Mark a Best Answer
Fortinet Community
Recently active
Hello, On my Fortigate 100F I would like to create an admin user with following profiles:- Able to change the admin users password- Able to update the SSH key of users But I didn't find the possibilities to do in system/admin profiles.Thanks.
I integrate Starlink Maritine antennas on Yachts.At the time of delivery of the Yacht, the Starlink antenna is not activated.The antenna is then activated months later.I need to make a report that demonstrates the correct functioning of the antenna (I don't want advice on how to prove if it works, I want to do it with the Starlink app).With the Peplink devices that we use, by implementing the following rule it is possible to reach the antenna via the Starlink App even if it is not activated:- Outbound policy – ​​IP Address 192.168. 100.1 – Enforced WAN 1 (where Starlink is connected).Installations on Yachts include an antenna, power supply and direct connection to the Fortinet WAN.The Starlink router is not present.I tried with a static route 192.168.100.1/255.255.255.255 but it doesn't work. Is it possible to instruct a Fortinet so that when a user is connected via the App he can reach the antenna even if it is not active?I hope I was clear.I'm waiting for your suggestions
Hello,i'm configuring IPv6 in my network. I have the FortiGate (7.4.5) configured with a DNS server as a secondary for all my Active Directory zones. With IPv4 this is working without problems even with the reverse zones. Now i'm trying the same with the IPv6 reverse zone, but the GUI is telling me that the name is to long. I havn't try in CLI. And when configuring a slave DNS zone, why can i only enter a IPv4 master address? Looks like IPv6 is in the DNS server configuration not completely implemented. Or is this only a GUI problem and all can be done in CLI? Kind regardsStefan
Hello EMS adminsEMS 7.4.1 and FOS 7.2.10.When I put EMS VM in a VLAN attached to FGT, the clients' tags are updated correctly, and we can see the tags of each connected client under Policy & Objects > ZTNA > ZTNA Tags.However when I put a firewall between my FG and the EMS, the fabric connector connects successfully and we can see the shared tags, but we can't see the tags of the connected clients anymore.Note that I opened the required ports from the FGT to EMS, like 8013, 8015 and 443.Does it mean it is a requirement to put EMS in a VLAN directly connected to FG, or did I miss something?
I'm trying to configure my Fortigate 30E to use dual WAN ports. I've set up LAN1 as a WAN port with the role changed to WAN and DHCP enabled, which it gets from the Starlink router. My primary link is from my ISP.The problem is, whenever I plug in the secondary Starlink WAN port, the internet drops entirely. I've already configured the policies and static route, but I can't figure out why it's behaving like this.Any ideas or suggestions https://omegle.onl/ ? Thanks in advance!
Hello,A user have a new PC that is ARM64 based so Forticlient does not work. I have found the client on the MS store. He does connect but will be dropped after 20-30 sec.I also tried from my PC where is worked just fine (same MS client and user creds). I do not get dropped. My PC is a regular x64 basedI tried disabling IPv6 on the newer PCs NICs, but no dice. Any suggestions?
Hello,I configured a VPN in IKE to connected any host on the network.All works with all Windows Laptop, but we've one MAC and on this MAC, with the same configuration on FortiVPN Client, but the MAC won't be connected and failed on P2.Anyone have the same issue ? ike V=root:0:User_Remote_VPN_2:115:51105: peer proposal is: peer:0:192.168.6.3-192.168.6.3:0, me:0:0.0.0.0-255.255.255.255:0ike V=root:0:User_Remote_VPN_2:115:Test:51105: tryingike V=root:0:User_Remote_VPN_2:115:Test:51105: matched phase2ike V=root:0:User_Remote_VPN_2:115:Test:51105: dynamic clientike V=root:0:User_Remote_VPN_2:115:Test:51105: my proposal:ike V=root:0:User_Remote_VPN_2:115:Test:51105: proposal id = 1:ike V=root:0:User_Remote_VPN_2:115:Test:51105: protocol id = IPSEC_ESP:ike V=root:0:User_Remote_VPN_2:115:Test:51105: PFS DH group = 14ike V=root:0:User_Remote_VPN_2:115:Test:51105: trans_id = ESP_DESike V=root:0:User_Remote_VPN_2:115:Test:51105: encapsulation = ENCAPSULATION_MODE_TUNNELike V=root:0:User_Remo
I have a very simple setup. One foetigate with 2 interface lan - 192.168.2.1/24 and wan with ip for example - 172.34.1.1. For reaching internet from lan I have created the firewall policy with source nat. It works. I want to test it from foetigate's own ip. When I do - Execute ping-options source 192.168.2.1 Execute ping 8.8.8.8 I am getting no reply. From debug and packet capture seeing that source nat is not applied. Is it intended by design that foetigate's own ip is excluded from nat? Or I am missing something.
I've created a port mirror using the cli and when I plug it into another switch that I want to aggregate the span ports to I get a switching loop. Switching-packet is disabled so I'm unsure why its trying to route traffic through the other switch, any idea?
I have a Fortigate 3700 with single mode fiber QSFP's installed. Several of those QSFP ports are configured in aggregates.When I take the aggregate interface down, the member links stay up. This is a problem, because the Fortigates are in HA pairs and link-failed-signal is enabled which is supposed to take down the HA monitored interfaces (on the primary that is moving to secondary mode) when a failover occurs. However, none of the aggregate member interfaces go down. Only "normal" interfaces go down. I have tested aggregate behavior on a 60E HA pair and the aggregate member interfaces (copper gig ports) go down when an aggregate interface is taken down. This is the expected behavior. Is this known behavior for the 3700? Why does the 3700 not take down the member interfaces when an aggregate is taken down? The 3700 is running 7.2.8.
Hi,for some strange reason: 1) the fortiview website monitor is not resolving the IPs into the relative domain name2) I am only able to view for "now" all other options don't work ( 1hr, 24 hrs, etc..) looking around I have created my local DNS servers in thinking that I needed a reverse lookup?therefore I created 2 local DNS using 8.8.8.8 and 8.8.4.4 with " A" records and I created also 2 "PTR" records off of each IP. therefore I have 4 records. question 1: is it correct to use google IPs for my local DNS?question 2: is it correct to use the relative "PTR" records?question 3: seems none of this is working to get me the domain names in the fortiview website monitor therefore something is wrong. thank you
Hii can't finish the bgp to gcp configuration, basically i have the vpn up, one tunnel all ok it works but if i do cloud router and bgp i can't get it up. if i configure bgp ip and peer ip they are all ok asn as well, but they don't show up, i have the wan1 with gcp tunnel which is called gcplab, but the 169.x.x.2 ip of the /30 i have to configure it somewhere?in gcp i have the other ip 169.x.x.x.1do i have to put firewall rules on fortigate side? because i can't find any documentation on how to proceed?thank you all for the help
HI,I have configured SSL Web mode VPN. I want http/https bookmark must be open in Internet Explorer as local website is compatible only with IE how to do it, please suggest Regards,FAhmad
Hello,I can't find any document about FG-200E EOL.I know it end of sale but I need to know about end of support date and it has not exited at the product life cycle.Thanks.
I would like to automatically connect to the VPN network, but I do not want to use FortiClient. I have FortiGate with remote access set up, and I can connect normally via FortiClient. Is there an option in Windows 10 and 11 to connect using the default Windows settings, under Network & Internet -> VPN? VPN configuration is attached. I know, that in Microsoft Store is Forticklient, but only for SSL not IPSec.
Dear Fortinet TAC Support,I am currently implementing EAP-TLS authentication in our company’s network. Our environment consists of Domain Joined PCs, IP Phones, and Printers. I have configured 802.1x with MAC Authentication Bypass (MAB) for non-EAP-capable devices. The 802.1x policy configuration is below. config switch-controller security-policy 802-1X edit "FNAC-802-1X" set security-mode 802.1X-mac-based set user-group "FNAC-Switch" set mac-auth-bypass enable set open-auth disable set eap-passthru enable set eap-auto-untagged-vlans enable set guest-vlan disable set auth-fail-vlan enable set auth-fail-vlan-id "NAC_AG_Dead_End" set framevid-apply enable set radius-timeout-overwrite disable set authserver-timeout-vlan enable set authserver-timeout-vlanid "AG_Corp_WiFi" set authserver-timeout-tagged disable set dacl disable next end Here is the current
Hello everyone,Could you please advise which latest firmware version is recommended/stable for FortiWeb 400F. Thanks & Best RegardsMohamed F.
Dear Team, We have been exploring a solution to enable GRE multicast traffic to flow simultaneously to two FortiGate firewalls. After discussing with our team and consulting AWS Support, it has been confirmed that this configuration is feasible and supported on AWS infrastructure. AWS has assured us that there are no blockers on their side that would cause traffic disruption when sending GRE multicast traffic to both firewalls simultaneously. However, as we are not using AWS VPN services, AWS was unable to provide any documentation specific to FortiGate configurations for this use case. Therefore, we would greatly appreciate your guidance on configuring FortiGate firewalls to handle GRE multicast traffic in this scenario. Specifically, if you have any documentation, best practices, or technical configurations for setting up such a system, please share them with us. Looking forward to your assistance. Regards,Tanish Jain
Hi, Please see the below diagram which shows connection for fortigate SDWAN. My question is after adding two Cisco ASR1K in front of Fortigate, what special configuration do we have to add so that we can let the fortigate SDWAN work well? Thanks
Hi there, kindly please help.I've created policy, with setting:- enable NAT- enable web filter, with web filter's setting: - restrict youtube access- enable fortigate category based filter using default setting. I try to every computers, they can access youtube via web browser. I'm using FG30E with firmware v6.0.11 build0387 (GA). and network topology is:Internet - Fortigate - Wifi Router - client. try to connect from fortigate to LAN port or Internet Port on wifi router, still get same result, client can access youtube. kindly please help how to block access youtube effectively.moreover, both from web browser or from application. thank you
Hi!in section "Checking FortiManager databases" of "FortiManager Upgrade Guide", I see: "Before running integrity check commands, ensure ... no objects are locked." but does not say how to achieve this if there are many ADOMs, many Devices, many Policy Packages and many Objects. What's Fortinet’s recommendation for achieving this?Thanks!
I have two fortigates with a site-to-site VPN connection. This works fine, and is configured like this: 192.168.10.0/24->Fortigate 1->WAN->Internet->WAN->Fortigate 2->192.168.20.0/24 My question is, can a pool be created on Fortigate 1, say a portion of the 192.168.10.0/24 network, for example, 192.168.10.200-250, that incoming connections from remote network 192.168.20.0/24 get mapped to? End goal is to make devices on 192.168.20.0/24 appear to the server on 192.168.10.0/24 that they are on the same subnet as the server. Thanks, -John
Using the menu "VPN Location Map" does show me a nice overview of the currently connected VPN connections (IPSEC, SSL VPN). However, the locations of the fortigate are most of the time somewhere in the Gulf of Guniea (0°S, 0°E). The physical location of all our fortigates is configured in FortiCloud (product details) with the address (street, ZIP, town, etc.). I did not find a way to set the device location in the fortigate GUI, nor via CLI. I checked with dia "geoip geoip-query <IP>" on each fortigate it's own location and it shows a somewhat accurate location (sometimes off by a lot, based on the ISP). So, I have several questions:How does the fortigate determine it's own location used for the VPN location map? From the location configuration in FortiCloud? (difficult, if not impossible)Via geo-ip query? (most likely)If yes, which IP is used in a milti VDOM environment with several WAN IP's per VDOM?Note: If I use "dia geoip geoip-query <my-wan-ip>
I've configured a policy with SSL Deep Inspection for my company and installed the Fortigate CA certificate on our devices in order to now be shown the certificate warning. However (on both mac and windows devices) when using Firefox it does seem to work correctly and the certificate shown by the browser is the Fortigate's, though when using either Chrome or Edge the certificates shown in the browser.I have even a problem with web filtering I'm blocking social media and still have access to all social media Did anyone have an idea what is the problem? Thank you
Hi guys, i got some problem and i cant figure this out. I have a virtual machine on server which will be a mail server in future. Ive created a VIP on Forti that is internal address mapped to public. It pings and is visible from outside but services are not responding at public address f.e. SSH port 25.I also added even port forwarding for all ports 1-65535 and it still doesnt answer. Anyone got an idea what to do? I can log in to machine from our internal network through SSH but i cant do the same when i try to log in to public address
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.