Mark a Best Answer
Fortinet Community
Recently active
Hi FML adminsOn FML 7.6.0, Monitor > Log > History, I can't find Session ID anymore, so I can't display detailed session log, and I can't find a way to display additional columns in order to show Session ID column.Is it me or is this a regression?
hi we have an IPSEC tunnel configured on our fortigate FW which is linked to Azure.this tunnel has intermittent connectivity drop outs and its affecting production servers/users and what they are doing.as far as I can tell the phase 1 and phase 2 settings are correct at both ends. this includes the pre shared key, DPD, algorithms, diffie-hellman group, key lifetime for phase 1 and 2 and the PFS.based on the fact that the VPN is on for most of the time and the drops are intermittent, this would indicate that the settings are correct otherwise the connection would not be established... am i correct in saying this? i have noticed that we DO NOT have auto-negotiate or Autokey Keep Alive enabled on this tunnel. Not sure if this is required? but ive read some posts indicating that this is a useful feature to enable.https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepalive/ta-p/189536fortigate detailsFortigate 1800Fv7.2.9 build 1688&
I have FortiSIEM, FortiSOAR and CheckPoint firewall. Connected FortiSIEM and CheckPoint firewall with FortiSOAR through connector. Now can anyone please guide me that how can I take action from SOAR. For example:SIEM detects a brute force attempt. SOAR ingest data from SIEM. Now I want soar to take action against the attacker through checkpoint firewall. eg: block IP/block url.FortiSOAR FortiSIEM
We are a Cisco meraki LAN and AP shop with Fortigates. I'm keen to go full Fortinet stack with all the NAC features, reporting and insights into end users.Cisco meraki is easy to use and is well known within the company, but expensive, what are people's experiences in moving? I have read some negative reviews on the Forti APs in particular.I've also read FortiNAC can still be used without a Forti switch and AP but has it's limitations. As I don't want to go down the ISE route as it's a headache.
Hello, I have not found a way yet to set up intercom an extension using a prefix button. We are coming from an ESI PBX where a simple press of the extension on an interoffice call could be set to auto answer. Anyone have any luck with this? As it is, I have to program an intercom button for every extension using *92XXX where the X is the extension. This takes up a lot of real estate.
We’re currently using an IPsec VPN on a FortiGate device for remote access because SSL has reached EOL. Our entire network, including both internal and public IP addresses, is IPv4-only (no IPv6). Here’s a rough summary of our setup:Public IP: For security reasons, I'll use an incorrect IP example: 300.77.11.260Internal server: 10.0.0.4/24 (NVR system requiring remote access)FQDN: vpn-mycompany.com resolves to our IPv4 public IP (300.77.11.260)Issue Summary:The IPsec VPN is configured correctly; users on Wi-Fi can connect and access the internal NVR server (10.0.0.4) without issues. However, cellular clients using IPv6-enabled ISPs experience the following problems:They can connect to the VPN and ping the internal server, but RTSP fails to load live camera views.No internet access is available, as they lose all external connectivity - Internet traffic doesn't go thru VPN.Pinging vpn-mycompany.com while disconnected from the VPN (on cellular) resolves to an IPv6 address that we haven’t
Dears, what is the difference between access control rule delivery and recipient
Hi, I wonder if some has experience in establishing a SIP trunk between FortiVoice and Cisco Call Manager?
I have a FGT40F (behind NAT) at a remote office and a FGT61F at my home office with an IPsec tunnel between them. Both were on 7.4.3 and all good. I updated the 40F to 7.4.4 and now the IPsec VPN will not connect. I rebooted both ends and tried to enter a new key and still no luck. I then rolled the 40F back to 7.4.3 and loaded the config back onto it and it still won't connect. I've read about a new FW version changing something that affects VPN but I have not been able to tie that to my situation. Thanks for any help.
Hi, I made the mistake of uninstalling an old version of Forticlient to install the 7.2.2 and since then Forticlient doesn't work for any of my clients. When I try to log on, it gets stuck on "connecting". I gave full disk access to both Forticlient and fctservctl2. But I haven't enabled the "extension" which was prompted in mac OS 13 in "security and privacy" but not anymore in Mac OS 14. How do you enable forticlient extension in Mac OS 14? I have the same issue with older version now. log of fortitray.log: 20231208 19:24:56 TZ=+1100 [FortiTray:INFO] AppDelegate.swift:128 App: FortiClient-7.2.2.077620231208 19:24:56 TZ=+1100 [FortiTray:INFO] AppDelegate.swift:129 OS: Version 14.1.2 (Build 23B92)20231208 19:24:56 TZ=+1100 [FortiTray:INFO] AppDelegate.swift:261 Checking privileged helper.20231208 19:24:56 TZ=+1100 [FortiTray:INFO] AppDelegate.swift:270 Privileged helper was installed.20231208 19:24:56 TZ=+1100 [FortiTray:EROR] ConfigManager.swift
Does anyone have a chart or template or custom report they are willing to share that graphs (in and out bandwidth utilization) on each of the WAN interfaces of each of the Fortigates? The closest to what I am after would be the Chart: Interface Utilization Device List1) Is there a way to filter just on WAN interfaces?2) Is there was way to remove all graphs except for the utilization sent and received? Using FAZ 7.4.2
Does any one know where is the Upgrade Path Tool for FortiMail? Or any one have a cheatsheet/pdf with that information? In the Fortinet web the Upgrade Path Tool doesn’t have information about FortiMail
Hi,I want to send the events from FortiPAM to the SIEM, to see login to the console and so on. In the FortiSIEM CMDB-->Devices I see the PAM device and "Pending" status, I approve the status and in Edit Device, select Type: FortiProxy, there is no FortiPAM type. When I search for the events in SIEM they appear as "Unknown_EventType".In the raw events I can see "Authentication Failure: Local", for example...Thanks
Hello, I’m currently trying to connect to my company’s FortiClient VPN while working from another country. However, the connection is being blocked due to the firewall’s restrictions on connections originating from outside the allowed region.To overcome this, I attempted to set up a proxy using an Amazon EC2 instance located within the allowed region. I’ve tried various methods, including using socat, stunnel, and nginx, to forward the traffic from my local machine to the VPN server via the EC2 instance. Unfortunately, I haven’t been successful in establishing a working connection.FortiClient often stalls at 31% or 40% during the connection process, which I suspect could be due to TLS version mismatches or certificate validation issues. In some cases, FortiClient fails to present the usual certificate acceptance prompt.Are there any specific configurations or tools you’d recommend to make this work? Thank you
Hi all, I found that some hosts are found under Compromised Hosts. 1. Does it mean it is infected by malware? I scanned with AV and got nothing2. One record show nylon.com is SpywareCnC but I checked it is a fashion website. Is it false alarm?[link]http://nylon.com[/link] Thank you!!
Hello,I’m experiencing an issue with an SSL VPN setup on my Fortigate, and I’d appreciate some guidance. Here’s the scenario:There are multiple VLANs (e.g., 100, 200, 300, and 400), and the Fortigate handles the routing between them. Within the local network, devices in VLAN 100 can access VLANs 200, 300, and 400 without any issues, as there are existing firewall rules in place to allow this.The SSL VPN is configured in Tunnel Mode with the setting Enabled Based on Policy Destination. SSL VPN Portal Settings:Routing Address Override: UnconfiguredSource IP Pools: SSLVPN Tunnel Address RangeFirewall Policy for SSL VPN:Incoming Interface: ssl.rootOutgoing Interface: VLAN 100Source: SSLVPN Tunnel Address Range and VPN User GroupDestination: VLAN 100 Address RangeService: AllNAT: DisabledWhen a client connects to the Fortigate via FortiClient VPN, they can access resources in VLAN 100 as expected. However, they are unable to access devices in VLANs 200, 300, or 400.It appears that the
Hi.I'v got a forticlient ems poc installation on 7.2.5 (about to upgrade to 7.2.6) Iv got the before_os to connect with the machine cert (with a ldap check to the ad that then computer is there with dns) and then the auto connect when log in to user cert (again with the ldap to check if the user is there with cn) and that works fine.But sometimes when i have the computers lid closed and open it and login with Windows Hello pin or face its stuck on the machine auth, thats a major problem cause iv got firewall policies som the machine auth only allows for password reset and the user cert to allow more.Anyone have problem with this thing? if i can't fix it im think about going with the before logon option with the button so the only auto connect tunnel is the user.Morten
I've blocked many mobile phones from connecting to our wifi via MAC blocking at the DHCP advanced options on Fortigate. But the problem is most of these phones have MAC randomisation turned on, so the next day they're back on my Wifi again. Is there any other way to block these devices, other that using a whitelist option?Is there a way to block by hostname? or any other identifier?
I have worked with different vendors and technologies for a couple of years in the IT industry. Still, when it comes to Fortinet I have very limited experience, and rarely when I touch firewalls setup...etc.recently, I've got involved with a new Fortinet project, a lot of branches offices with 2x HQs, all VPN made manually with headquarters, with no centralized mgmt,branchcustomer it planning to set, fortimanager, and analyzer to orchestrate mainly SD-WAN and central management Fortinet environment,I want to start learning the most effective way, my question is: can I start with SD-WAN training (NSE7) directly to understand how their SDWAN works for Fortinet? I do have CBTNuggest access.or I must do NSE4 training first before I jump to something else,or may be I have to think otherway, please let me know you thought on how to get started my main focus now is SD-WAN fortinet,
Hi, We have an IPSec Tunnel between office1 and office2 to connect two Servers. We need office1 users to connect to the server in office2 using another interface instead of the IPSec Tunnel and let only the servers communicate over IPSec. How can we achieve this, if it is possible? BR.
Hi Guys, on the fortigate 120G I have created a automated weekly backup to our TFTP server.everything is working fine, my only concern is that the password is in plain text. is it possible to encrypt it? i have looked everywhere but can't find solution. Fortigate 120G - running firmware 7.2.10 script : execute backup config sftp E:\Backup-Netwerk/ROVPNFG/backup_%%log.devname%%_%%date%%.conf <server-IP> <username> <password>
Hello folks,I have the problem, that my remote-site does not use static-ip-adresses. So I can only use a dial-up-vpn-configuration. Some devices between the 2 VPN-endpoints are needing a permanent connection, but when no traffic goes over the tunnel, the tunnel will not "get up". Is there a way, to keep the dial-up-tunnel up, although there is no traffic going over it? (keep it up permanently)
Dear team, I have a Captive Portal, and I need to log in to two devices using the same user account. How is this possible.?
Hello Expert, I create a automated stitch to schedule daliy back and tftp the file to windows server.When I Test using a exec backup full-config tftp backup.cfg 192.xx.xx.xx from the fortigate the backup works okay. I created the action trigger and stitch but for some reason the backup is not generated at the designated time as defind in the trigger. I humbly request some guidance to troubleshoot Thank you
Hi guys. I have a FortiAP that would not become online in the Fortigate. It would take IP from DHCP, would respond ping , but would refuse SSH, and when accessed by web it would show the message below. Any idea if it can be fixed? Access Error: 404 -- Not FoundCan't locate document: /
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.