Mark a Best Answer
Fortinet Community
Recently active
Recently had EMS updated 7.2.5 1061 and no longer see see the quarantine action, was this moved or a known issue? In the past we navigated via. select endpoint -- action -- Quarantine.
Hello team!! I need to do the following but I dont know how.We have the only 2 WAN connections in the same SD-WANEverything is working fine, but now we need to specific IP range to use WAN2, and when WAN2 is down, this specific IP range should not use WAN1 connection (Should not navigate).Is this possible to accomplish this with SD-WAN rules? Thanks in advance.Regards,Damián
I have a VIP setup with a static route, so it can be advertised into bgp. The link-monitor checks the server the VIP is mapped to. When I shutdown the server, the link-monitor shows the status is dead, but the static route is not withdrawn from the routing table. Is blackhole as a next hop not supported for link-monitor? FortiOS 7.0.15 config firewall vipedit "VIP"set uuid 6b05a182-a52a-51ef-84f5-d38866bd0382set extip 77.77.77.77set mappedip "172.16.78.10"set extintf "WAN"set portforward enableset extport 80set mappedport 80nextend FortiGate-VM64-KVM # show router staticconfig router staticedit 1set dst 77.77.77.77 255.255.255.255set blackhole enablenextend config router bgpset as 65017config neighboredit "10.17.255.1"set remote-as 65000nextendconfig networkedit 3set prefix 77.77.77.77 255.255.255.255nextend FortiGate-VM64-KVM # get router info routing-table staticRouting table for VRF=0S 77.77.77.77/32 [10/0] is a summary, Null, [
Hi All, I'm getting a lot of help desk tickets with stuff like "It looks like mathsbot.com closed the connection" (one of many sites!) I use deep packet inspection. I've tried pretty much every option on the profile to change that, but the only thing that seems to work is adding the site (or the relevant category) to the SSL exceptions. I'm getting enough of these tickets for it not to be sustainable. Any ideas anyone? (I do need DPI, educational institutions)CheersJon#fortigate
How are we updating firmware on the free (three device) faz / fmg vm64 licenses these days? I am unable to get firmware for faz from support portal because I don't have a support contract for it, and from the web gui it only has older versions in the drop down list.
facing below error while activating licence Fail to download license, please give it try later. [Error_code: -3040]
I've created a bunch of address objects for all the host IPs in a given environment but in the forward traffic logs I still see IPs and some DNS entries if RDNS for those IPs has been setup (externally). I was wondering if theres a way to link these address objects in some way so its easier to read through forward traffic logs, and fortiview for identifying systems in various tables?Also wanted to ask, is there any advantage to linking an address object to an interface? I tried to do it after the fact, but wouldn't let me as it said the object was already in use. I find it pretty frustrating that certain config changes cant be made without undoing everything related first. I dont care if it's impacting, just let me do the thing and warn me that certain policies will need to be repaired/updated.
WAN1 port has got 5 different IPs from the same block. I noticed SSL-VPN is active all of those IPs, but I wish for it to only reply to the main address.Are you forced to write a specific firewall policy, or is there a way to only bind SSL-VPN service to a single, specific IP address?
Hi, In the case that a website suggest a list of domains and/or IP addresses, I would like to know how to make a CLI script to either create a new group or add members to a new group. I know the indentation is important. Example: https://learn.microsoft.com/en-us/mem/intune/fundamentals/intune-endpoints?tabs=north-america I was adding things manually but now there's so much that I'm looking into upload CLI scripts. Thank you for your time.
Hi, We have our customer encounter issues with their end users getting VPN locked out and upon checking, the Forticlient still has their OLD passwords.We already disabled the option "Allow client to save password" under VPN Manager > SSL VPN > Portal Profiles > Tunnel Mode Client OptionsSo far, we got multiple different issues on the Forticlient 2 known issue are below.Scenario 1. User able to login and Logout on the VPN. Username and Password are removed upon Logout but still seeing the check box to save password.Scenarion 2. Check box is gone. User is able to login and logout but upon logout, the username goes blank but the password remains.The issue is happening on users whose passwords have been reset by our customer since they are using AD to manage end user accounts. The old password has been saved on the forticlient and we want the option to save the password disappear to avoid the users using their old passoword to avoid being locked outOur forticlient version is
I have configured two WANs on my fortigate 100F.I wrote two routes to the 0.0.0.0/0 network with the same weight and priority.one that points to wan1 and one that points to wan2.and I would like to ensure that the PCs in group 1 navigate with wan1 and those in group 2 with wan2. what should I configure??if I write two policies to DOC only one works.
Hi,I'm trying to schedule a full-config backup, from a 40F to a ftp server visible on vpn s2s. using this command:execute backup full-config ftp '/xxx/FGT_%%date%%.txt' 10.3.64.113 user pwd I receive this output:"Send config file to ftp server via vdom root failed." ping from fgt to the server not working, so I did a packet capture for destination ip 10.3.64.113 and I found that the Fortigate use, by default, the wan interface, but in this case that port is disabled and I'm using A port as a Wan port. what can i do to route the backup procedure correctly via vpn s2s using the correct tunnel-interface?
Hello guys,So basically my client wants to know if there is a way to force the fortigate to validate an AD group prior to all others, so that the users in that group (that belong to other groups also), may get the permissions set in that first group.He wants to know if theres is any sequence in wich the fortigate does that, and if so how is it done, by alphbetical order? As an example /VPN GRUPO ANF/AD_VALIDA , whould this be verified before this one /VPN GRUPO ANF/BD_VALIDA Thanks
I configured a VPN L2TP via IPsec on a Fortigate (401F). To manage authentication I used FortiAuthenticator that connects to a OpenLDAP server. Radius is used to connect Fortigate and FortiAuthenticator.In the end of the configuration all works but now I have a problem, that´s because I have 2 different user groups and I want to make different firewall policies (manage access) to each group. Let´s imagine a group "students" and a group "teachers", both authenticate via L2TP but with different accesses.How can I create different policies based on the group of the users?
All, I've setup a 100E with web filtering profiles and connected it to my DC successfully. However when I enable Web filtering and use the groups and users I've created users cannot login. I can login as a local firewall user but not an LDAP user. I've had users try their username, their full name, their username@domain.local, and domain\username. None of the above work. is there something I'm missing here?
Hi, we have two FortiGateRugged 60F in an active-active HA cluster.internal1 and internal2 ports were originally members of a hardware switch interface, with 5 VLANs. We changed the configuration to a software switch interface, to have a more granular control over the vlans for the seperate two ports, because the first approach doesn't allow to assign some VLANs on internal1, and some other (but overlapping) VLANs on internal2. The problem: Prior to the change from hardware switch to software switch, we could unplug the cable on port internal2 on FortiGate A (Primary, higher priority) and the traffic would be forwarded through internal2 on FortiGate B.But this isnt possible anymore. If we unplug the cable, there is no rerouting/forwarding and the connection is simply lost. I guess the FortiGate cluster still keeps FortiGate A as Primary, even though one interface is down? I wanted to add the two interfaces to the "monitored interfaces" of the HA, but this isnt possible -
Hello Fortinet Community,I'm currently facing an issue with my FortiNAC-F 7.2.8 (previously 7.2.7, upgraded in an attempt to resolve this) when trying to connect to switches via the Validate Credentials button in the device configuration. The credentials are verified to be correct, and FortiNAC successfully connects to the devices via SNMP. However, it fails to connect using CLI for validation. Here’s a breakdown of the problem:SNMP Connectivity: Successful – FortiNAC recognizes the device through SNMP without any issues.CLI Connection (SSH) Fails with Validation: When attempting to validate CLI credentials on FortiNAC, the connection fails even though the credentials are accurate.Direct SSH Attempt from FortiNAC CLI: When I directly try to SSH into the switch from FortiNAC's CLI, I receive the following error: Unable to negotiate with [Switch_IP] port 22: no matching key exchange method found. Their offer: diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha1, diff
Hi All, I've configured a policy with SSL Deep Inspection for my company and installed the Fortigate CA certificate on our devices in order to now be shown the certificate warning. However (on both mac and windows devices) when using Firefox it does seem to work correctly and the certificate shown by the browser is the Fortigate's, though when using either Chrome or Edge the certificates shown in the browser are the original webserver certificates, just as if the deep inspection policy didn't exist at all. What am I missing?
Dear Support Forum, I have an ipsec tunnel problem from branch to HO, where the download traffic from branch to HO remains 0 bytes,and in the configuration of the ipsec tunnel HO to the branch the peer id (gC.b) appears as the username.Is there anyone who can help to solve this problem?
Hi everyone, I have a LAN user wants to connect to a LAN server from the public address that is in the same subnet as the fortigate external address. I have setup VIP and firewall policies but it does not seem to work, debug flow shows it was DNATed to the server's internal address but the traffic does not go through(my server does not receive any traffic), the final log of the pakcet was "allowed by policy" then followed with nothing. My topo and configs are as follow, any idea is appreciated.config firewall vipedit "vip"set extip "10.1.1.2"set mappedip "192.168.8.200"set extintf "wan" # have tried with "any" but also not workingset portforward enableset extport 443set mappedport 443config firewall policyedit 1set name "lan1-to-lan2"set srcintf "lan1"set dstintf "lan2"set action acceptset srcaddr "all"set dstaddr "vip"set schedule "always"set service "ALL"edit 2set name "wan-to-lan2"set srcintf "wan"set dstintf "lan2"set action acceptset srcaddr "all"set dstaddr "vip"set schedul
As an MSP, we co-manage firewalls with in-house IT. Combination of leased and customer owned appliances. We have all customers in our FortiGate Cloud MSP edition instance. Technicians are all setup with individual cloud accounts and forced MFA. In-house IT takes the included tokens. For other systems, we have a shared MSP login with TOTP key entered into our password management system. Password management is protected by individual logins with MFA. IT Glue…. I believe this is pretty common. The problem lies in three spots. 1. We cannot add a FortiToken to any password management system. We have to manually add/remove technicians. This is a huge security blunder waiting to happen. 2. FortiTokens expense would get unreal. We have many clients that are T&M. We don’t get paid to have access, but when we get called, we need secure acce
Hi team,I created an admin account (local) with admin-profile as super-user. Although it is the highest privilege, I cannot add device/edit, even though I checked the information in the admin-profile (super-user) and selected the add Device feature.Thanks
We replaced our core switch (HP 8212zl) with an Aruba CX 6405 back in June. We hired a consultant to reconfigure the config to be compatible with the new CX OS. Ever since then, FortiNAC is intermittently reporting Contact Lost events for our Aruba Controllers and Aruba APs. The controllers and the APs are on the same VLAN, and there are no ACLs or firewalls in-between VLAN 1 (new core) and VLAN 40 (wireless network). There are zero port errors on the core and it's not an STP issue. The contact lost events only occur with the wireless controllers and APs, and not with our other edge switches or servers. If we check the Aruba wireless side of things, none of the controllers or APs lose network connectivity. There's just a brief/random comms issue when FortiNAC reaches out to poll via ICMP. Does anyone have any ideas? Fortinet support is claiming it's a network issue and not on their end. I could really use some help. Thank you.
Allow me to outline for you a nightmare scenario... You're using BGP for routing, with a wholly separate netblock for those links.You have a few (let's say 6-7) AD servers doing LDAP authentication across the company VPN, and you'd like to actually leverage that redundancy.Address auto-selection based on the interface for binds to 0.0.0.0 is definitely a thing, and you're just not allowing those BGP-wrangled interfaces to talk directly with any other netblocks.You have a Fortimanager and need to configure over a hundred devices for this, when each and every one will default to using the BGP-provided address bound to the VPN interface to make outbound connections within the VPN network. Without more metavariable support, the Fortimanager is now a liability. You may eventually figure out that CLI templates (which do support metavariables) will allow you a somewhat ugly way to slap the definitions of the AD servers into all these devices (which seems like it
ALL, I am creating my Fortigate Lab, using vmware workstation pro.i have downloded the lates VM-FGT_VM64-v7.6.0.F-build3401-FORTINET.out.ovf.zip (98.44 MB)i did all config, and i can reach out to internet, but when i try to activate the trial license using GUI or CLI, it give me Timet error msg. find the SC belos, and please helpNOte, i alread do all theses steps inthis link:https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/441460/permanent-trial-mode-for-fortigate-vm
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.