Mark a Best Answer
Fortinet Community
Recently active
Hi, We work with FortiClient VPN 7.4.0.1658 with one predefined SSL-VPN Gateway to an external Partner (User and Password, no Client Certificate, Port 18443) on Windows Server 2016 VMWare ESXi.The connection is established after confirming the "Server Certificate Warning" for FGVM2VTM23001833 fortinet-subca2001. After updating FortiClient VPN to 7.4.1.1736 the "Server Certificate Warning" is no longer prompting and no connection possible. On a reference client outside my company network it works.Exporting the certificate there and importing it on the Server does'nt change.After downgrading FortiClient VPN to the previous version on the Server the connection works fine again. Any idea ? Thanks,Roland
I noticed that on FortiProxy, the VM platform version is displayed as FortProxy-VM64. However, when I check the Firmware Download images, I don't see any image labeled VM64; I only see a VMware image. My question is: Is the VMware image the same as the VM64 image? For FortiGate, I see separate images, but for FortiProxy, there is no specific VM64 image.Can you please advise if the VM64 image displayed is the same as the VMware image available in the Downloads section on support.fortinet.com?
Hello, I was wondering if anyone could clarify what the different interfaces displayed with the command "diagnose netlink interface list" actually mean when used on a fortiswitch operating in standalone mode. I did not see the command listed in the official CLI documentation for Fortiswitch running 7.2.7 firmware. The device I'm testing this on is a Fortiswitch Rugged 112D-PoE running firmware 7.2.8 . Here's a snippet of the command output, 112D-PoESW1 # diagnose netlink interface listif=lo family=00 type=772 index=1 mtu=16436 link=0 master=0flags=up loopback runif=mux0 family=00 type=1 index=2 mtu=1500 link=0 master=0flags=broadcast multicastif=p0 family=00 type=1 index=3 mtu=1500 link=0 master=0flags=up broadcast run promsic multicastif=sp1 family=00 type=1 index=4 mtu=1500 link=0 master=0flags=up broadcast runif=__port__1 family=00 type=1 index=1001 mtu=1500 link=0 master=0flags=up broadcast run multicastif=p1 family=00 type=1 index=5 mtu=1500 lin
The detailed information is: You are not allowed to access this resource because the SAML request from your service provider (https://192.168.199.60:10443) has expired. Please try to access your service provider page again.
Hello dear community,A brief introduction since I’m new here.I am an IT employee at a company, and over the years, we have been using a Sophos firewall. However, we are now switching all our branch offices to Fortinet.I also successfully completed the FortiGate Administrator training at the beginning of this transition.We started with our smallest branch and implemented the simplest rule set. So far, everything seems to work well—we have configured an IPsec VPN connection to our headquarters. At the headquarters, we still have a Sophos UTM 230 SG running. The VPN tunnel is established, and the ping is clean and fast at approximately 30 ms with a TTL of 254.Our issue is that accessing the web interface over the VPN tunnel is nearly impossible. The login still works, but then a white page appears. If you’re lucky, content might load after a while. However, if you click on a menu item, the web interface freezes again.At the branch office, we have a FortiGate 60F. The system load is low.Wh
hello teamWe are initiating a new project to deploy FortiSandbox, and we have a few questions regarding its operation and features. Could you kindly provide insights on the following:How does FortiSandbox operate to achieve real-time blocking of malicious files?What is FortiSandbox's approach to threat protection?Could you explain the key malware detection components included in FortiSandbox?How does the blocking policy function?What is the estimated time for a client's request containing files to go through FortiSandbox's full scanning process and reach the backend server?Looking forward to your guidance.
HelloToday I have FortiAuthenticator when we connect to the Wifi it asks for username and password both on the cell phone, when the user leaves the room and goes to connect again to the Wifi it comes again asking for username and password, would there be any way to put or period or time to wait for this?
I need to connect a Forti AP through a Dell switch I have 2 x fortiswitches with several working AP's, 2x SSID's all fine. I setup a physical port which connects my Dell switch to my Edge switch stack and the fortiAP is online and given the correct DHCP address i setup. But I cannot get DHCP to work on the SSID's of this AP. Do i need to recreate VLANS? as I tried this and nobody could connect on any AP and was giving random 169.xxx addressed. When i try and connect to either SSID on the not working AP - i get a 169 address. I need it to see the VLANS on the fortlink - but dont know how to do this or if it can? thats why i think i need to recreate them? Thanks
We are trying to create a rule in FortiSIEM to detect the absence of a specific type of log being received from a device. For example, if a log source is configured to send PING, Sysmon, and Syslog logs to FortiSIEM, we need to create a rule that triggers an alert only when Syslog logs are missing from that device, even though other log types (e.g., PING, Sysmon) may still be received.The default "No logs from a device" rule in FortiSIEM triggers alerts if all logs stop coming from the device, which does not meet our requirement to monitor the absence of a specific log type.Has anyone implemented a rule or workaround to address this scenario? Any guidance or suggestions would be greatly appreciated!
Hello,we have, from many years, a WiFi infrastructure composed from two FortiWLC-50D configured in Cluster Mode with nplus1 mode.From last few months we have issue with Zebra Android RF Terminals, that show a popup when connected to AP: limited connectionAlso if the Terminal is under the AP, we have many connection issue, or the connection falls out or the telnet application gets stuck.Firmware version of our Controller and APs are 8.1-3-2.I've tried to reboot the controller but didn't solve.Any suggestion, please?
hi Peeps please help Fortimanager vm and fortigate vm version : 7.0.1 I just installed the two vms and linked them but when I tried to install the policy, it keeps failing with "Input is not a valid CA certificate" I deleted the root_ca2 from the CLI configuration, under device manager, but when I try to install policy again it tries again to install the CA and it fails and when I check if the CA was really deleted or not I found that it has reappeared. I did not find CLI configuration under Policy&package to uninstall the CA from there too. please help
Hello, I have Fortinet 60 F device. An error showed up while trying to connect via SSLVpn that too many bad login attempts.-455 . When I check firewall failed authentication parts I saw that there are a lot of attempts to login. I am adding the screenshot. What can I do as an emergency solution? Thanks in advance.
Hi,My Apple device running iOS 15.6.1 is failing to connect to FortiClient VPN. In Android and Windows OS, the FortiClient VPN connection is normal.IOS 15.6.1 ( FortiClient 7.4.2.0151) – Not work * No popup for enter the username and passwordIOS 18.1 ( FortiClient 7.4.2.0151) - OK Does anyone know if there is any compatibility issue between FortiClient 7.4.2.0151 and devices running iOS 15.6.1? Remark: The related FortiGate firewall is running v7.2.5.
Hi there, having an issue getting to certain websites. Profile is very simple... lan-wan, all, all, always, nat enabled, only security profile is ssl "certificate-inspection". No content filtering, dns, antivirus, ips etc. Regardless of the browser, we get your connection is not private. NET::ERR_CERT_COMMON_NAME_INVALID. Try to import the fortinet certs into the trusted root authority but error still persists. Tried both flow and proxy based inspection. Any thoughts?
Hi, I just want to know this in generic, I know it depends on environment of each network But is there a top recommended FGT firmware version that would be stable.in My environment we are upgrading to 7.0.16
I have four standalone switch 1048E. I am in the process of implementing to new fortigates. I am having an issue where the switch isnt passing the vlan accross to the uplink port. This is the HA port for the Fortigate pair. I have packet captured off both the inbound and Uplink port. I can see the fortigate is sending the HA packets to the port but nothing appears to be getting to the uplink port. I have reviewed the config to ensure that the vlan is set to allow on that trunk. So my question is that has anyone seen this on Fortiswitches and if so what can I do to fix it. I have had an open support ticket for months and no resolution so hoping the community can help me out. Thanks ahead time.
When we add credentials in FortiSIEM admin settings, it only asks to map IP.Same IP can belong to multiple clients also, But in mapping there is no option to select collector. So how to map credentials to correct device linked to correct collector. Also do i need to allow supervisor to firewall port 22 if i want to add SSH credentials? This is not possible by allowing collector to firewall connection over port 22?
Hello,I am experiencing an issue with the dot1x configuration on FortiNAC.I am using FortiNAC 700F, version 7.2.8.0149. I have followed all the steps shown in this video:https://www.youtube.com/watch?v=7pRg2-SVipoThe problem is that I don’t have the "EAP-Type-Name" option.I still followed the entire video and applied the instructions, but when I connect a PC to the switch port where dot1x auto-registration is enabled, the PC shows "authentication failed." On the FortiNAC side, I don’t see any activity logs. Here is the switch configuration: interface GigabitEthernet0/17switchport access vlan 2switchport mode accessswitchport voice vlan 150srr-queue bandwidth share 1 30 35 5priority-queue outauthentication host-mode multi-hostauthentication port-control autoauthentication periodicauthentication timer reauthenticate 180mabsnmp trap mac-notification change addedsnmp trap mac-notification change removedmls qos trust device cisco-phonemls qos trust cosdot1x pae authentic
Hi, im having an issue with my FortiEMS as it says that my license is about to expire but i already renewed it.I already tried the function "Sync License now" on the Dashboard but it didn't help.Is there any other way to get the EMS to read the new license?Im using FortiEMS 7.2.4Thanks
Hi Team,We have a requirement to setup alerting from Fortimanager and the alerting should be pushed to ticketing tool to create the ticket.We have multiple Fortigate SDWAN devices are being managed from Fortimanager. Can we aceive the below?> FortiManager to pull all the devices CPU, Memory, Interface utilizations and all the SNMP traps.> Can we set the thresholds for each of the traps and system resources.> Fortimanager to trigger an alert to SNOW when it hits the threshold.Is it acheivable?Can all the devcies be monitored from Fortimanager at all?Do we need to setup each device or can we setup the thresold or any monitoring config from Fortimanager and push it to the devices, kind of centralized management?Any suggestion or guidance will really help.Regards,Sanjay S
Good day. Simple issue: I want to use SDN connectors with an onpremise FW (physical, not cloud). But for PCI compliance, I need to rotate the access keys periodically. Has anyone encounter a situation to make an automation between the cloud and the firewall, so the firewall pulls the new access keys and installs them into itself? Can it be done using a Lambda or API? (let it be AWS or Fortinet) I have the feeling that it can be done using the Fortigate API, so I can call it from AWS and pass the new access keys, but wanted to be sure. Thank you. #Fortigate
Dear Team,We hope this email finds you well.We are currently working on a task to delete a specific ADOM from our FortiManager, which contains templates and policy package databases. Before proceeding with the deletion, we need to take a backup of this particular ADOM.However, we have reviewed the documentation available to us and could not find any information related to taking a separate backup for an individual ADOM.Could you please confirm if it is possible to take a backup of a single ADOM? If yes, kindly guide us on the procedure and share the relevant documentation or steps that we can follow.We would appreciate it if you could provide this information at the earliest, as the customer is urgently requesting this action. Thanks,Nithishkumar S
We have a Third Party that would like to allow us access to a subnet on their system via a Site to Site VPN. There is no need for them to access stuff on our network but they want us to use a small subnet to avoid clashes on their end of the network ( 192.168.255.1 / 24 as an example ) we have set this subnet up as a Vlan and have setup and established a IPSEC Tunnel and the tunnel works if your on aforementioned subnet. Is there anyway to get a Fortigate FG100 to route traffic from another subnet over this tunnel? I can't create a static or policy route to route traffic to the gateway address 192.168.255.1 as it just complains it's a interface address (well yes )) Essentially we want it to take traffic from our vlan(s) and act as a NAT gateway sending stuff over the VPN. In the past we have done this by having another router take traffic out of the main router and pipe it back in via a WAN port. This is a little Jank though and I was hoping for something a bi
When i try to connect to vpn through IPSEC IKv2 on specific devices its giving me no response from peer. i tried everything and even opened the specific ports on the firewall and router thought maybe it could block the connection and still the same issue. 
Hi, all. I cannot ping a local interface IP on the Fortigate from a AWS host, connected through a VPN tunnel. I can ping the interface using a dial-up (FortiClient). It goes like this: From PC connected through FortiClient (IP is 10.10.1.2):Pinging 192.168.4.1 with 32 bytes of data:Reply from 192.168.4.1: bytes=32 time=1ms TTL=255Reply from 192.168.4.1: bytes=32 time=1ms TTL=255Reply from 192.168.4.1: bytes=32 time=1ms TTL=255 From linux host in AWS:PING 192.168.4.1 (192.168.4.1) 56(84) bytes of data.(zzzzz)--- 192.168.4.1 ping statistics ---22 packets transmitted, 0 received, 100% packet loss, time 21481ms To a host on the interface subnet, from linux host in AWS:PING 192.168.4.13 (192.168.4.13) 56(84) bytes of data.64 bytes from 192.168.4.13: icmp_seq=1 ttl=127 time=21.1 ms64 bytes from 192.168.4.13: icmp_seq=2 ttl=127 time=21.2 ms On the Fortigate, a trace shows Packet Trace #2004,2024/12/04 08:57:54,"vd-root:0 received a packet(proto=1, 172.31.32.14:53
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.