Mark a Best Answer
Fortinet Community
Recently active
Hi Team, I have output as DestIP = ['1.1.1.','1.1.1.2'] and I want to update this in a text file of server which i have integrated using SSH connector, while trying to update it is getting updated as it is ['1.1.1.','1.1.1.2'] but I want to update these mutiple IPs in text file of server in a vertical format without any brackets and commas. For example, refer below: Is there any utility to change the format like this ? 1.1.1.11.1.1.2 Regards,Shashank
Hi all,I've a FG-1800F that I've upgraded to 7.0.16.SSLVPN tunnel mode works well, but SSLVPN web mode have a problem when i try to connect using http/https or other protocols.It shows the message "SSL VPN Proxy Error. Reason: Access Denied".I state that firewall policies are correctly configured so much so that I can navigate via tunnel without problems.By debbuging I see the ouptut below:[5530:root:56b2]deconstruct_session_id:709 decode session id ok, user=[testuser], group=[VPN],authserver=[LDAP],portal=[fullaccess],host[x.x.x.x],realm=[],csrf_token=[BF28A52BF8CD26D67351B134F895BF9],idx=4,auth=16,sid=3e129ec9,login=1732875556,access=1732875556,saml_logout_url=no,pip=no,grp_info=[FP00ys],rmt_grp_info=[pSVTnq][5530:root:56b2]dns_query():296 tried IPv4 0 www.google.com[5530:root:56b2]dns_on_read():178 got result[5530:root:56b2]sslvpn_policy_match:2641 checking web session[5530:root:56b2]remote_ip=[x.x.x.x], user=[testuser], iif=34, auth=16, dsthost=[www.google.com], portal=[full-
Hi, I have 3 internet links:Broadband 250/250 Mbps PPPoECorporate 1000/500 Mbps Static IPMPLS 10/10 Mbps Static IPThe issue you're facing is that you cannot access the AGO website or the site is very slow, but you can access Google, YouTube, and social media normally.How can you fix this issue? And how should you configure the SD-WAN link?FG100F Firmware : v6.2.3 build6188
Some of our Fortigates are located behind other firewalls and the only way for those Fortigates to reach the Internet is via a web proxy. We were able to configure Fortiguard to use the web proxy to reach FDN to pull AV,IPS etc auto updates. Is there a way to configure threat feeds to use a web proxy too? If the answer is yes, how is this configured?
All of a sudden I can't login to my 40F device in our Forticloud instance...the appliance is up and I can connect to it via VPN, but for some reason when I try to connect to remote management via Forticloud I just get a blank screen. No config changes were made....anyone else seeing this?
When i go to the download page, and trying to download the windows version of VPN only, but can not access to the page. At the end this message showed out : Fatal error: Uncaught PDOException: SQLSTATE[08004] [1040] Too many connections in /var/www/html/src/Core/Database/DBAL/Database.php:22 Stack trace: #0 /var/www/html/src/Core/Database/DBAL/Database.php(22): PDO->__construct('mysql:host=mysq...', 'v-kubernetes-my...', 'HZKn0qIwHWdALJ8...') #1 /var/www/html/src/Core/Database/DBAL/Database.php(41): Core\Database\DBAL\Database->connect() #2 /var/www/html/src/bootstrap.php(11): Core\Database\DBAL\Database::Get() #3 /var/www/html/public/index.php(7): require_once('/var/www/html/s...') #4 {main} thrown in /var/www/html/src/Core/Database/DBAL/Database.php on line 22
Hello,I am trying to set up automatic failover wan using link-monitor and not SDWAN. Before I even get as far setting up the link-monitor I am running into an issue. My primary is wan2 and backup is wan1. I have tried setting the static route for the backup to a higher priority and/or distance value. When they are both connected it uses wan2 (what I want) then if I unplug wan2 it switches to wan1 (also good), but when plug wan2 back in it still uses wan1. Shouldn't it switch right back to wan2? I think I must be using the distance and or priority incorrectly.wan1 and wan2 are in a zone and my internet access policy uses the zone.  
hi,is the FG dashboard > network > ipsec view for "incoming" and "outgoing" data an "incremental" value over time, i.e. from the time ipsec VPN tunnel was built up to current date?how to view "real time" ipsec VPN traffic in GUI?
We have a small set-up, 1 Fortigate and 7 Fortiswitches. We have the same VLANs going to different switches and on some we have multiple VLANs. I have a couple of questions for things I don't quite understand. Does VLAN traffic carry over the fortilink port exclusively? My tagged VLAN port from the switch doesn't seem to be carrying much traffic. With our limited number of switches and a lot of free ports on our firewall, we want to run a cable for each VLAN for every switch. What is the best way to do this? I was going to do an aggregate connection but I am wondering if there is a better way. Thanks.
Hi everyone,I noticed FortiDeceptor supports integration with Cuckoo Sandbox, but given that Cuckoo is no longer maintained, I have a few questions:Is anyone actively using Cuckoo (or forks like Cuckoo3) with FortiDeceptor?For those who are, what does your environment look like? What security measures have you implemented to safeguard an unmaintained Cuckoo server?Are there users here leveraging other sandboxing alternatives instead?Has Fortinet issued any official statements about continuing to support Cuckoo integrations or recommendations for alternatives?Looking forward to hearing how others are approaching this. Thanks!
Hello,I am currently dealing with an issue related to the FSSO feature, which helps us manage rules on Fortigate. We are experiencing a situation where a user is not authenticated via FSSO when they switch from a wired connection to Wi-Fi. After this change of adapter, the user receives a new IP address and FSSO does not authorize them immediately. We also have a feature enabled that should detect IP address changes, but either it works with significant delay or not at all.Could someone advise me on how you handle FSSO during a change in the connection method? We would like to continue using rules for selected users. Best regards and thank you,Jan
Hello, We have an issue with configuring and using ZTNA tag for filtering internal traffic.We would like to base our config on following example:https://docs.fortinet.com/document/fortigate/7.0.0/new-features/477578/ztna-ip-mac-filtering-examplebut we would like to use it with many Fabric firewalls not just one (as it is shown in the example). Here is our setup:1) EMS server (7.2.6) assigns ZTNA tag - it works OK2) Forti manager (7.2.8) synchronizes ZTNA config to all our firewalls (7.2.9) - it works OK3) We configure internal traffic rules using ZTNA tag as source criteria. Unfortunately, we discovered that above config works properly only within one firewall. That is because ZTNA tag is mapped ONLY to local IP addresses on the firewall.Thus if we want to use ZTNA tag globally as a source criteria, it doesn't work (because particular firewall maps ZTNA tag to only local IPs and doesn't know anything about remote source IPs for that tag). Question:Is there a way to
My Apple device running iOS 15.6.1 is failing to connect to FortiClient VPN IOS 15.6.1 (FortiClient 7.4.2.0151) – Not work * No popup for enter the username and passwordIOS 18.1 (FortiClient 7.4.2.0151) - OK Does anyone know if there is any compatibility issue between FortiClient 7.4.2.0151 and devices running iOS 15.6.1?
Hi Fortigate experts,we need your kind help. End customer needs a DRP for some of their on-premise business critical applications.We are proposing AWS for the DRP environment .We are proposing Fortigate to protect some internet exposed services and also to enable VPN Clients to connect to the AWS DRP environment.The AWS DRP environment (and therefore the Fortigate) is only needed when DRP is declared by the IT department (1 or 2 times per year for around 24hrs each time). Is it possible to avoid being charged the Fortigate prices when DRP environment is not needed?, for example, "turning off" or "disabling" the Fortigate when it is not needed and "turning it on" only when needed ( or 2 times per year) without losing configurations?Thanks
Hi I am currently using Fortinet V7.4.4 and recently encountered an issue where users connected to the WiFi1 network were unable to browse the web. However, there were no issues with web browsing when connected to the WiFi2 network.After comparing the configurations of both WiFi networks, I noticed that the DNS filter was enabled on WiFi1. Disabling the DNS filter resolved the issue.We haven’t made any configuration changes, so I’m curious—why would the DNS filter block web browsing?
Hi,please refer to the screenshots - why is the FortiGate blocking legit HTTPS and HTTP traffic? The policy and the corresponding SDWAN rule should alllow everything. It just doesn't make any sense and the provided article is not helpful at all.https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Threat-131072-is-seen-in-logs-when-traffic/ta-p/192533
Hello,I took over the infrastructure with FSSO on DC installed, in services Domain Administrator is set for FSSO Service as run us account.I don't want to use Administrator account, can I change it for normal user or some special user ??If yes, what permission in AD this user should heve ??Thanks,
Hello, I’m experiencing an issue with my firewall. A service used within a website is fetching image files from its own server. Due to a problem with the firewall, I can't see these images. From the firewall logs, I see that there is no response from the other side. However, when I use my mobile internet, I can access both the website and the images fetched by the service. I’ve allowed access to the services the website connects to through Google Chrome in the firewall, but the issue persists.
hi,for now we have services fo0r 5/8we want to upgrade the services to 24/7what we should do?
Hi All, We are having issues in our MPLS - IPsec VPN Tunnel, please see attached network diagram for reference. Whenever we up the tunnel in ISP1, we have no problem.1. We can access the ATM and Blackbox Switch from the server and vice versa. We also have a test laptop in the client side which I forgot to in include in the diagram.2. We can traceroute the traffic and see that it is passing through the expected path, which shows the IP address from both sides in ISP1.3. Even on Fortigate logs, we can see that traffic is using the right policy and static route. The problem start when we swing to ISP2, for HA testing.1. We can still access the test laptop from the server and vice versa. We use the test laptop first before we proceed with adding the ATM and Blackbox, which is what we did in the ISP1.2. When we traceroute the traffic, we can still see that it is passing through the router in the ISP1 of the client side.3. The client also tried to traceroute
Hello,i have an issue on FortiAuthenticator HA on virtual machine,when trying to create HA Active-Passive between two virtual machine the HA status on the two nodes become primary with one has high priority and the second has low priority but no sync happen between the both devicesi have attached a copy of the config of the ha setting on both devices
We are attempting to Push the Persistent Agent to our Mac's via JAMF School. We are seeing the package and script pushed to the macs but it is not Executing. Has anyone attempted this? Any luck?
Quick background on the environment.Root vdom contains all the physical connections to the VMWare stack and the internet. VDOM A - All internet bound traffic (inbound or outbound) runs through an intervdom link. Everything works as expected.I understand how one would pass traffic through for either all ports or a single port from an external IP, through a VIP on Root, to the intervdom link IP of VDOM-A and then another VIP on VDOM-A to 'inside' VDOM-A.What happens when you need to have multiple external IPs all routing to something within VDOM-A? With the intervdom link, VDOM-A essentially only has 1 'external' IP. For example, you've got external IP: 40.40.40.40 that goes to WebserverA in VDOM-A and you've got 40.40.40.41 that goes to WebserverB in VDOM-A. Do I create separate intervdom links for each external IP?Do I take the VIP from external to Root and do something like take 40.40.40.40 port 80 outside, translate it to 172.17.172.1 (intervdom
I have a fortigate 90G and I have to console into it to reset the admin password as we forgot itI browsed online and it says to download fortiexplorer as we have usb console cable but couldnt find fortiexplorerCould you please guide me how to get to the consoleThanks in advance
Recently had EMS updated 7.2.5 1061 and no longer see see the quarantine action, was this moved or a known issue? In the past we navigated via. select endpoint -- action -- Quarantine.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.