Mark a Best Answer
Fortinet Community
Recently active
Hi, I am seeing that error in my dashboard, and was planning to click the 'Activate' so I can log in button but its greyed out. I do not have the full subscription to the FortiGate Cloud. Is this the reason why? Thank you
Hello Team, would you share your recommendations of migrating core switch Cisco 4507R+E to fortiswitch 448E is it applicable ?will the FortiSW be enough or i'll need to go to another versionand may i know what does that means ? "Supporting up to 48 ports in a compact 1 RU form factor, "
I've been searching through the Product Life Cycle info but I'm unable to locate the end of life date for the following models FortiGate-40FFortiGate-60FFortiGate-101F Is anyone able to help with this please Thanks & regardsSteff
hi,we have FG-xx "F" in our environmentmy question is, since these FG have internal HDD1. is it "safe" to enable log "all sessions"?2. haven't seen much FG docs regarding syslog, is logging buffer "circular" in a FG, i.e. overwritten by newer logs?3. is there a default threshold or buffer size in the HDD by these "F" models? is there also a "preferred" FW policy sequence based on its specific purpose/criteria? this is to prevent an overlap or "shadow" FW policy. refer sample below1. DNAT using VIP2. SNAT using IP pool3. SNAT using Egress interface
Hi, I would like to use my Fortigate hostname to login into the device using SSH (e.g. Username@hostname). However, PuTTy gives me an error when I try it this way. Is there a setting or command I must enable to allow me to login in this manner?
We make use of the Guest Management facility to create vouchers for the guests at the Lodge.We have 2 areas where guests can make use of their vouchers and sometimes the same voucher is printed due to the fact that there are 2 locations (FortiAP at each location)There is a Comments field available if a Single user is created, but alas when multiple accounts are requested, the Comments field is no longer available.The Comments field would be ideal to indicate, say the location where the voucher is being used. This would mean that no double prints are done.Is there a way around this? Could it be a feature request?Maybe in CLI to do a bulk update to a range of userxxx - userxxy and set Comments to "this is for Lodge 1"
Hi all,I am working on a test machine configured to access the Internet via a proxy PAC script set to FortiProxy. At the moment, when I open the browser, the proxy authentication banner appears correctly; by entering the domain credentials, I can browse without problems.Now, however, I need to configure FortiProxy so that Microsoft Teams can bypass authentication. The goal is to allow Teams to run without requiring proxy authentication, while for other services the proxy login request should continue to work as it does now. What are the methods for doing this? Thanks in advance for the supportBR
I'm going to be taking a backup of 1 fortinet and then doing a LOT of massaging of the .conf file to restore to a different fortinet. I'm wondering if anyone has used some kind of .conf "editor" program. Something with a little bit more 'oomph' to do things than Notepad++. I'm thinking features like being able to "collapse" a section without having to highlight the whole section and then hit 'hide'. Back in the day when I used to write ColdFusion I used DreamWeaver to edit the code and it had features like that which it could parse for ColdFusion code. Has anyone used a code editor like this when modifying .conf files for fortinets?
Hi, I'm seriously at my wits end with issue after issue with the migration process to FortiClient EMS v7.4.x. Besides all the other issues I experienced and managed to resolve myself (here), I now have a new one where I can't sign the Windows installer with the code signing certificate due to the following error. failed to sign installer file /opt/forticlientems/data/clients/installers/default/Corporate_Laptop_v7.4.x/FortiClientSetup_7.4.1_x64.exe: fail to move signed file: rename /tmp/emssign191630999/FortiClientSetup_7.4.1_x64.exe /opt/forticlientems/data/clients/installers/default/Corporate_Laptop_v7.4.x/FortiClientSetup_7.4.1_x64.exe: invalid cross-device link /opt and /tmp are on different mount points. We've tried mounting it (successfully) so that /tmp now sits on top of /opt/tmp (same partition) but it doesn't solve the problem. Please help!
Hopefully my pain and suffering, with multiple issues, over the last couple of days will benefit others. 1) Make every effort to install the new server in a virtualised environment and take snapshots as often as you can. I landed up reinstalling and rolling back to snapshots more times than I can count. 2) If you deploy a minimal install of Ubuntu make sure that logrotate is installed as well otherwise the FortiClientEMS install will fail with no way to start it up again (roll back / reinstall time) 3) If you have a code signing certificate on your old server, make sure you remove it before running the migration tool (the migration will fail (I used the v7.4.1 migration tool) with no way to restart the migration (roll back / reinstall time). The migration tool throws a rather useless error (sqlalchemy.exc.DataError: (pyodbc.DataError) ('22001', '[22001] [Microsoft][ODBC Driver 17 for SQL Server][SQL Server]String or binary data would be truncated. (8152) (SQLExecDirectW)
Hi Support and Community,Today scan my site on virus total and I saw it is listed in Fortinet Phishing. We are using Django restful APIs with subdomains i.e. production dot planclear dot comProgrammers have tested the entire code and they said all good. Can you please remove the flag or give us further details so we can ask developers to fix things?Thanks.
Dear All, am facing the problem on viewing the traffic logs in Fortiweb which is deployed in Azure. Enabled the traffic logs in CLI but still it's not visible, any suggestion pls
Hi,Application control is enabled. Client is attempting to access a specific URL using HTTP.Browser_Edge, (on non-default port/non-default port blocking is enabled) Running in FortiOS 7.2.8 Is there a way to configurre an override for a specific IP combination while Application Control is enabled? Apply an override for the destination ip and port combination of - 4.196.74.81:8030TIA :)
Hi, Is it possible to use RSA keys for Site to Site IPSEC VPN set up? I am trying to look for KBs but unable to find one. Thank you!
A Standalone FortiSwitch configured with 3 VLANs and the interfaces to match.Devices on the VLANs can ping each other but they cannot ping anything that must use the default route, stuff outside the 3rd party firewall. If I add a static route to 8.8.8.8 I can ping it. Any ideas why the default route isn't working? config switch vlanedit 1set description "Data"nextedit 2set description "Door-Access"nextedit 3set description "IN-Printers"next edit "Doors"set ip 192.168.2.254 255.255.255.0set allowaccess ping https sshset snmp-index 60set vlanid 52set interface "internal"nextedit "Printers"set ip 192.168.3.254 255.255.255.0set allowaccess ping https sshset snmp-index 61set vlanid 54set interface "internal"nextedit "Data"set ip 192.168.1.254 255.255.255.0set allowaccess ping https sshset snmp-index 63set vlanid 50set interface "internal"next config router staticedit 1set dst 0.0.0.0 0.0.0.0set gateway 192.168.1.50next
Hello guys! Im planning updating a few Fortigates from v7.2.6 build1575. I have two of them in HA. I would like to know what are you guys experience with 7.2.10M. Whats the stability and what issues if its the case that you guys are having?
Chrome Extension for VPN blocked by FortiGate 60E with FortiOS 5.6.2We are running a Fortigate 201-F with firmware v7.4.5 build2702 We have a user that occasionally needs to use a VPN (1clickvpn.com). We would prefer to use a Chrome Extension that allows turning the VPN access on/off easily. We have tried different extensions but they seem to be unable to get through the firewall. Oddly, if you use a standalone VPN application instead of a Chrome Extension, it works. Is there something in the application or security policies on the Fortigate that would prevent a VPN via a Chrome Extension?
we are running 7.2.9 on our fortigate and 7.2.4 on our APs this is remote location.any idea what would cause this not to pop up for users.
Hi, I've been struggling with this one for a couple of weeks now and haven't found a solution. In my lab environment with a single IP address available I was running a 600c perfectly well, but I decided to change to a 200e (v7.6.0 build3401) for the additional functionality. Internally I am running an On-Premise Exchange Server, an ADFS Server for webmail authentication, along with an unrelated website all on separate servers. I use virtual servers (HTPS) to connect to the appropriate real server based on the host header. e.g. (not real IP addresses) mail.myname.com (100.100.100.1:443) -> Server 1 (192.168.0.1:443)adfs.myname.com (100.100.100.1:443) -> Server 2 (192.168.0.2:443)website.myname.com (100.100.100.1:443) -> Server 3 (192.168.0.3:443) Browsing to the Web Server works perfectly.Browsing directly to the ADFS authentication page (passing appropriate parameters) works perfectly. Including redirecting back to the mail server after aut
Hi, I noticed that when I establish a BGP session with my peer, Fortinet takes about 30 seconds to send its routes to the peer. The peer instead sends its routes to Fortinet almost instantly after establishing the session. How can I reduce this time?
Hi Team,So I have a case with TAC that is hitting the wall in the last 2 weeks. I have a client with 800 users , Fortigate and FortiEMS.The main reason that he purchased FortiEMS is to have the users always connected and to be able to control which user can disconnect or not).The problem is that even everything looks just fine, has the proper configuration from all the possible documentations, the auto-connect is not working! Not to speak about "user EMS: <options><allow_personal_vpns>0</allow_personal_vpns><certs_require_keyspec>0</certs_require_keyspec><on_os_start_connect_has_priority>0</on_os_start_connect_has_priority><keep_running_max_tries>0</keep_running_max_tries><autoconnect_only_when_offnet>0</autoconnect_only_when_offnet><disable_connect_disconnect>1</disable_connect_disconnect><secure_remote_access>1</secure_remote_access><show_vpn_before_logon>0</show_vpn_be
Hello , could someone give me a light I'm configuring F60 , when the WAN1 card is set to receive DHCP modem from the operator it navigates normally , when I put it in Manual it stops navigating , I already went to the modem of the operator I made a DMZ I put the same IP and nothing someone could help me with this
Hello team, This time, a basic question.https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/369092/enabling-automatic-firmware-upgradesThis article says "updates within the same major release", so I am wondering, what is this "major release".For example, if we want to schedulle an automatic update to afterhours, I will need to know to which version will be updated Thanks in advance.Regards,Damián
I need the installer for Forticlient VPN 7.0.8.0427 (ideally the MSI) for a large-scale uninstallation via Intune. Is there anywhere I can find it? I've seen some posts within this community that contained a link, but they were all expired.
Hi Folks! Hope you are all doing well, I am new to the firewall role. I would like to ask why I cant see any denied logs related on our block list policy. we have this group for IP address and full qualified domain, we plae any malicious object from this group. but as I checked, It has block other IP address that are not included on the repository. and the IP address that are on the group are not is it because the user are not accessing this IP or I cant see it because of the 7 days log retention. I would appreciate your insights on this Also here is the policy (Version 7.2.8) NameFromToSourceDestinationScheduleServiceActionLogBlock Inbound TrafficanyanyGroup of Malicious IP and FQDN detected from QradarallalwaysALLDENYEnabledBlock Outbound TrafficanyanyallGroup of Malicious IP and FQDN detected from QradaralwaysALLDENYEnabled
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.