Mark a Best Answer
Fortinet Community
Recently active
I've configured a policy with SSL Deep Inspection for my company and installed the Fortigate CA certificate on our devices in order to now be shown the certificate warning. However (on both mac and windows devices) when using Firefox it does seem to work correctly and the certificate shown by the browser is the Fortigate's, though when using either Chrome or Edge the certificates shown in the browser.I have even a problem with web filtering I'm blocking social media and still have access to all social media Did anyone have an idea what is the problem? Thank you
Hi guys, i got some problem and i cant figure this out. I have a virtual machine on server which will be a mail server in future. Ive created a VIP on Forti that is internal address mapped to public. It pings and is visible from outside but services are not responding at public address f.e. SSH port 25.I also added even port forwarding for all ports 1-65535 and it still doesnt answer. Anyone got an idea what to do? I can log in to machine from our internal network through SSH but i cant do the same when i try to log in to public address
How can I upgrade the firmware of my FGT-101F from FortiOS v6.4.11 build 2030 (GA) to FortiOS v7.6.0 build 3401?
Hello Fortinet Community, I am experiencing an issue with CPU utilization on one of my FortiGate VM02 instances. I have two clusters, both configured similarly, but their CPU load behavior differs significantly. Cluster 1 (Normal Behavior):The CPU load is distributed evenly across both cores during IPsec operations, as shown in the output of the # diagnose vpn ipsec cpu command: # diagnose vpn ipsec cpu Software crypto CPU distributions: CPU# enc dec-in dec dec-out 0 18524077877 0 7856389447 7856389447 1 18703560081 0 198249897 198249897 Cluster 2 (Problematic Behavior):On the second cluster, the load is uneven and concentrated on a single core, which is causing performance concerns. Below is the output for the same command: # diagnose vpn ipsec cpu Software crypto CPU distributions: CPU# enc dec-in
Just upgraded FortiGate to 7.2.9 from 7.0.14. Just noticed that there are some new feature about Compromised Host. But it required My FAZ to have IOC subscription license. So, I wonder Does IOC license's expiration affect to our production if it's expired likes UTP License. If it's expired, it affect to my policy rule if it use Webfilter Profile.
is it possible on Fortinet to get only access to SDWAN using RBAC?Means Users should only access SDWAN module and not the other team will manage the Firewall policies. Is it achievable in Fortigate?Regards,Sanjay S
Wondering if anyone has had any experience with the topic above. I have a current environment with fortilink managed switching in MCLAG with a LACP connection to a single Ruckus switch. I'm running into some interesting STP issues where my ICLs are being blocked when connecting to the Ruckus switch. Ruckus switch is running per VLAN RSTP and I'm not sure on the interoperability here with Fortinet's MST. Assuming that my MCLAG configuration is correct (lldp profiles, stp-aware, etc...) is there some other gotcha that I should be looking for specifically with Ruckus?
How do I know if this image refers to a ADOM mode normal or workflow mode?
We are encountering an issue with FPX where the Palo Alto firewall attempts to retrieve updates via FPX, but the connection is randomly refused. Upon analyzing the packet capture from FPX during the issue, we observed that FPX uses TLS 1.0 to communicate with the Palo Alto update server, causing the connection to fail. However, when FPX uses TLS 1.2, the connection is successful.Is there any option to enforce FPX to use TLS 1.2 for communication with the Palo Alto update server in a specific policy or profile?
Hi All,I just built a FortiManager VM on my Hyper-V server and I am unable to access the Web Interface. I have looked at similar issues, followed guides to add web services, verify https, ssh, ping, etc. are in the config for the port I'm using, yet I am still unsuccessful at connecting to the device remotely, primarily with the GUI.For Port1, I have the following:config system interface edit "port1" set ip <internal ip address> <my subnet> set allowaccess ping https ssh webservice set type physical nextend I can ping the interface (couldn't before doing the set command above), SSH works, but https does not. Any thoughts? Thanks.
I have a problem with FortiClient VPN 7.4.1 on macOS 15.1.After launching the application, I configure the VPN, enter the IP and user, and save. I enter the password from the administrator, and a window to enter the token appears in the background, which immediately disappears - so I have no way to enter the token. How can I solve this problem? I went through all the tutorials and set the necessary permissions (notifications, disk access, network settings, and permissions for FortiClientProxy and FortiClientPacketFilter) in the settings. I also installed Visual C++ tools and the application several times, but the problem continues.
Dear Forum Community , I want to access remote in my working company and have acess in all vlans . The infastructure of my fortigate is the bellow :Interface WAN: For Access in ISP Interface Trunk with subinterface: Vlan1,Vlan2, Vlan3 etc I do all the settings with ssl-vpn address and i want to have one firewall policy to access and administrate all VLANs.
We've been using Fortinet for a long time and renewing their premium support contracts every year, expecting reliable help for business needs like SSL VPN. However, our recent experience has been very disappointing, and I wanted to share this to see if others have faced similar issues.We raised a ticket about an SSL VPN problem where the VPN connects initially, but after a few minutes, we lose access to LAN services and the internet, even though the VPN still shows as 'connected.' Despite providing all the necessary details - configuration files, logs, and background information, support didn't attempt any troubleshooting. Instead, their first response focused on licensing, suggesting we might need FortiClient/EMS licenses before they could help. This makes no sense since SSL VPN is a built-in feature of Fortigate, and we're using the free FortiClient from Fortinet's website.The support process was frustrating and unprofessional. We received repeated reminders stating that support hadn
How can I Create a Username on Fortinet 400F Firewall with Special Characters in a username For Eg (Network.Support)
Previously the IP addresses were cached in the log filter view and you did not need to retype them, you could simply click on them - feature is GONEPreviously you could click on the IP address and change one digit, now you have to type the entire IP in again from fresh.If you use text view on filters and would like to revert back to the other view, it says:Switching to filter mode will clear all search text, are you sure you want to continue?why have all these features been lost, surely firmware upgrades bring better features, not remove them and make it more clunky ?
Hello,We want to inplement fortinac to have a guest portal for self-registration guest with sponsor, linked to a FortiAP SSID.We are stuck where the fortinac needs to change the user from the isolation vlan to the guest vlan but it doesn’t work.Any ideas on what to check https://vidmate.onl/ ?Thanks
Dears,I have a question regarding Fortivoice sizing. There is a feature called "concurrent calls," which is supported by Fortivoice.My question is, Fortivoice concurrent calls, what is included? Is it included(Internal calls, external calls, AA,) or what? BR,
My FortiEMS has quarantined a file that has the excact same checksum as a file in my allowlist, its just the name thats different but it still got deleted from the client. But because the checksum is already listed in my allowlist i have no option to unblock the file. Has anyone an idea on why this happens and how i can unblock the file?
I have IOT devices that can only connect to an SSID using a PSK so using WPA2 Personal. I'm trying create NAC profile rule/access policy to move them to a different vlan on that SSID (Tunnel mode). I have two sub-interfaces under the SSID for dynamic assignment. Config #1 - My FortiAP SSID config is WPA2 personal with NO RADIUS server defined. On NAC, the connected device is properly profiled, hits the correct Profile/Policy with the desired new VLAN. However, the vlan on the SSID is not changed. Config #2 - My FortiAP SSID config is WPA2 personal AND I assign the NAC Radius server and select "Dynamic VLAN Assignment". With this config, I can no longer even connect to the AP. I get the error message like "STA denied by Radius based MAC authentication". Here's a config snippet. config wireless-controller vapedit "iot_devices"set ssid "iot"set broadcast-ssid enableset security wpa2-only-personalset radius-mac-auth enableset radius-mac-auth-server "fnac_radius"set radi
As stated in this guide (https://docs.fortinet.com/document/fortisandbox-private-cloud/4.4.0/vmware-esxi-vm-install-guide/371849/installing-the-windows-vm-package), I downloaded the default Windows VM00_BASE.pkg package to a local server and installed it. According to the VM Events logs, New VM WIN7X86SP1O16 and WIN10LTSCO21V1 have been installed successfully.However, the Default VMs tab does not appear in the Scan Policy and Objects > VM Settings section. Additionally, the Optionals VM tab only shows the Android VM.In the Dashboard, the color of the Connectivity and Services icons is green.Output of the vm-status -l commandEven after attempting to download directly from fsavm.fortinet.com using the command fw-upgrade -v -s fsavm.fortinet.net -t https -f /images/v4.00/VM00_base.pkg via CLI, the issue persists.
hi All, Today I was doing some changes on my Lab Fortimanager for my newly added Fortigate device. When i tried to push the configurations via install wizard option, it shows some weird configurations were also being pushed along with my configurations. Those weird configurations were never added. It tries to change my default dns filter profile. In my DNS filter configuration it tried to change the category settings in DNS filter For example the dns filter configurations on my Fortigate were config dnsfilter profile edit "default" config ftgd-dns config filters edit 1 set category 1
Hi, we have configured the fortigate to use SDWAN for the fortiguard traffic, we are also using UDP 8888 for that traffic for better performance. Everything is working fine but iam not sure if the traffic is being processed by the dedicated SDWAN rule or the implicit rule (routing table lookup) which will work anyway (the internet SDWAN zone has the 2 WAN interfaces in it and the default static route is pointing to that zone). Both interfaces are up and running. The dedicated SDWAN rule is placed as the first rule (src: ALL / dst: Fortinet-Services) - manual rule with the 2 WAN interfaces as members. This rule is constantly used (hit counts and last hit) but the confusion comes when i check the session information (diag sys session filter dport 8888) i can not see one single session with SDWAN information in it. Questions: 1. how can i check whether the fortiguard traffic is actually processed by the configured SDWAN rule? 2. must the SRC be set to 'all'
hi,we would like to use the lock feature when an admin is making change/FW policy push.my questions are:1. is it "safe" (no downtime/outgea) when enabling "workspace" in FMG? just want to "lock" or create workspace for a specific ADOM only.2. what mode do i choose and what's the best practice?3. do i just choose "workspace" then apply?4. what is per-policy lock?5.does a user always need to "lock" the ADOM and create a new "workflow session" when making a change?
Hey Everyone,Does anyone know how long an Active-Passive cluster member can be offline for before it will fail to rejoin the cluster when it comes back online? Both units are still the same firmware version etc. and we have 1 unit in each of our DCs. One of our DCs is going down for a long period of time for about 3 months, but I can't find any KBs that say if there is a duration before it will fail to rejoin. CheersRowan.
Hello,We tried to issue a manual backup like: exe backup all-settings sftp <SFTP Server> /data/tftp/Fortigate <remote username> <remote SFTP user password> Starting backup all settings in background, Please wait.Fortimanager # MD5: ee622a71b5f1217d24b271bb8f4165a9Starting transfer the backup file to SFTP server...* /var/fwclienttemp/fmg_clibackup.dat -> sftp:// <SFTP Server>:22/%2Fdata%2Ftftp/Fortigate* Trying <SFTP Server>:22...* connect to <SFTP Server> port 22 failed: Connection timed out* Failed to connect to <SFTP Server> port 22 after 129820 ms: Couldn't connect to server* Closing connectionSFTP failed: Timeout was reachedFailed to backup all-settings due to SFTP transaction!Backup all settings...Failed.Fortimanager # Please note that we verified access to that remote folder by opening a SFTP session and send a file to this destination from a linux box. $ scp fortigate.bak sftpbrutus@<SFTP Server:/data/sftp/Forti
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.