Mark a Best Answer
Fortinet Community
Recently active
Hello, I have a forti60f, fortios 7.0.16 build 0667, since I updated the firmware every time it wants to update the fortiguard bases it crash,Sometimes in the logs I saw this messages-Kernel enters memory conserve mode.-The system has activated session fail mode. Without network, without internet and we have to restart it.How can I update the bases without the forti crash?
Can someone share FAC Upgrade (Path) details
I need to setup a VIP on my Fortinet 101F firewall (FortiOS 7.0.16) that provides SAML authentication in my Azure environment (Azure should play the role of Identity Provider), is it possible to create such an inbound policy using the firewall I have?
I've had this same problem since I've had FortiClient installations managed by EMS (6.0.4.0158) and I don't know if I'm doing something wrong, or this is just expected behavior. Over the holiday break I assigned a deployment package to the profiles for most computers with the thought they would be upgraded by the time we got back. That didn't happen, out of about 75 desktops, which are usually left powered on, only 12 upgraded and most of those are ones I upgraded before the break while testing to upgrade. In EMS most of the PCs state "Endpoint Notified", but if you go to the actual computer there is no message to begin the installation - and as far as I know the deployment settings shouldn't require manual user input so I don't understand why they aren't getting upgraded. I've always had problems with getting EMS to successfully upgrade FortiClient. It doesn't help that there are no real helpful log messages to help determine why a client didn't get the up
I'm facing issue while accessing the sec boxI tried taking the direct mgmt connection but im not able to ping nor access the sec fgt though the primary box works fine
Hello,I have several RADIUS confs serving several WiFi networks auth.I'd like to have a status return of these radius server using SNMP, but I don't find anything about this in the MIB files.Do you knwo how I can do this ?The goal is to monitor RADIUS availability in Zabbix solution. ThanksNico
Hello, We are on EMS 7.4Forticlient on 7.4.1. We have some machines that occasionally cant connect to SSL vpn. When they hit connect in the Remote access, nothing happens. Our connection is set to use external browser for saml auth and normally it opens edge and authenticates and vpn connects, but when they are having issue browser doesn't open and nothing happens. I have tried setting up a new profile and unticked the use of external browser for auth, still it doesn't bring up the native FortiClient login window for auth, it just sits there, restart doesn't fix, have already tried reinstalling and it keeps reoccurring. The only thing i can find in the fortivpn.log is this error, I can't find anything on web relating to this, does anyone have any idea about this ?[8308:8312] [FortiVPN 1171 warning] fortivpn::StateMachine::HandlePreflight_EnvironmentCompliance environment does not permit VPN connections: Power is suspending.
is there any limit on the IP address that I can used for ipsec site-to-site tunnels from fortinet firewall to 3rd party firewall like in AWS cloud.currently we have site-to-site ipsec using 172.xx.xx.xx/16 as our MPLS network are all in the range 172.16.0.0 to 172.32.0.0/16.Can we do IP subnet out of this range?
Hi We've been having spotty internet connectivity since adding a 4G interface ( a Teltonika device in pass-through mode) to the SD-WAN on our 200E running 7.2.10. The three fibre interfaces in the SD-WAN are only running 20-30 % utilization generally, and the 4G is weighted as a last resort. The only traffic I see on the 4G is the SD-WAN SLA targets. The 4G does work well enough when I add a SD-WAN rule to force a device to use it. I came across this post saying to not use any-any in SD-WAN rules, and not to use the SD-WAN interface as a default route in heterogenous environments. We did have an any-any rule, that was an easy fix, but regarding the routing, would a zone consisting of 3 fibre connections with different ISPs and a single 4G connection be considered heterogenous? Should I instead be adding a default route for each SD-WAN zone member interface? I can't add multiple interfaces to a single default rule as per the above post.
I'm doing an exchange program and I use Forticlient VPN to connect to the network of the institution where I study in my home country. It works normally on my laptop with a Windows OS, but when I use it on the computer in the lab, which is Linux, it doesn't work. I don't think the problem is the network or that I'm in a different country because I use the same network with my laptop. We formatted the lab's computer so that I could use it and installed the Kubuntu 22.04 LTS distribution. I installed Forticlient VPN, and when i tried to connect to the network it wouldn't leave the “connecting” status. I searched on the internet and saw that other people also had problems with this Linux distribution to connect to Forticlient VPN and that possibly the problem was the Kubuntu uses KDE. We formatted the computer again, this time using Linux Mint 21.3 (Virginia) and with that I was able to connect to the network but I can't browse the internet. The measurements are 0.4 Kb sent and
I have purchased a new Microsoft Surface Pro X and the Forticlient agent and application will not install. Can someone give me guidance on how to get it installed or if they are working on developing support for ARM processors?
Hello, My use-case:I have deployed the FortiGate NVAs in my vWAN Hub via the Azure Marketplace as prescribed here.I want to use Azure Routing Policies as prescribed here. I don't want to have to manage UDRs if possible.I want to use the NVAs as a Firewall only (for now).I have the hub's VNet and the spoke's VNet(s) connected to the VWan Hub. My two questions relate to the Azure side of things in terms of NVA capabilities:Can I send all internet-bound traffic through the NVAs (and potentially filter that traffic)? When I set up that routing policy in Azure, I lose outbound connectivity. Is it a limitation, or perhaps a mis-configuration on the NVAs?When I enable the private traffic policy through the VNAs, I lose connectivity between the hub and spokes. Is the fact they're all connected to the VWan Hub; but they need to be peered to the hub's VNet instead? Can I manage traffic from one subnet to another subnet in the same VNet? Thank You
In my environment, I have some endpoints that had FortiClient installed and were managed by EMS. From there, they retrieved the necessary VPN configurations to connect to the corporation's servers. The users lost their license because they were not seen for a period longer than what is defined in EMS Settings > EMS license timeout. As a result, they are no longer being managed/monitored by FortiEMS. Is there any way to block these users' access to the VPN? Or force them to rejoin EMS?
I have 10 VDOMs and want to assign one VMAC to 5 VDOMs and VMAC2 to other 5. So that when they communicate with internet firewall it appears to be a different firewall.Also, if that's possible then how can I make VMAC1 VDOMs communicate with VMAC2 Vdoms? Thanks,Kevin
I've got a couple of VDOMs set up using a shared internet connection through Root. Root has to have firewall policies to allow/foward/nat the traffic from the VDOMs to the internet. I will have the security profiles implemented at the individual VDOM level so does it make any sense to have the same security profiles enabled on the Root VDOM firewall rules? Seems to me like it would just be wasting system resources. Basically would be checking traffic that's already been checked. Thoughts? I'm thinking no security profiles at the Root VDOM, just rely on the individual VDOMs security profiles.
We are currently using FortiClient EMS (Endpoint Management Server) version 7.2.5, with clients running version 7.2.4. The clients are linked with the EMS, and the hostname (user) on one of the clients was recently changed. While the change is correctly reflected in the OS, the EMS still displays the information as it was when initially registered and does not update it.We are managing around 50 devices, but even after searching the database, I couldn’t identify where the relevant information is stored.Is there any solution to this issue?We are not using an AD server and instead have configured each client PC to connect to the EMS using their IP addresses.
Hello, is there a way to generally detect emails with Forti Sandbox Viruses in FortiMail logs?
how to upgrade FAC in HA
FORTIMANAGER UPGRADE PROCESS
The customer wants to configure Microsoft Entra ID in FortiClient EMS while using Azure AD Connect to synchronize users. They currently have on-premises Active Directory integrated with EMS for user synchronization. Can both On-Premises AD and Microsoft Entra ID be used simultaneously in FortiEMS, with specific endpoint policies assigned to users from Entra ID and others to users from on-premises AD
Since upgrading our EMS server to 7.2.5 and our clients to FC 7.2.5, the clients Web Filter, Video Filter, Vulnerability, and System Events no longer populate in EMS at all. These events don't update under the Endpoint Views for the clients and therefore the Vulnerability Dashboard does not show any information for detected Vulnerabilities either. If you check the clients, they are definitely logging these events and, they are just no longer being populated in EMS. I've checked every setting in EMS and on the Client configurations and I can not find out what is breaking this. I've confirmed that the necessary ports are still open and that there are no filters in place to prevent them from showing in EMS. The clients are still successfully updating everything else in EMS just not the event info. Anyone else come across this and have a fix?
Hi there, I have FG60D with no license. since this product already end of life support.I want to use this firewall as basic firewall with:1. restrict user from certain port, that only can access internet to exact address.2. use antivirus with installed latest definition3. use as VPN IPSEC between other FG60D or other client. I've tried to make policy, activate antivirus and web filter policy with create custom profile.custom profile has been set:- disable fortigate category based.- activate web url rule, and add some address, with parameter wildcard, allow. and at the bottom rule box, I set * , blocked.- nat on then I try, all client can't access internet, until i disable web filter. kindly please help:1. can we use old fortigate without license for basic firewall, as above?2. why my problem occur, client can't connect internet? thank you-
Hi EMS adminsEMS 7.4.1. I want to change the IP address of the VM.Can I just change it at Linux level? Will EMS work properly after that? Or is any extra change required in EMS config?
HelloIn some cases I noticed the temporary license expires about 5 to 10 days before time. I mean instead of expiring after 60 days it expires after 50 or 55 days.I've seen this behavior two times, one on a FortiWeb an one other on a FortiMail.Did anyone have the same issue?Any idea what can be the cause?
Hello everyone, i working on new job and there is FortiGate 100F (i`am new to fortios) Users pass captive portal authorization for internet access, but Security mode on Lan Interface is disabled,also didn't find anything at config. FortiOS cookbook shows that captive portal configurate at Interfaces, where another places i can find current settings of captive portal? FortiOS 6.2.16 FortiGate #FortiOS 6.2.12
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.