFP module on switch. but the port is not coming up. Is there any compatibility issue with extreme & brocade SFP module ? Attached are the snapshots.Fortigate SFP ModuleExtreme & Brocade SFP Module
Hello, In Fortinac I´m trying to add an Fortinet Fabric. I already added the Fortigate, but to add the fortiswitches do I need to have an valid Fortilink subnet (exemple 192.168.10.X)? I need to configure SNMP in the fortiswitch too? Thanks in advance
Can anyone else verify that Apple iOS 18.2 breaks the Forticlient IPSec and SSL VPN? Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.