Mark a Best Answer
Fortinet Community
Recently active
This is my first foray into the need for VXLAN and have some questions. My current site has a L3 Aruba switch, which handles my internal VLANs, an egress VLAN connecting to my FortiGate which connects to both a private WAN circuit to my data center (which in turn, provides Internet) and a backup Internet circuit for Internet failover and the IPSEC VPN spoke to hub (data center). Bought new building that we will be moving to, so want to implement VXLAN so I can use the same VLANs and subnets for all the new equipment going in so when we do actually move, it will be an easier transition. So the VXLAN config will be a temporary situation (no more than 6 months is my guess). From a design perspective, my idea is to implement the same low cost Internet "backup" at the new site, but it will be the main Internet connection until time gets closer for the move to add the higher dollar private WAN circuit as the primary. I will establish a IPSEC VPN connection between the two sites dir
Hi Am running Fortinac v7.4.0.0427 (GA) and the Endpoint Compliance doesn't run when a registered host connects back to the network ,or it takes very long to do so ,6+ mins however if i scan the host ,the compliance action is executed .Any idea why this could be happening ?
Hi I want to achieve this :When a registered host is connected ,its first put in isolation vlan until it passes endpoint compliance ,is this possible? I have set the default vlan as isolation ,however when a registered host connects ,its moved from isolation -> production then isolated.Thanks
Dear Fortinet Community. Today I have a very easy and short question. We will buy a Fortianalyzer in the next days. And now our data security guy wanted to know who exactly has access to the data collected on the FortiAnalyzer. We have seen sometimes a bigger packet of dataexchange between the FortiAnalyzer and Fortinet Servers... So we asked ourself. Does our FortiAnalyzer TestVM send data to Fortinet, so that our data will be shared with the manufacturer? Or in another way... Can Fortinet access in any case our FortiAnalyzer and read the data stored on the appliance? However. There is just one qestion :) Can anyone instead of me as Admin can see the data collected by the Analyzer? Any help or hint is very much appreciated. :) With kindest RegardsFortiLover
Dear all,A question about how FortiGate handles the communication with a SCEP server when the CSR is based on elliptic curve.As stated in this FortiGate article [1], a CSR based on elliptic curve can be sent to a SCEP server.In that case, and as specified in the SCEP rfc8894 [2]:"The form of encryption to be applied depends on the capabilities of the recipient's public key. If the key is encryption capable (for example, RSA), then the messageData is encrypted using the recipient's public key with the CMS KeyTransRecipientInfo mechanism. If the key is not encryption capable (for example, DSA or ECDSA), then the messageData is encrypted using the challengePassword with the CMS PasswordRecipientInfo mechanism. "That further says: "Note that some early implementations of this specification dealt with keys that were not encryption capable by omitting the encryption stage, based on the text in Section 3 that indicated that "the EnvelopedData is omitted"My question: when emitting a CSR based
Hi guys. I have an issue with this device. Aleatory, it would work for some days, other days it would not turn on the radios. The logs shows it constantly leaving and joining. Accessed the SSH interface, and got the following log. Every exactly 24 seconds it shows a "signal 11 (Segmentation fault) received". What does it mean? FP221ETF18009026> crash1: 2024-11-25 10:45:23 <05543> $ 8: e5d33000 e0822003 e15b31b6 e28310022: 2024-11-25 10:45:46 <05753> firmware FortiAP-221E v5.04,build437b176,170810 (Release)3: 2024-11-25 10:45:46 <05753> application wtpd4: 2024-11-25 10:45:46 <05753> *** signal 11 (Segmentation fault) received ***5: 2024-11-25 10:45:46 <05753> Register dump:6: 2024-11-25 10:45:46 <05753> r0: 00a47790 r1: 00a47790 r2: 00a5778e r3: 00a577de7: 2024-11-25 10:45:46 <05753> r4: 0023d598 r5: 000000a5 r6: 00000008 r7: 000000008: 2024-11-25 10:45:46 <05753> r8: 00000000 r9: 00000000 r10: b6fe9f7c fp: bead4a2c9: 2
I am having problems when upgrading to the new version of FortiAnalyzer. The database recontruction gets stuck and does not progress. It has been taking the same time for days. This does not allow me to review and collect logs.
Hello experts, I have this issue with my users while using FortiClient:When a domain user's password, configured as a VPN User, expires, FortiClient, despite prompting for a password change, is unable to actually reset it.It reports "Password Field do not match," but upon checking, the fields are identical.
Hi,we have such problem on every webpages with the newest chrome version 131 error appears:ERR_SSL_PROTOCOL_ERROR as I read Chrome implemented any new TLS mechanism in this version:https://chromestatus.com/feature/5257822742249472is any solution for this?
Hello fellow gurus. I am hoping one of you maybe able to help me with a problem I am facing.I just deployed two Azure FortiGate VMs using the market place in a HA acive-passive with ELB/ILB.I am able to get in to the management web interface. When I try to ping 8.8.8.8 from the cli 'exec ping 8.8.8.8' I am getting a 100% loss.I check and I have the static route setup (which is created by default).What else am I missing here? I'm new in Azure so it's probably something simple.Thanks!
Hello Everyone, we have a problem with the configuration of our HA, the HA is well configured and synchronized but the problem is that the master works well, but as soon as there is a problem on the master and we switch to the slave there is no traffic passing through the slave and we lose all access to the internet until the master is restored. a lacp conf has been set up (the master and the slave belong to the same LACP aggregate on the switch side).Initially, when I plugged the ports, they were all UP, but the slave ports went down later after a LACP negotiation I guess. https://docs.fortinet.com/document/fortigate/6.4.15/administration-guide/666376
greetings all, I got the information as following from FortiSwitch, what is an Internal port and the usual reason why it shows so much drops? Port(internal) is Admin up, line protocol is upInterface Type is Pass Through without PHYAddress is E8:ED:D6:51:77:14,MTU 10000 bytes, Encapsulation IEEE 802.3/Ethernet-IIfull-duplex, 1000 Mb/s, link type is autoinput : 13316481778 bytes, 82631689 packets, 0 errors, 481076 drops, 0 oversizes42314 unicasts, 55849479 multicasts, 26739896 broadcasts, 0 unknownsoutput : 252618470 bytes, 1781502 packets, 0 errors, 0 drops, 0 oversizes25319 unicasts, 1754202 multicasts, 1981 broadcasts0 fragments, 0 undersizes, 0 collisions, 0 jabbers thanks you.
We have an issue at our org where some machines have the "free" FortiClient VPN installed on their machine with existing connection profiles to random sites. The issue is that we are pushing FortiClient Zero Trust and during the install process, it removes the free version along with their VPN profiles. Is there a way to find a "backup" stored in the local machine somewhere by default or no? Is there also a way to stop this behavior when the new client gets installed? I doubt there is but I thought I would ask. Thanks. I know you can add custom connection profiles when the Zero Trust version is installed but that doesn't solve my current problem.
Hi, we have a IPSec connection from our main 200F (7.4.4) firewalls to Azure. Users complain about performance so we are checking the connection. We use AES126 256SHA and have 6 networks in P2. We checked package capture and we saw retransmissions so thats why we would like changing MTU. First the MTU, we get through by: ping x.x.x.x -f -l 1280, so I thought 1280 + 28 = 1308 should be best MTU config, correct? Changing the MTU for the VPN interface would affect all connections in Phase2? Thanks!
A somewhat special problem: Background:The clicks on our homepage are to be analysed. Clicks that are made from the office (fixed IP address) can be filtered out so that they do not distort the result. However, some employees work from home and there are many different IP addresses and these cannot be filtered out. I would therefore like to be able to specify in the VPN connection that calls to a specific domain do not go via the employee's local IP, but via the VPN connection and then via our fixed IP. This would also filter out these clicks via the fixed IP. Is that possible?
Hey,We are using a Forti 100F as a firewall and have several FortiAP 231F in different locations. These are all on the same network and directly connected. Now the question is, is it possible to use the "locate wifi clients when not connected" feature without an extra server and without using Aeroscout (because we don't want to use another server for that). If so, is there any documentation on what needs to be done to use this feature, or does it just need to be enabled? Another question would be where these disconnected clients are listed and how to distinguish them from the "normal" connected clients.Thanks for your help!
We currently use passive authentication for web filtering using FSSO with a collector agent installed on a local domain controller. We are finding more and more situations where local domain controllers are being decomissioned in favour of Azure based AD and wish to know if passive authentication is supported in this way. Our only resource to go off is https://docs.fortinet.com/document/fortigate/7.2.5/administration-guide/33053 but as we haven't attempted before, perhaps someone who has can shout up and advise whether or not this is the answer, or advise whether or not passive authentication is supported. Thanks in advance!
hi,i was trying out 'worflow' in FMG and already had a few session list/history.i can't seem to remove/purge old session ID, so i just disable workspace and re-enable it back to clear it.can the old session be manually removed from the list so that only new session will appear and be approved?
I've set up an IPSenc VPN between a head office and a branch office, two F60 fortigates, but we can't access the head office network folders, when I put DNS on the network card it works perfectly, without DNS on the card I can ping and everything, is there anything I can do so that I don't have to put DNS on the network card?
I'm curious what people are doing for a NOC view for your Fortinet infrastructure? We're migrating to Fortinet in January, and we would like to display the current bandwidth usage for our SD-WAN infrastructure in our IT area. I know there are various tools like PTRG, Solarwinds Netflow, or even exporting to Grafana, but I'm curious how the seasoned vets of Fortinet do this. Does Fortinet offer something or do you have to use something more?Thanks in advance everyone
Hi,I have Fortigate 40F and I need to set 2 LAN and WLAN networks. LAN 1 and WAN 1 should be on the same subnet and same LAN2, WAN2.LAN 1: VLAN 101 (e.g. 192.168.1.0/24)LAN 2: VLAN 102 (e.g. 192.168.2.0/24)WLAN 1: VLAN 101WLAN 2: VLAN 102Port A - LAN 2Port 1 - LAN 1Port 2 - AP 1 (Ubiquity UAC-AC-Pro)Port 3 - AP 2 (Ubiquity UAC-AC-Pro)In normal environment I would add Port 1 to VLAN 101, Port 2 and 3 to VLANs 101, 102 and Port A to VLAN 102. I would set IPs for VLAN 101 and 102 (GWs for both VLANs), but not sure how to set this config on Fortigate. Would you advice?
Hello, We experience a weird issue with some of our users. We use FortiToken to enable 2FA, but sometimes user get a 'server unreachable' error message when approving their login attempt. Our FortiGate is available, and we're able to connect to it without any problems.Whenever we remove the current FortiToken and re-invite the user (by scanning a new QR code) the problem is temporarily resolved. Does anyone experience the same and/or does anyone know how to solve this?We're have a FortiGate 100F running firmware 7.2.5 1517.
I have 1 RADIUS group that has 3 Microsoft NPS server IPs (primary/secondary/tertiary). through the GUI I have successful authentication to the Primary and am able to use my test user in the associated AD group. the secondary fails, and I'm unsure of the tertiary due to my issue with this command to help me narrow things down server by server: #diagnose test authserver radius-direct <server IP> <port> <PSK> <auth protocol> <username> <password> when using this command in parallel with debug flow - it is using a source IP of the default mgmt 192.168.1.99 IP (the interface is disabled) - I then set the IP on the disabled interface to 0.0.0.0/0. the new debug shows the system using a 169.x.x.x address.this is resulting in failed attempts as these are not the trusted IPs the NPS server is expecting... when debugging to watch the flow of testing the credentials against the primary server via the GUI test button or
I have Ipsec vpn between Cisco Router and Fortigate 100F Ipsec phase 1and2 are up, I have subinterface on Fortigate firewall. I do ping fortigate firewall subinterface ip over ipsec tunnel but ping working after some times does not work what is problem? I can not di ping alla subinterface ip sometimes ping working after stop ping I dont see any error .policy router is normall
Hello, On my Fortigate 100F I would like to create an admin user with following profiles:- Able to change the admin users password- Able to update the SSH key of users But I didn't find the possibilities to do in system/admin profiles.Thanks.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.