Mark a Best Answer
Fortinet Community
Recently active
When i try to connect to vpn through IPSEC IKv2 on specific devices its giving me no response from peer. i tried everything and even opened the specific ports on the firewall and router thought maybe it could block the connection and still the same issue. 
Hi, all. I cannot ping a local interface IP on the Fortigate from a AWS host, connected through a VPN tunnel. I can ping the interface using a dial-up (FortiClient). It goes like this: From PC connected through FortiClient (IP is 10.10.1.2):Pinging 192.168.4.1 with 32 bytes of data:Reply from 192.168.4.1: bytes=32 time=1ms TTL=255Reply from 192.168.4.1: bytes=32 time=1ms TTL=255Reply from 192.168.4.1: bytes=32 time=1ms TTL=255 From linux host in AWS:PING 192.168.4.1 (192.168.4.1) 56(84) bytes of data.(zzzzz)--- 192.168.4.1 ping statistics ---22 packets transmitted, 0 received, 100% packet loss, time 21481ms To a host on the interface subnet, from linux host in AWS:PING 192.168.4.13 (192.168.4.13) 56(84) bytes of data.64 bytes from 192.168.4.13: icmp_seq=1 ttl=127 time=21.1 ms64 bytes from 192.168.4.13: icmp_seq=2 ttl=127 time=21.2 ms On the Fortigate, a trace shows Packet Trace #2004,2024/12/04 08:57:54,"vd-root:0 received a packet(proto=1, 172.31.32.14:53
Hello, i have a problem with my FortiClient 7.2.4 that is connected to a FortiEMS.The clients connect to the EMS with an invitation code but after they go offline and then online again they have to reenter the invitation code again.Is there a reason why a client has to reenter the invitation code and how can i prevent that? Many thanks
Dear forum, I am unable to implement successful SAML authentication using azure entra ID for fortigate/forticlient vpn.Fortigate 200F v7.2.10FortiClient 7.4.0.1658Azure/Entra ID for SAML AuthenticationVPN Phase 1/2 settings working correctly (confirmed with local auth).Any guidance would be greatly appreciated.Logs:Parkside-Core-FW1 # diagnose debug resetParkside-Core-FW1 # diagnose debug application ike -1Debug messages will be on for 30 minutes.Parkside-Core-FW1 # diagnose debug application fnbamd -1Debug messages will be on for 30 minutes.Parkside-Core-FW1 # diagnose debug enableParkside-Core-FW1 # [2579] handle_req-Rcvd auth cache message[132] __saml_auth_cache_push-Auth cache created, user='F23484CE-7E30-4530-8175-C0754B374085', SAML_server='saml-entra-id', vfid=0[139] __saml_auth_cache_push-Hash bucket 157[3438] fsm_initialize-Sent ACCT-ON[2085] fnbamd_cfg_init-[468] fnbamd_add_ca_hash-new ca 'ACCVRAIZ1', subject '/CN=ACCVRAIZ1/OU=PKIACCV/O=ACCV/C=ES', vfid -1[468] fnba
Dear all,Can you please advice me how I can block the auto update of WPS office software in FortiGate firewall ?
HelloAnyone available for urgent support I have fortigate 81e I have config admin login to fortigate using two factor authentication and now when I login to fortigate I don't receive otp I tried to access it over console it also ask for otp that I didn't receive I need urgent support please
Hi all,A stated in subject, my question is about passwordless logins. So we are trying to implement yubikey with PIN + Touch as a primary authentication. Then Fortiauthenticator agent for windows with PIN + Token as a secondary/fallback authentication in case user forgets his yubikey. This two already work without any issues. Now comes the 3rd part :) On top of this we want to implement Always ON VPN with Forticlient and EMS. User should have zero interaction with forticlient. My question here is if this is even possible to do? Thank you for your help
Hi all,We are slowly moving to password-less based login for our users. We have already piloted YubiKeys as our primary method of authentication. As a failsafe we are now testing also FortiAuthenticatior agent for windows since we already have it on-premises. The login with PIN and Token works fine without any issues. What is happening is, that from time to time (once, twice, multiple times per day, or maybe not even happening) login screen starts behaving erratically not displaying login screen at all. In the event logs I can see, that it was caused by crashed LoginUI.exe and Fac_AgentCredentialProvider.dll and ucrtbase.dll. Here is the log:Faulting application name: FAC_Agent.Service.ServiceHost.exe, version: 6.0.0.0, time stamp: 0x66dba094Faulting module name: ntdll.dll, version: 10.0.19041.5007, time stamp: 0x688f8c4bException code: 0xc0000374Fault offset: 0x00000000000ff3c9Faulting process ID: 0x14d4Faulting application start time: 0x01db40bfcd70a7caFaulting application
Hi,We have a really simple rule e.g.Source: private IPsDestination: Some AWS URL objects which resolve the correct IP addresses (confirmed using dns dump from the FW)Service: TCP/443No SSL. No URL filtering. We see the traffic in the logs on the firewall and by all accounts they should be permitted but we see they are being blocked: Threat Action: BlockThreat name: Policy violationThreat severity: MediumThreat type: Reconnaissance When I check the individual threat logs -> Antivirus, Intrusion prevention, Application control, web filter, filer filter, there is nothing in the logs. In addition we removed all UTM profiles to test and still had the same issue with the same threat block. Fortigate 3301E running 7.0.15. Example trace (which doesn't show any block): id=20085 trace_id=594 func=print_pkt_detail line=5867 msg="vd-XXX-PROD:0 received a packet(proto=6, 10.X.X.X.136:53314->3.5.245.179:443) tun_id=0.0.0.0 from portC1.999. flag [S], seq 2081025662
is there any sample of an initial endpoint policy for NAC-F ? I just want to see what a very simple basic initial policy looks like . Assuming this would be some sort of posture check? What is the most common policy type that is being used fort a simple deployment? Thanks,
ok trying to have secure VPN connections for two different type of users. We currently have a Fgate 60F V7.2.1; Windows AD environment; Fclient 7.2.5; EMS on Windows server We can't use the SSL VPN. I have two sets of users 1/ home PCs using the fclient free version; IPSEC VPN (IKE V1) then they RDP to their desktops; only RDP allowed in the firewall policy 2/ work supplied laptops using fclient with EMS; to have full normal access; currently using SSL however we have to move away from SSL. Questions are A: is 1. a silly thing to do. Should we just bite the bullet and buy bad laptops that are locked down to only allow the VPN and nothing else. Can we have a home PC connect securely, only allow them to RDP to their desktop; is this a massive security risk. B: can I have two IPSEC dialups set up on the Fgate? Can anyone share a decent doc that actually explains what all the options do or even better says choose these ones.&nbs
Hi, Can anyone share the link where I can see the EOS / EOL products, right now I need the FortiAP EOS. Thanks
HiI am observing an issue as DNS entry stuck / not refreshed to default for local network adaptor while disconnects the FortiClient IPSec VPN. Following URL is found over the internetFortiClient DNS gets stuck : r/fortinet Resulting, if the user connects another network later, it connects but unable to surfing internet due to wrong DNS entries It is being observed with 10% users only with following firmware combination:FortiGate Firmware Version 7.4.5 build 2702 (Mature)FortiClient Firmware Version 6.0.9.0277 Regards,FAhmad
I'm trying to use two SDWAN zones to browse different services, 1 sdwan - link 1, link 2, link3, link4 2 SDWAN - link5, link6 and link7. However, when I create the default static route for the 2nd sdwan, I start to have navigation problems in the rules that have the 1st sdwan set as the exit link, can you help?
Background on environment.Root vdom contains all the physical interfaces for traffic to the internet and vmware stack. All traffic coming into or flowing out of the VDOMs has to route through Root. Vdom-A and Vdom-B share IP schemes, so everything has to route through the Intervdom network 172.17.17.0/28. Vdom-A has a VPN tunnel to another site. The traffic to establish the VPN flowsInternet > Root Vdom > VIP in Root VDOM that translates the external traffic to 172.17.17.1 (the vdom-a side intervdom link between Root and Vdom-A) > Vdom-A picks up and establishes the VPN tunnel.In my initial test, the VPN establishes and traffic flows so I know I've got that part set up correctly. However, Vdom-A will have a server with a "public IP" (let's call it 40.40.40.40 just for ease of conversation) that should be only accessible through the VPN. I'm having some difficulty in establishing where the private IP (let's call it 10.10.10.40 for ease o
Dear Sirs, please help me with this problem that occurred today. I have 5 users who have not been able to log in to Forticlient on their Windows computers. The VPN reaches 40% and then returns to the credentials stage, without displaying an error message.The same test is performed on another computer within the community and outside the company domain and the user does connect, but doing so from those computers does not succeed.Windows updates have been checked, keeping them up to date, uninstalling the VPN and reinstalling it, connecting to different networks, re-entering passwords in Active Directory and the problem persists on those computers.The laptops are from different brands and are on Windows 11.When validating the logs in the firewall, it shows me user attempts N/A and in the action ssl-exit-error and in Reason N/A.
Hi, I'd like to configure our customer FortiGate running on OS version 7 to get users to our external landing page first, and after they have preformed a task, redirect them back to the local authentication page. How do I do that and is that possible?
How does fortisase spa works and how can we setup
I've come across a strange something I've never seen before in web categorisation. There is a link that Is currently getting blocked on of my FG's. Looking at the logs on the FAZ it was Categorised as Advertising but when looking on FortiGuard's web filter lookup It has the category of business. Creating a simple exemption would get me access to the link but was just wondering why there would be this difference. FG is running on 7.0 could it just be the OS version the FG is on?
Hello, I'm working on a pre-configured Fortigate firewall and seeing too many logs under VPN Events, most of them SSL VPN alerts. I realized these logs are coming from other countries than the intended country. After looking for some solutions to minimize the logs, I came across this "limit access to specific hosts" option. I tried to add my country as the hosts, however, after applying the policy, it doesn't let anyone connect to the VPN. What I'm seeing under VPN logs when a user tries to connect is "Action: tunnel-up - Reason: login successfully", and a few minutes after I'm getting this "Action: tunnel-down - Reason: User requested termination of service". Additionally, on the client side, it app doesn't even ask for a token verification and just drops the connection.I hope someone can let me know the reason for this issue and what I should do next. Secondly, I tried to revert SSL VPN to the way it was and apply the restriction under firewall policies. This time, I was ab
Is it possible to sync the fortigate webfilter with the EMS
Hello,I had the one more unpleasant surprise after upgrading the FortiAnalyzer to 7.4.5: several datasets that worked perfectly in 7.0.x stopped working with strange syntax errors, not being valid anymore. Also other datasets which were ok before, now need SQL code adjustments because hcahe requirements are very strict. Also, apparently only temporary tables are permitted, which is a change that is impossible to understand for me, and I had quite a lot of datasets that prepared tables on disk which were used by subsequent reports refering such persistent tables. No more permitted, but why? This is an example of dataset which is no loger valid. The goal is to drill down into the DNS queries, listing the domains and query counts per each hour interval. DROP table if exists time_intervals;CREATE TEMP TABLE time_intervals ASSELECT generate_series(extract(epoch FROM (now() - interval '7 days'))::bigint,extract(epoch FROM now())::bigint,3600) AS interval_start;select cnt,from_itime
Looking at implementing the process below and we are having a hard time finding specific instructions. 1) Guest user attempts connection to SSID2) User is prompted for email address3) User enters email address4) Email address is sent to system 5) System sends a code to users email6) User is prompted for code7) User enters code to access wifi Any ideas?
Hello, i have an error with connecting to IPSEC vpn IKEV2 using Azure AD email whats happening is after i get the pop up to enter the credenials after i enter and get the 2FA popup it says VPN connection is down and when i check the logs i get this error: i tried turning off the firewall on the device im trying to connect from, i restarted the services, removed and redownloaded the vpn and still nothing is changing
Hey, we have VXLAN between DC and DR sites. We can access through the same subnet, so we can ping or access to the GUI. On the different subnets we can't access to the DR site FW with the HTTPs,PING or something but we can access to the DC site FW GUI or can ping it.For example; We have 10.10.10.0/24 and 10.10.20.0/24 subnets. .1 is the VRIPs, .2 is the DC site FW, .3 is the DR site FW IPs. I can't access 10.10.20.3 from the 10.10.10.0/24 subnet but can access to the 10.10.20.2. When I try to ping and sniff from DR site FW it only gets icmp-requests but doesn't send reply packets. MTU sizes the same on both site. How could we solve that?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.