Mark a Best Answer
Fortinet Community
Recently active
Hi everyone,I want to evaluate an internet availability connection from ISP for a period of time, but I have already checked in my FortiGate, I don't see where I can check the uptime of an uplink, it means since the system is up, how many hours the internet has been available, taking into account the time of interruptions and times out.I have only seen where I can see the system uptime, which shows the time my device has been up since it was turned on.
Hi, I'm getting an SSL certificate warning when using FortiClient VPN on 1 of my Linux machines but not on 2 other Linux machines. Why does this only happen on 1 machine and not on the others? I've tested this on 3 machines, and only 1 of them has this problem (openSUSE). Context: - There are no certificate warnings at all if we visit the SSL endpoint in the browser, or when we run 'sslscan' or 'testssl.sh' on the SSL endpoint: vpn.ourdomain.tld:10443All good here. - All 3 machines are running the same FortiClient version: 7.2.2 (build 7.2.2.0753) - libssl versions on the 3 machines:Debian: 3.0.11Fedora: 3.0.8openSUSE: 3.1.4 - All 3 machines are using the same DNS server, same DHCP, same internet connection. - The cryptographic policies are set to DEFAULT. - To make FortiClient usable at all on openSUSE, I temporarily(!) disabled AppArmor. That allows me to establish a successful VPN connection, although I see the certificate warning shown in the
Client laptop has a cert issued by Microsoft AD (via Intune) the Trusted CA has been imported to the FAC 6.6.0 as per this video:EAP-TLS Authentication with FortiAuthenticator | Identity and Access ManagementThe fortigate is set to use the FAC / WPA2 Enterprise as per the instructions, everything is configured as per the fortinet website, but nothing gets sent to the FAC (other traffic using SSL VPN is fine, so its not a connection issue) Running debugs and logs on both the FAC and the Gate, the EAP-TLS request is not even reaching the FAC, Fortigate logs show:2024-11-06 15:09:28 05768.944 70:32:17:11:01:7a <eh> IEEE 802.1X (EAPOL 14B) ==> 70:32:17:11:01:7a ws (0-10.16.152.100:5246) rId 0 wId 1 38:c0:ea:a0:d0:81 2024-11-06 15:09:28 05768.974 70:32:17:11:01:7a <eh> IEEE 802.1X (EAPOL 5B) <== 70:32:17:11:01:7a ws (0-10.16.152.100:5246) rId 0 wId 1 38:c0:ea:a0:d0:81 2024-11-06 15:09:28 05768.974 70:32:17:11:01:7a <eh> recv IEEE 802.1X ver=1 type=1 (
I'm facing issue while using 2fa fac agent for wins loginthe fac agent login portal itself is not getting trigger and getting bypass with admin login
How to add existing Azure Virtual networks to the firewall? I about ten vnets and i want to add into the firewall, but I am not seeing how to do this.
Hi,We have noticed that our domain, highstreetpharma.org, is blacklisted by fortinet as reported on securityscan.getastra.com. After conducting a thorough review of our files and database, we did not find any malicious content on our website.
Hi,on CLI console I want check interfaces configuration without success.admin@fortinac:~> show system interface-bash: show: command not foundadmin@fortinac:~> execute show system interface-bash: execute: command not foundI try also with root user without success.With command get the result is the same.Fortinac appliance is a virtual machine.Could you help me? Thanks
We have Fortinet firewall 200FCan we increase socket connection timeout for specific clients OR for specific firewall rule ?
Hello everyone,I recently discovered that the FortiAuthenticator supports a proxy authentication mode for remote RADIUS servers:FortiAuthenticator DocumentationHowever, the FortiGate does not seem to offer a similar option:FortiGate 7.4.5 Documentation (our current version)FortiGate 7.6.1 Documentation (latest version)If you want to set up remote Dial-Up IPsec VPN tunnels using EAP-TLS authentication via Microsoft NPS (RADIUS), it seems you would need to purchase a FortiAuthenticator solely to forward the requests to the remote RADIUS server.Will FortiGate ever introduce a proxy mode for authentication via remote RADIUS servers?
Hi Team, I have output as DestIP = ['1.1.1.','1.1.1.2'] and I want to update this in a text file of server which i have integrated using SSH connector, while trying to update it is getting updated as it is ['1.1.1.','1.1.1.2'] but I want to update these mutiple IPs in text file of server in a vertical format without any brackets and commas. For example, refer below: Is there any utility to change the format like this ? 1.1.1.11.1.1.2 Regards,Shashank
Hi all,I've a FG-1800F that I've upgraded to 7.0.16.SSLVPN tunnel mode works well, but SSLVPN web mode have a problem when i try to connect using http/https or other protocols.It shows the message "SSL VPN Proxy Error. Reason: Access Denied".I state that firewall policies are correctly configured so much so that I can navigate via tunnel without problems.By debbuging I see the ouptut below:[5530:root:56b2]deconstruct_session_id:709 decode session id ok, user=[testuser], group=[VPN],authserver=[LDAP],portal=[fullaccess],host[x.x.x.x],realm=[],csrf_token=[BF28A52BF8CD26D67351B134F895BF9],idx=4,auth=16,sid=3e129ec9,login=1732875556,access=1732875556,saml_logout_url=no,pip=no,grp_info=[FP00ys],rmt_grp_info=[pSVTnq][5530:root:56b2]dns_query():296 tried IPv4 0 www.google.com[5530:root:56b2]dns_on_read():178 got result[5530:root:56b2]sslvpn_policy_match:2641 checking web session[5530:root:56b2]remote_ip=[x.x.x.x], user=[testuser], iif=34, auth=16, dsthost=[www.google.com], portal=[full-
Hi, I have 3 internet links:Broadband 250/250 Mbps PPPoECorporate 1000/500 Mbps Static IPMPLS 10/10 Mbps Static IPThe issue you're facing is that you cannot access the AGO website or the site is very slow, but you can access Google, YouTube, and social media normally.How can you fix this issue? And how should you configure the SD-WAN link?FG100F Firmware : v6.2.3 build6188
Some of our Fortigates are located behind other firewalls and the only way for those Fortigates to reach the Internet is via a web proxy. We were able to configure Fortiguard to use the web proxy to reach FDN to pull AV,IPS etc auto updates. Is there a way to configure threat feeds to use a web proxy too? If the answer is yes, how is this configured?
All of a sudden I can't login to my 40F device in our Forticloud instance...the appliance is up and I can connect to it via VPN, but for some reason when I try to connect to remote management via Forticloud I just get a blank screen. No config changes were made....anyone else seeing this?
When i go to the download page, and trying to download the windows version of VPN only, but can not access to the page. At the end this message showed out : Fatal error: Uncaught PDOException: SQLSTATE[08004] [1040] Too many connections in /var/www/html/src/Core/Database/DBAL/Database.php:22 Stack trace: #0 /var/www/html/src/Core/Database/DBAL/Database.php(22): PDO->__construct('mysql:host=mysq...', 'v-kubernetes-my...', 'HZKn0qIwHWdALJ8...') #1 /var/www/html/src/Core/Database/DBAL/Database.php(41): Core\Database\DBAL\Database->connect() #2 /var/www/html/src/bootstrap.php(11): Core\Database\DBAL\Database::Get() #3 /var/www/html/public/index.php(7): require_once('/var/www/html/s...') #4 {main} thrown in /var/www/html/src/Core/Database/DBAL/Database.php on line 22
Hello,I am trying to set up automatic failover wan using link-monitor and not SDWAN. Before I even get as far setting up the link-monitor I am running into an issue. My primary is wan2 and backup is wan1. I have tried setting the static route for the backup to a higher priority and/or distance value. When they are both connected it uses wan2 (what I want) then if I unplug wan2 it switches to wan1 (also good), but when plug wan2 back in it still uses wan1. Shouldn't it switch right back to wan2? I think I must be using the distance and or priority incorrectly.wan1 and wan2 are in a zone and my internet access policy uses the zone.  
hi,is the FG dashboard > network > ipsec view for "incoming" and "outgoing" data an "incremental" value over time, i.e. from the time ipsec VPN tunnel was built up to current date?how to view "real time" ipsec VPN traffic in GUI?
We have a small set-up, 1 Fortigate and 7 Fortiswitches. We have the same VLANs going to different switches and on some we have multiple VLANs. I have a couple of questions for things I don't quite understand. Does VLAN traffic carry over the fortilink port exclusively? My tagged VLAN port from the switch doesn't seem to be carrying much traffic. With our limited number of switches and a lot of free ports on our firewall, we want to run a cable for each VLAN for every switch. What is the best way to do this? I was going to do an aggregate connection but I am wondering if there is a better way. Thanks.
Hi everyone,I noticed FortiDeceptor supports integration with Cuckoo Sandbox, but given that Cuckoo is no longer maintained, I have a few questions:Is anyone actively using Cuckoo (or forks like Cuckoo3) with FortiDeceptor?For those who are, what does your environment look like? What security measures have you implemented to safeguard an unmaintained Cuckoo server?Are there users here leveraging other sandboxing alternatives instead?Has Fortinet issued any official statements about continuing to support Cuckoo integrations or recommendations for alternatives?Looking forward to hearing how others are approaching this. Thanks!
Hello,I am currently dealing with an issue related to the FSSO feature, which helps us manage rules on Fortigate. We are experiencing a situation where a user is not authenticated via FSSO when they switch from a wired connection to Wi-Fi. After this change of adapter, the user receives a new IP address and FSSO does not authorize them immediately. We also have a feature enabled that should detect IP address changes, but either it works with significant delay or not at all.Could someone advise me on how you handle FSSO during a change in the connection method? We would like to continue using rules for selected users. Best regards and thank you,Jan
Hello, We have an issue with configuring and using ZTNA tag for filtering internal traffic.We would like to base our config on following example:https://docs.fortinet.com/document/fortigate/7.0.0/new-features/477578/ztna-ip-mac-filtering-examplebut we would like to use it with many Fabric firewalls not just one (as it is shown in the example). Here is our setup:1) EMS server (7.2.6) assigns ZTNA tag - it works OK2) Forti manager (7.2.8) synchronizes ZTNA config to all our firewalls (7.2.9) - it works OK3) We configure internal traffic rules using ZTNA tag as source criteria. Unfortunately, we discovered that above config works properly only within one firewall. That is because ZTNA tag is mapped ONLY to local IP addresses on the firewall.Thus if we want to use ZTNA tag globally as a source criteria, it doesn't work (because particular firewall maps ZTNA tag to only local IPs and doesn't know anything about remote source IPs for that tag). Question:Is there a way to
My Apple device running iOS 15.6.1 is failing to connect to FortiClient VPN IOS 15.6.1 (FortiClient 7.4.2.0151) – Not work * No popup for enter the username and passwordIOS 18.1 (FortiClient 7.4.2.0151) - OK Does anyone know if there is any compatibility issue between FortiClient 7.4.2.0151 and devices running iOS 15.6.1?
Hi Fortigate experts,we need your kind help. End customer needs a DRP for some of their on-premise business critical applications.We are proposing AWS for the DRP environment .We are proposing Fortigate to protect some internet exposed services and also to enable VPN Clients to connect to the AWS DRP environment.The AWS DRP environment (and therefore the Fortigate) is only needed when DRP is declared by the IT department (1 or 2 times per year for around 24hrs each time). Is it possible to avoid being charged the Fortigate prices when DRP environment is not needed?, for example, "turning off" or "disabling" the Fortigate when it is not needed and "turning it on" only when needed ( or 2 times per year) without losing configurations?Thanks
Hi I am currently using Fortinet V7.4.4 and recently encountered an issue where users connected to the WiFi1 network were unable to browse the web. However, there were no issues with web browsing when connected to the WiFi2 network.After comparing the configurations of both WiFi networks, I noticed that the DNS filter was enabled on WiFi1. Disabling the DNS filter resolved the issue.We haven’t made any configuration changes, so I’m curious—why would the DNS filter block web browsing?
Hi,please refer to the screenshots - why is the FortiGate blocking legit HTTPS and HTTP traffic? The policy and the corresponding SDWAN rule should alllow everything. It just doesn't make any sense and the provided article is not helpful at all.https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Threat-131072-is-seen-in-logs-when-traffic/ta-p/192533
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.