Mark a Best Answer
Fortinet Community
Recently active
Hi there We are rolling out MFA to our Forticlient VPN users. When user clicks connect a popup window appears for the SMAL idp, titled "Forticlient SAML Authentication". There is a timeout counter in the tile window that starts counting down from 300 seconds. When the popup appears, we can see in the FortiClient window, above the VPN Name box it says "status:connecting". The user needs to enter a login name, then a password, then a passcode, each on a different screen within the popup window. The popup closes and the user is returned to the Forticlient window which then goes through the connection stages and connects to VPN. The issue we are having is that if the user does not enter their login details within 30 seconds in the popup window, when the popup closes, the "status: connecting" message disappears and no other connection messages appear and the user is not connected to VPN. Even if we do nothing in the popup window, the "status: connecting" message disappears wi
Hi there, I've got a FortiGate running 7.2.9 and FortiClient EMS server running on 7.4.1 but I'm not quite sure where to start getting ZTNA up and running. We use Okta for our IdP and I'm presuming that'll be what manages the role based access control but I was hoping there was some guide available to walk you through getting everything working together. Everything I've found so far has been for previous versions of FortiClient EMS which requires Active Directory (which we don't have.) If anyone can point me in the right direction, I would REALLY appreciate it! Thanks!
HiI was wondering if anybody have made a Fortinet network with, FG, FS and multiple FortiAP 233G and how to extend the Zigbee network to get IOT devices to work all over the network with example an Homey Pro Since it would not be able to cover the entire office area.If you have an idea for something better than a Homey Pro, please let me know.
Hello, I'm confused regarding network lockdown support for IPSec in FortiClient.Document Library for FortiClient 7.2.0 describes in the New Features section that network lockdown is supported.https://docs.fortinet.com/document/forticlient/7.2.0/new-features/394388/ipsec-vpn-support-network-lockdown-and-hotel-mode-7-2-5On the other hand, documentation for FortiClient EMS says it is not.Which one is correct?Or how to resolve situation when we need to disable Internet communication for client who is not connected to IPSec VPN or disables the tunnel?Do I need to use permanent route to FortiClient's virutal interface for that?
Good guys, can someone provide me with a download link for the FortiClientTools file from support.fortinet.com Support -> Firmware Download. unfortunately I don't have access.Thanks
Hi FNAC adminsIn FortiNAC or FortiNAC-F, is there a way to restrict access to admins to some containers (or switches), in such way some admins can manage some switches, and some other admins can manage some other switches.
Hi all, I hope you're well. I am testing FortiSASE and have setup and working as I would like however, I would like to run some alternative IPsec VPNs as well as the SIA into FortiSASE. Within the SASE portal I have added the IPsec VPN into the "VPNs available to users" section and this Endpoint Profile is pushed out to my device. The problem is that within the portal I cannot find any section whereby I can specify my VPN settings and even though this VPN gets pushed to my device I am unable to adjust the VPN settings within FortiClient as they're greyed out and therefore I can't get the VPN working. Is there anyone that has configured other VPNs in the Endpoint Profile that can help me locate these settings or tell me how I can push the IPsec VPN settings I require to the device from the profile? Thanks, Dan.
I am using a FortiRecorder VM with a number of cameras. Unlike the 400F's I am seeing the system load reach 99% for the same number of camera's as the 400F, the network environment is very similar. 1gb to the recorder and all the camera's are on one switch running at 100 Mbps. What I seem to not be able to find is any information on what System Load means exactly. What is System Load?
greetings all, I know that SLA targets in performance SLA are a set of constraints that are used in SD-WAN rules to control the paths that traffic takes. and The Link Status section of the performance SLA configuration consists of three settings that determine the frequency that the link is evaluated, and the requirements to be considered valid or invalid. what if I set: Packet Loss in SLA targets to 12%, andFailures before inactive in Link Status: 5.And I use= Lowest Cost (SLA) in SD-WAN rule Scenario: there are 5 consecutive Packet Loss at a specific time point, but the Packet Loss rate is still lower than 12% (calculated based on the latest 100 probe). Will any a link re-selection occur? If yes, will existing traffic session be interrupted and re-established via the newly selected link? If yes, will the communication of the session be down for a short time? Thanks,Sean
We have configured our FortiGate with a WPA2-Enterprise SSID that authenticates via LDAPS pointing to an Azure AD Domain Services instance. All our company users are cloud-only and synced to Azure Domain Services. We do not have an on-premises AD or an Azure hybrid deployment, and we don't have FortiAuthenticator.Users can connect to the Wi-Fi, but they suddenly disconnect, The connection then reconnects after some time either automatically or sometimes when the user manually reconnects.I initially thought the issue might be due to network latency, so I set a traffic shaping policy that gives high priority and bandwidth to LDAPS traffic destined our Azur AD DS public IP, but the problem still persists.Has anyone faced a similar issue?
Hi all, does it possible to create on FGR60 and Hardware Switch interface with port(n) and WAN(n) port? I'm asking because I don't have the possibility to verify directly. Best RegardsAlberto
Hi guys, i am trying to configure our Fortigates to send scheduled backups to Azure blob storage, but with no success.I've set up a blob containers and a webhook on Forti side, but keep recieving this error when triggering the automation:auto_curl_perform()-107: Curl perform error:22 - HTTP response code said error.__action_webhook_status()-150: Failed to perform curl for url:https://....... ( URL to my containers)Here is my webhook action:---------------------------------------------------------------------------------------------------config system automation-actionedit "HTTP-to-azure"set action-type webhookset protocol httpsset method putset uri "<HIDDEN>.blob.core.windows.net/<HIDDEN>"set http-body "%%results%%"set port 443config http-headersedit 4set key "Content-Type"set value "text/plain"nextendset verify-host-cert disablenextend----------------------------------------------------------------------------------------------I am pretty sure that my Azure configuration i
Hello,After making a research regarding of the (im)possibility to make it work, and some tests on FAZ 7.4.x, I wonder if this is feasible or even in the roadmap. Apparently the log parsers can be assigned to a device only if it is recognized as Fortinet, and appears first as unauthorized. However, sending syslog to FAZ from any device seems to store the logs into the Syslog ADOM, but when you try to assign a parser it's not possible because there is no device to select. Also, even if the logs would come from a Fortinet device (e.g. FortiSOAR), the docs say they would be parsed and inserted in a "SIEM db". But how can the latter be used?Any ideas?Thank youCristian
Hey People! I would like to raise a concern I have a little knowledge in firewall role. Just wanna regarding on the SSL failed Login. our client want to block the IP address of unknown and random credentials found on VPN event logs. We already block those IP using the deny policy (example we already add the 80.94.95.x) but upon checking the VPN event logs the still existing on the logs. Am I doing it wrong? or is not possible to block the IP using local policy is it possible to minimize this load of logs?. our client said they are already disabled the SSL VPN because they are using IPSEC the first image is the firewall objectthe second is from VPN event logs Thank you (Version 7.2.8)
Hello Community, We recently upgraded an existing Fortigate Rugged 60-F (FGR-60F) cluster from 7.0.x to 7.2.x. The cluster was in sync and operating fine in 7.0.x but failed to establish the HA cluster after the FortiOS upgrade. After troubleshooting this with Fortinet we learned that even though there is only one SKU for order placement (FGR-60F), Fortinet itself has various generations of this hardware platform (currently 5). The first 2 generations came with only one power supply and since the 3rd generation a 2nd power supply was added to the platform. The problem now is that FortiOS 7.2.x added new command statements (config system vin-alarm) that only work on gen 3-5 which results in a configuration difference between gen 1-2 and 3-5 that prevents clusters from being able to get in sync. How can you tell what generation of hardware you have? Two ways:Run the CLI command "get system status" and look for the "System-Part-Number".&n
Hi All, I 'm facing an issue, in the Forticloud report, the user who use the most the bandwidth is displayed as N/A.We use FSSO as authentication method. Have anyone an explanation ?Thank you in advance
Good day Fortipeeps, I just want to ask if there's such command to get fortigate CPU utilization for specific time? For example diag sys top 2024-11-11. or that command does not exist. Thank you!
Hi, New to using FortiSwitch and FortiAP so bear with me. I'm trying to configure a SSID to authenticate users based on a provided certificate they have. We already have this all set up and working using our Cisco AP's, but for this site we are trialing a full FortiNet setup. We also dont have FortiAuthenticator. The SSID is configured to use WPA2 Enterprise and points to our RADIUS server. It looks like the configuration for the certificate authentication is done on the FortiAP Profile. I have enabled 802.1x and selected EAP-TLS as the type. But its asking me for a username and password and wont let me proceed without it? What is this for as I want the clients to authenticate solely with the installed certificate on the machines? Also, if I have .1x enabled on the profile, can I still use another separate SSID with a PSK for authentication as well? Thanks.
Hi all I have this problem i have 2 vpn tunnels on one Fortigate the external interface is wan1 for both vpn1 --- interface ---wan1vpn2----interface-----wan2 both vpn are working and i can reach a vm on both sides from the lan interface lan ---- vpn1-----ok working. vm1 pinglan----vpn2--------ok working vm2 ping now i have on both vpn ends a vm i need to connect vm1 to vm2vm1 ping fortigate lan interfacevm2 ping fortigate lan interface i cannot ping vm1 from vm2 and viceversai have setup routing and firewall policies, maybe i miss something please helpthanks
A few years ago, we transitioned from an on-premises server to using Azure Files Storage for managing our files. To ensure accessibility, we mapped 10–11 Azure folders to drive letters on client workstations via File Explorer. This setup worked seamlessly until yesterday when our ISP replaced our connectivity hardware.Original Configuration:ISP modem (Spectrum) connected directly to a FortiGate device.FortiGate configured with a static IP provided by the ISP for VPN connectivity.New Configuration:ISP replaced the modem with a modem-router combo (to maintain the static IP).Configuration: ISP modem-router → FortiGate device.This resolved our intermittent connectivity issues and improved bandwidth. However, the new setup has caused problems with accessing Azure Files Storage.Issue Details:Symptoms:On my home network (Frontier), I can map Azure file shares on my laptop (Windows 11) as before.On the office network:My Windows 11 laptop cannot access the mapped Azure shares.A different laptop
Hi,I've been reading and tweaking the firewall policy rule to no avail.Made IP lists from official Microsoft web page.Allowed website and application from their official website.Tried with and without SSL InspectionThe policy is put above almost everything else and nothing affect the IP subnet rangeAutopilot won't work (often when choosing Office/365)Nothing is being blocked in FortiAnalyzer except for a few .cabWe're thinking it might be linked to the .cab issue:The DLP is still blocking some .cabauthrootstl.cabdisallowedcertstl.cabpinrulesstl.cabEven if the DLP HTTP-Get is activated or notEven if the file filter for .cab is activated or not. Threat :Action: blocked Threat Direction: incoming Threat Name:data leak by Filter: none Threat Pattern: disallowedcertstl.cab Threat Severity: low Threat Type:Data LeakAny help appreciated.Thank you for your time.
I am currently experiencing this issue-I have connected a phone &behind it a pc to a cisco switch on an ethernet port enforced by fortinac.when i shut & unshut the ethernet port with both the pc & phone connected it stays in a loop.On the switch cli i see fortinac putting the port into admin state down-> applies a dacl -> port moves into correct vlan-> then shuts its down and this happens over & over ,However if i let the phone come up register & thereafter i connect the pc ,its not a problemAnyone experience this?
Is anyone out there using FortiCloud Overlay as a Service? Why do I feel like I'm the only customer. We are replacing our old firewalls with Fortinet, and I'm trying to deploy about a dozen firewalls with the Overlay as a Service connecting the offices via SD-WAN. Unfortunately, the IPSec tunnels at two of the locations (my datacenter and HQ) keep going offline and won't come back. It seems like there's something out of whack with whatever configuration is being pushed from the cloud. No one in support seems to understand the overlay cloud service, and the team they escalate to internally never get back to us. We ran a debug and the cloud service IP addresses aren't responding to the VPN requests. I've blown away the entire config and it works fine for a week or so, and then things start to fall apart again. Seems really unstable.
We are rolling out the FortiClient EMS with an IPsec connection profile to all our users. I have it setup with Azure SAML to perform the authentication, without user intervention. However, sometimes we are noticing that upon reboot the client hangs during the IPsec VPN connection, and as a result it blocks ALL internet access on the device. The FortiClient can't communicate with the EMS Cloud server, and you are unable to open any web pages. The only solution is to reboot or open the EMS client and force a disconnect. Has anyone experienced this? Some users don't have the issue, while others seem to have it more often. (probably because they shutdown/restart more than others) There's no error, and nothing I can see in the logs that is helpful. Thanks.
Hello,I have a FortiGate 60F in transparent mode, behind a MikroTik router. I use port3 as external - connected to the mikrotik router and port4 as internal, which is connected to a mikrotik switch.I followed the official documentation to set the FortiGate in transparent mode, and after that, because I have 12 VLANs set on my MikroTik router, I followed this technical note to setup the VLANs and forwarding domains. I configured the forwarding domains, because without that, as soon I plugged the fortigate into the network, it created a loop.Now with this configuration everything seems to be working fine, but when I try to run a ping from the fortigate, or from the MikroTik to the fortigate's management IP, I get DUP! packets: It is my first time working with a fortinet device, I've read through a lot of the documentation, but I couldn't figure out what the issue is.Thank you in advance for any input.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.