Mark a Best Answer
Fortinet Community
Recently active
Hello All, Hope you are all doing well, I'm facing an issue today while working on IPSEC on Fortigate VM, When I try to create a IPSec VPN tunnel using the wizard this error show up " 61: Input not as expected." as a workaround I create it mannuly to avoid this error but on the Phase2 of VPN Tunnel the fortigate keep loading with out saving the configuration ( screen attached ) +The OS info : v7.6.0 build3401+ Config : 2CPU, 2GB RAM Do you have any recommandation on that ? Regards,Karim
I'm having some troble getting some messages over the size of 10MB on my server. I've changed the max message size on the domain, session profile and content profile to 34MB. However, every time that I tried to receive a test email over 10MB on size, the message bounces without any further information and I have no related logs on my Fortimail. Messages under 10MB are received and logged correctly on the monitor secition, I also tried to configure the max message size on the system GUI and through CLI but the GUI option is nowhere to be seen and the "set max-message-size" command is not being recognized either.
Hi,I have an FG61F and have downgraded the firmware from FGT61F-7.2.6-FW-build1575 to FGT_61F-v6-build6188. After the downgrade, I am unable to access the Fortigate GUI page, and no status LED lights up when I connect to the Fortigate port. What should I do to restore the device to Firmware Version 7?
I configured my FortiGate with the CLI command as below: ---config system adminedit adminset two-factor email--- Does this affect ssh log-in? If so, is there any solution to divide ssh authentication and http authentication? thank you,
I have a FGT61F running 7.4.3 at the home office and another identical in a remote office. Home office has the static IP. We had a long-term power outage over the weekend and once it was restored the tunnel will not come back up. I have rebooted the FGTs and modems on both ends. In logs I see action-negotiate and stats-success on the home office every 30 seconds and delete_phase1_sa on the remote office. I tried to flush the tunnel from both ends and no luck. Any ideas? We have had power failures in the past and never had this issue. Thanks for the help.
Fortinet is working at my place looks good the equipment is nice. I teeter from one idea to another as I look through the interface. I had to use YouTube to get me through hooking-up the appliance. It works good, I can pause backup and go forward through the videos. Enhanced web and telephone support was necessary to get me logged into the dashboard. I could not reset the devise when advised over the phone. Support told me I did not have and support subscriptions. I mentioned it should go online without a subscription so I was offered to reset my device with a phone call. I could not hear and the call dropped three to four times. It was time to gave it a break for months to realize the reset button has to be hit for a long time to get the device to restart. Support told me this after I purchased the supports subscription for two of my devises. Knowing how to reset the devises made all the difference in the world for setting-up the FortiGate appliance. The login is n
Hi, We are trying to setup to setup another SSL VPN to our FortiGate's.I was wondering if it is possible to have two ssl vpn interface and two public ips?We want to setup two azurer SAML entra ID's for the VPN's.TIA :)
Until now we’ve used SSL vpn with SAML authentication with Microsofts Entra ID as IDP. However since we want to stop using SSL VPN due to the deprecation, I’m wondering what setup makes most sense when fitting the requirement of entra ID as IDP with SAML. What’s your experience with IPsec for forticlient and with SAML, and how is the deployment? So far we’ve used intune app for a preconfigured forticlient for SSL VPN https://vidmate.onl/ .
Hi I have issue when i already authenticated myself in Captive Portal but I cant connect to the internet. on the browser says error Your connection is not Private; NET: ERR_CERT_COMMON_NAME_INVALID. but if i disable the captive portal, i can open the internet with no problem. Could you please advise?
Hi All, Error Message: Connection with License Server Failed I have two subnet configured on my firewall fortigate 60F. SAP B1 was configured on the 172.18.10.x subnet and users are coming from subnet 172.18.10.x. We can do ping and connect to the server, but we are not able to log in as we get the error message above. anyone have same problem?
Hi all,I have a Fortigate (7.4.4) with a discovered FortiExtender (7.4.3) in WAN extension mode added to it. From the FortiExtender, I can ping anywhere on the internet. I have a /30 link between it (Port1) and the Fortigate (Port A), and I can ping it's LAN address from the Fortigate, and vise versa.I cannot for the life of me see as to how to get it Online, or as to why it is showing as Offline. On the Fortigate, I have Fabric allowed. When I do a diag sniffer packet on port 5246, I'm not seeing anything at allAny thoughts or pointers as to where to check next ?
I have this problem with Fortinac. I have a port and computer A is plugged into this port. When computer B is plugged into the same port, both computer A and B appear under the port even though computer A is not plugged in. Even though I deleted computer A, it is still under the port. The device is quarantined because there is more than one device. Fortiswitch can be used.
Hello. Fortigate has versions 7.0.15 Fortiswitch 7.4.2. They are interconnected with Fortlink. My problem is the following. I plug machine A into any port of Fortiswitch. Then I unplug this machine and plug machine B into the port. When I check in Fortigate, both machine A and B appear on the port when only machine B should appear. What is the reason for this?
getting below error on FAC 2024-11-24T17:02:41.605283+05:30 NIC-FAC-MC radiusd[7644]: (25771) facauth: Remote ldap user 'manoj': NULL password is not allowed2024-11-24T17:02:41.605289+05:30 NIC-FAC-MC radiusd[7644]: (25771) facauth: Remote LDAP user authentication failed2024-11-24T17:02:41.605799+05:30 NIC-FAC-MC radiusd[7644]: (25771) facauth: Updated auth log 'manoj': Remote LDAP user authentication(chap) with SMS/email dual token failed: invalid password USER IS remote user AD user and we are using chap on the FGT acting as a client
Hello everyone, I’m experiencing an issue and would appreciate any suggestions: I’m using Windows 11, but when I run a "Vulnerability Scan," it detects errors related to Windows Server, which is clearly not my operating system. The recommended security patches are already installed via Windows Update. Any advice?P.S.: The "Auto-Patch" option doesn’t resolve the issue either.
Hello, I have some issues with dns forwarding between to fortigates (601E and 601F) over a site to site VPN tunnel.In general the VPN is working great and there are no connectivity issues at all.Main-Site (FG 601F) has some internal DNS zones with entries and some of them forward to other DNS servers. The DNS service is enabled on all interfaces and each client on main site gets all dns entries of Main-FG as it should.On site B (FG 601E) I tried to create the same DNS zones as on Main site and entered the Tunnel IP of Main-FG as DNS forwarder. If a client on Site B tries to query anything from those zones from FG-B it gets no answer. If the client tries to directly query the Tunnel IP of Main-FG it works, but that's not what I want. Does anyone has an idea what could be wrong? I already experimented with source-ip and stuff but it didn't help. Both Fortigates have FW 7.4. Greetings,daniels7
We have fortigate 201F in a HA cluster, there is a Proxy Policy that uses a schedule to filter traffic based on the time of the day. The policy was working alright, but when we upgraded v7.4.5 build2702 it has stopped working. Is there a change that affects schedules in the new version? and how do i check if a configured schedule is currently active or inactive?
Looking for a sassy way to secure your distributed workforce? Well, look no further — Fortinet FortiSASE (yes, that's Forti-sassy) has arrived! This cutting-edge connector adds some serious attitude to your cybersecurity arsenal by extending enterprise-grade security to users wherever they are. Whether you're in the office, working remotely, or sipping a latte at your favorite café, FortiSASE has your back (and your network). But that's not all! Here's a quick peek at the latest additions making waves in FortiSOAR: Our Outbreak Response packs are on high alert, tackling critical vulnerabilities like the Palo Alto Networks Management Interface Attack and the Progress Kemp LoadMaster OS Command Injection Vulnerability. Because cyberthreats don't take coffee breaks, and neither do we. CylancePROTECT is stepping up to keep malware at bay with AI-driven endpoint security. It's like having a cybersecurity crystal ball but cooler. Infoblox DDI brings seamless DNS, DHCP, and IPA
Hello guys!Override FortiGate block-intra vlan traffic.Is it possible to override block-intra vlan I have two client on the same subnet need to talk with each other. But in the same time I will like to block anything else to reach each other is it possible to do so. Thank you
hi everyone. i need to configure ssl vpn with ldap authentification.is it obliged to generate a certificate from my winfows server, or use the buikt in certificate of fortigate or buy a certificate for may vpn connection.please help
Hello,i'am a new user in fortigate world :) with FG-51EI read some tuto to learn how it works, and i'm stuck with routing between vdom.it won't work :'(i'm french, and my isp provider is named free.To be able to watch tv with their player, it have to get an IPV6 SLAAC without DHCPv6. unfortunately, i don't know how to do that with fortigate. (it's not the subjet but if someone can help me for this point, i will be very happy )So i create a root vdom in transparent mode, with member interface wan 1, and port 1. my tv player works without problem.now, i create another "test" vdom in NAT mode, for testing, homelab. the interface member are the others portsi wish to link this nat vdom with the root transparent vdom, and .... no way to make it works :'(i miss something but i don't know what.I relied on these links, for helpinghttp://socpuppet.blogspot.com/2014/09/a-meshed-vdom-transparent-using-inter.htmlhttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Connect-2-Transparent-VDOMs-w
Hi,we have a customer with a FortiWLC-50DWhen we try to set some options, for example security profiles, system ask us a login.Both our admin (level 15) accounts doesn't work.Is there any other root account? Can we solve it via CLI?Thanks
Hi Everyone, We have a Wi-Fi setup with a FortiWLC 200D controller and approximately 50 FortiAP 822i access points. Currently, we’re experiencing significant issues with Wi-Fi stability. When connected to an SSID, the connection is highly unstable. On devices like Windows PCs or Android phones, the Wi-Fi signal icon frequently fluctuates between full connection and a single bar. This issue affects all available SSIDs. Here’s what we’ve tried so far:Changed the connection type between the access points and the controller from Layer 2 to Layer 3.Conducted a Wi-Fi scan with a professional company. They reported that the Wi-Fi itself appeared fine and suggested the issue might lie elsewhere in the network. I also investigated the network infrastructure, including switches and firewalls, but found no apparent problems.The FortiWLC and APs are running on version 8.4-8. I’ve also checked the debug/diagnose section on the WLC but didn’t notice anything unusual. Does anyone
Question on Radius policy, I have a FortiGate connected to a FAC for 2 sets of users (both using the same LDAP source) One set is using a policy, that requires chained authentication, (RSA Token server) and that policy is at the top and it works fine, I added a second policy, as I want WIFI users to authenticate with AD if they are in the WIFI Group, so I created a 2nd policy and placed it above, with the a matching radius attribute of SSID = "MYSSID" My question is, when someone connects to this SSID, does it send this radius attribute? or do I have to tell the gate to send this attribute ? I cant test this from the Gate, as you can add radius attributes in the "test autheserver radius etc etc" or can you?
Hello, We have virtual Fortigate Deployed in VMWARE, We are trying to configure Dial-up VPN with cert authentication, but we get "XAUTH authentication failed" error, also in debug we see "fnbamd_cert_auth_copy_cert_status-Leaf cert status is unchecked" What it can be and how fix?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.