Mark a Best Answer
Fortinet Community
Recently active
Hey Everyone,Does anyone know how long an Active-Passive cluster member can be offline for before it will fail to rejoin the cluster when it comes back online? Both units are still the same firmware version etc. and we have 1 unit in each of our DCs. One of our DCs is going down for a long period of time for about 3 months, but I can't find any KBs that say if there is a duration before it will fail to rejoin. CheersRowan.
Hello,We tried to issue a manual backup like: exe backup all-settings sftp <SFTP Server> /data/tftp/Fortigate <remote username> <remote SFTP user password> Starting backup all settings in background, Please wait.Fortimanager # MD5: ee622a71b5f1217d24b271bb8f4165a9Starting transfer the backup file to SFTP server...* /var/fwclienttemp/fmg_clibackup.dat -> sftp:// <SFTP Server>:22/%2Fdata%2Ftftp/Fortigate* Trying <SFTP Server>:22...* connect to <SFTP Server> port 22 failed: Connection timed out* Failed to connect to <SFTP Server> port 22 after 129820 ms: Couldn't connect to server* Closing connectionSFTP failed: Timeout was reachedFailed to backup all-settings due to SFTP transaction!Backup all settings...Failed.Fortimanager # Please note that we verified access to that remote folder by opening a SFTP session and send a file to this destination from a linux box. $ scp fortigate.bak sftpbrutus@<SFTP Server:/data/sftp/Forti
We recently updated to FortiClient VPN version 7.0.7.0345 for Windows. When users now start FortiClient VPN on their Windows machines, they get a User Account Control prompt Can anyone advise what has been changed in version 7.0.7.0345 that cause this UAC prompt to come up? And what we can do to, except lower the UAC settings, to prevent this prompt from happening?
I have a single, 8 hour, professional services support day banked. I've got a couple of options on how to use it. I've got a FortiManager license but I've never set it up and never used it. I would also like to configure my FortiGate that's in my DR site with a VDOM so that I could have a "bubble test" that's segregated from everything else, but uses Corp IPs. I've also never set up VDOMs or worked with VDOMs. I'm less than sure I can accomplish both of these tasks in 1 8 hour support day. Which one would you consider more complicated and I should use the support day for?
Hi all, I have a Fortigate device set up SSL VPN, when I create an account and connect on Laptop, I can ping to the Server normally, but when I also use this account to connect to my phone (Android and Iphone), I can connect, but I can't ping to the Server.Forgate uses Firmware 7.2.5 build1517Please help me with this problem.
Is there a way to use Fortimanager trial in an airgap environment? The Entitlement Files not work because the Trial has no support.
Im having following issue:Im using FortiEMS 7.2.4 with the Cloud functionality and whenever clients go offline for a longer period of time they get kicked out of their workgroup and they don't connect back to their previous workgroup whenever they come back online.Is there a way to connect the clients back to their previous workgroup even when the requirements don't match anymore or do they always have to match even if they only reconnect?Is there an option in the Cloud version to never let a client disconnect or increase the time until they disconnect? Thanks FortiClient
Hello Everyone I have a fortigate and fortimail VM setup in my lab that connects to two Exchange servers. I can successfully receive external email through the Fortimail VM however when I try and send externally, It just gives me an error immediately "too many hops". I have checked the fortigate and I see traffic passing for SMTP. I have policies setup on Fortimail and I can successfully validate MX records for my domain and i can telnet test externally on port 25 without issue. Not sure what to change or where to check what is causing this. I even set the max hops to 200 to test and it uses all 200. What I notice on the logs page is, that when I send externally, it lists the same email about 30 times, however when I receive, that mail is listed once. Please can you guide me where to check this? ThanksEd
Can I get data in the other Fortiview panels. but I can't see any data from our VPNs in our FAZ in the Fortiview section, any suggestions? Thanks
Hi all, I have 2 switches connected to 2 fortigate interfaces that forms a software switch. This software switch routes some Vlans that terminates at these ports. Both ports share layer 2 and 3 parameters. When traffic from different vlans reaches firewalls, I route traffic between then with rules.I won't go into the details of this design, but the switches are in different locations and need to share networks/vlans. With software switch, servers from both switches can directly reach the gateway with direct connections to the firewall. In some cases, I move virtual servers between locations (using a dedicated Fiber cable) and with this topology servers works with same network configuration in both sites. I would like to connect a new cable between switch 1 and switch 2 to bypass traffic between same vlans but, if I do that, I'll form a layer 2 loop. (Red line diagram). What I would like if it's possible is:1)Use 2 different ports in firewall to can route same networks/vl
Hello, I’ve set up two sites connected via VXLAN over IPSEC, and everything is functioning as expected. However, I’ve noticed an issue with ARP behavior under specific conditions: From Site A, when I connect from another VLAN (e.g., VLAN 30) to a virtual machine in VLAN 10 or VLAN 20 on Site B, I observe a change in the ARP table on the device in Site B.Example: I check the ARP table of PC B20 (a device in VLAN 20 on Site B).The MAC address for 10.112.20.254 (router’s IP) initially shows 00:09:0f:09:00:00 (MAC address of the FortiGate on Site B).When I connect from PC A30 (a device in VLAN 30 on Site A) to PC B20, and I re-check the ARP table on PC B20, the MAC address for 10.112.20.254 changes to 00:09:0f:09:02:00 (MAC address of the FortiGate on Site A).This unexpected behavior raises concerns about network stability and could impact communication. Has anyone encountered a similar issue, or does anyone have insights on why the ARP entry changes in this
Hello everybody, I'm working on a 60F Fortigate.I have an internal domain called vpn.xxx.com. I set some custom DNS records to redirect the request to vpn.xxx.com to a specific machine. The interface we are working on is the Wi-Fi interface. From the picture, 192.168.1.1 is the router. So far, so good. Everything is working. My network settings are:  If I ping vpn.xxx.com: 10.1.0.1 replies correctly Now I connect to a VPN Client. The network settings I showed before remain the same. The difference, now is that 10.1.0.1 is not the one ho replies to the ping. Now, 79.x.x.x replies to the ping:and vpn.xxx.com is not reacheable anymore. Who is 79.x.x. x? Is the WAN interface of the Fortigate: Now, you cou ld say that the problem is the VPN, that probably changes some DNS stuff. It could be right, but there is only one problem. If I disconnect from the Wi-Fi (on wich are set DNS custom records) and connect to my phone hotspot and to the VPN Client, vpn.xxx.com is reache
We are encountering an issue with users connecting to our VPN web portal via Fortinet using their Active Directory (AD) credentials. Specifically, when a user's password has expired and Fortinet prompts them to create a new one, the portal fails to validate whether the new password complies with AD's complexity requirements.As a result, Fortinet provides a confirmation that the password has been successfully changed, despite the update not being propagated to the AD. This discrepancy causes users to believe their password has been updated, when in reality, the original password remains active. Consequently, users frequently contact support after being unable to authenticate using their "new" password.Is there a way to enforce AD password policy compliance directly within Fortinet or otherwise mitigate this issue to reduce user confusion and support overhead?
Hello guys,We have Forgates 100F in our production with v7.2.8.I would like to configure encrypted logs sending to Syslog server. But I didn't find settings in GUI nor CLI commands.Could someone tell me if it is possible to do ? If yes, how ?Thank you.
Running Fortigate on 7.4.5.I have some VLAN interfaces that are part of a LAG. I need to move one of these VLANs out of the LAG and have it tagged on a separate physical interface (or perhaps a different LAG).I did see the article https://community.fortinet.com/t5/FortiGate/Technical-Tip-Migrating-VLAN-interfaces-from-one-interface-to/ta-p/257285 suggesting looking at the "parent" where the Integrate Interface is available, but I don't have that. All the VLANs as well as the parent LAG have the Integrate Interface greyed out. How can I move it? I really don't want to delete and recreate it as I have lots of policies linked I would need to delete and recreate too.
I have enabled fortigate ddns but site not loading. I need to know this option now days working or not ?
Hello,I am using an FG 80F with FortiOS version 6.4.15, connected to several Mikrotik devices via dial-up L2TP IPsec VPN. For dynamic routing, I use the RIP v2 protocol to enable communication between clients behind the devices and other remote networks.When upgrading to FortiOS 7.0.X, I followed the manual steps to adjust L2TP: adding a static route to the 192.168.254.0/24 network for l2t.root and modifying the firewall policy. While the VPN connections are established, RIP does not function, and routes to remote Mikrotik networks are not created.Below is my routing table in version 6.4.15 with the RIP protocol functioning correctly. S* 0.0.0.0/0 [10/0] via 181.120.228.253, wan1S 92.62.234.133/32 [15/0] via 92.62.234.133, VPN MikrotikS 178.255.168.3/32 [15/0] via 178.255.168.3, VPN MikrotikS 178.255.168.18/32 [15/0] via 178.255.168.18, VPN MikrotikS 178.255.168.25/32 [15/0] via 178.255.168.25, VPN MikrotikS 178.255.168.27/32 [15/0] via 178.255.168.27, VPN MikrotikS 178.255.168.28
Hi.We have had a terrible time finding a combination of versions that work for our clients, within the same client forticlients won't work with 7.2, some won't with 7.4, even some with 7.0x.We need to update all to the latest build in their branch and trying to find a quick easy seamless process that won't break everything. I obviously want to keep all current connections intact and settings https://tutuapp.uno/ .We have an RMM agent, so we can script to do this any way that is reliable.TIA.
 My fortigate firmware broken or corrupt. How can I reinstall new firmware to fortigate 200f. Please help #fortigate #Fortinet @everyone #firewall
Hi Team, anyone can help on "Fortinet VPN Zero-Day Exploited in Malware Attacks Remains Unpatched: Report" The DeepData malware framework was seen exploiting a Fortinet VPN client for Windows zero-day that remains unpatched.Link: https://www.securityweek.com/fortinet-vpn-zero-day-exploited-in-malware-attacks-remains-unpatched-report/
Hi, Currently managing HA cluster, but when trying to access the secondary firewall via CLI, I keep on getting connection closed advised after approx. 10 seconds. What might be causing the issue? I need to access the secondary firewall since the HA cluster keeps on getting out of sync. "Connection to x.x.x.x closed." Thank you!
After installing Hyper-v Fortimanager VM accesing the gui and trying to register a trial license. Cloud credentials are entered and the agreement is accepted. After that it returns to the license screen with "undefined" in red. Is it possible to just get a trial license to install?
Hi, I am seeing that error in my dashboard, and was planning to click the 'Activate' so I can log in button but its greyed out. I do not have the full subscription to the FortiGate Cloud. Is this the reason why? Thank you
Hello Team, would you share your recommendations of migrating core switch Cisco 4507R+E to fortiswitch 448E is it applicable ?will the FortiSW be enough or i'll need to go to another versionand may i know what does that means ? "Supporting up to 48 ports in a compact 1 RU form factor, "
I've been searching through the Product Life Cycle info but I'm unable to locate the end of life date for the following models FortiGate-40FFortiGate-60FFortiGate-101F Is anyone able to help with this please Thanks & regardsSteff
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.