Mark a Best Answer
Fortinet Community
Recently active
Hi guys,I am new to the field of advanced routing. In my company we have the following network construct to a branch office:A dark fibre line connects 2 fortigate firewallsAn LTE line is to be used as a backup lineBoth fortis are connected to each other via both lines using IPSecAt the moment the internet traffic goes over the LTE line, but in the future it should work as a backup internet line, but currently the LTE line is the internet access line for all clients in the branch office.If we put a new default route 0.0.0.0/0 on the WAN interface with the dark fibre, both routes go down.How do the two Fortigates have to be configured so that everything runs via the dark fibre and the LTE line is only used if the dark fibre fails?Thank you in advance for your answers.
Hello, One of my customers asked if FortiNAC-f would support their Dell Powerconnect N5548 switches.I assumed it would be possible with SNMP or just CLI. Back to the subject - is there a publicly available list of supported 3rd party switches or if not is the above model supported and in what capacity. Any answers to this or just pointers to the appropriate materials would be appreciated!
Hello expertsI I have configured FortiClient EMS to apply an endpoint profile system setting to send FortiClient logs to FortiAnalyzer, but no logs are being sent. I confirmed the settings iFortiClient EMS are correct. Below are the relevant local log lines from the fazlogupload.log file from FortiClient. 20241112 07:32:48.841 TZ=-0800 [fazlogupload:INFO] log_upload:183 Uploading traffic logs20241112 07:32:48.841 TZ=-0800 [fazlogupload:INFO] faz_comm:37 Connecting to {redacted}.ca-west-1.fortianalyzer.forticloud.com:514 (TLS: true)20241112 07:32:49.008 TZ=-0800 [fazlogupload:DEBG] faz_comm:92 EMS serial:{redacted}20241112 07:32:49.009 TZ=-0800 [fazlogupload:DEBG] faz_comm:93 EMS site: default20241112 07:32:49.009 TZ=-0800 [fazlogupload:DEBG] faz_comm:94 FCT serial:{redacted}20241112 07:32:49.010 TZ=-0800 [fazlogupload:DEBG] faz_comm:95 FCT UID: {redacted}20241112 07:32:49.010 TZ=-0800 [fazlogupload:DEBG] faz_comm:96 Log type: traffic20241112 07:32:49.010 TZ=-0800 [fazlog
Hello we a have installed a public certificate on our captive portal . when a machine is connected its initial location is the isolation vlan as per design. Cert looks to be installed correctly but we are still getting SSL Certificate error upon initial browser launch . Do we need to modify the firewall rule for isolation vlan? do we need to allow outbound internet access to the certificate authority ? What are people doing in this scenario. Running FortiNAC-f 7.4 Thanks,
FortiSOAR's latest updates are here, and we've added some powerhouse connectors and solution packs that'll make your SOC team look like superheroes—minus the capes (but feel free to wear one if you'd like!). Whether you're facing ransomware threats, digging through cloud analytics, or looking to streamline incident response, our recent releases cover it all. With the Lacework FortiCNAPP, you get unparalleled cloud visibility, empowering you to innovate with confidence. The new Outbreak Response packs keep you ahead of emerging cyber threats like Mallox ransomware and vulnerabilities that dare to show up uninvited. For those of you who live for analytics, we've got Azure Log Analytics and Splunk updates to help you dive deep, uncovering insights faster than ever. And let's not forget our trusty AWS WAF and Akamai WAF connectors that add an extra layer of security to keep the bad guys out (they've had enough practice getting in). Integrations with Google Sheets and M
Dear Team, Can you provide me please with documentation showing how many WEB applications can be protected on the Fortiweb? Thank you,Elsy
Is there a way to set up Port Knocking on 7.4.x
I recently added a cellular internet back up service to our Fotigate. For the last 2 or 3 weeks I have recieved over 1000 "Login Denied" email alerts. I would like to block all public ip addresses but I have not found a good step by step using the web interface (I don't use CLI). Can someone point me in the right direction?I have a Fortigate FG60F with version 7.0.16 build0667. I cuurently have the backup internet unplugged.
I’m working with an Acoustic customer who wants to give me access to their development sites using their VPN. They use Fortinet and we had a call to walk me through installing it on MacOS on my laptop. Installation worked fine, but I can’t actually use the client, because after entering credentials I’m prompted to modify the MacOS Privacy & Security settings (see screenshot). When I open the Settings window the usual prompt to allow software from this developer is not there, so I can’t approve it (see screenshot).
I' m curious if anyone has run into this problem and if so, what have they done to fix it? (v4 MR3 P8) I have FSSO configured and it has been working properly now for several years. However, in the last few years more and more wireless connections are being made available to our users. We have implemented group policy to configure our wireless adapters to authenticate users using 802.1x and PEAP to allow authenticated users access directly onto our corporate wireless network and keeping guest users separate. The problem we have is that with this setup, users frequently use both wireless and wired connections simultaneously as they generally forget to disable their wireless connections. This seems to present a problem with FSSO. It seems (this is a bit of an educated guess) that when a user authenticates they may source from either the wireless or the wired connection resulting in a event log entry that is monitored by the collector agent. However, sometimes when a user la
Our FMG and FGTs are all running 7.2.8, and several months ago we upgraded the security fabric across all our devices. Now, we have a problem to where our local-in-policy will deploy once from the FortiManager, and the next change we deploy deletes the configuration that as just installed. We're trying to enable BGP to a vendor for one of our new systems over one of the VPN tunnels, but BGP is being listened to on the outside interface. I blocked tcp/179 using the local-in-policy on the outside interface, but then had to make another change after that. It's now unblocked. We have 18 FortiGates, and all have various local-in-policy configurations, but we can't make any further changes. Can someone provide guidance on what we need to do? Thank you.
Hello,we have a problem when the captive portal load over android device and the user accepts the terms the browser closes automatically without going to the forwarded address on the other hand when you do that on an IOS device the browser stays open and forward the user to the site we have set.
Hi,I got isssue with access to fortisiem from web browser, is said that the service is unavailable.below is the result when i run phstatus command on server.and i not sure how to start AppSvr and other processes which are down. [style="background-color: #ffffff;"]PROCESS UPTIME CPU% VIRT_MEM RES_MEM[/style] [style="background-color: #ffffff;"]phParser DOWN[/style] [style="background-color: #ffffff;"]phQueryMaster DOWN[/style] [style="background-color: #ffffff;"]phRuleMaster DOWN[/style] [style="backgrou
Hi community, I'm connecting a fiber connection to the firewall with speeds between 350 and 450 Mbps, but I'm only getting 10 Mbps in return. I understand that there will be some speed reduction, but is this normal??? I have disabled all security features in the firewall policy and the "threat-weight" configuration, but I am still experiencing the same speed issues. Here is my configuration. Please, if you have any advice on how to increase my internet speed, I would appreciate it.
Fortinet Firewall 200FI want to allow each and every page before and after of manageengine.com I add an entry *.manageengine.com/* with Wildcard, Exempt and Enable but I am not able to allow all websites
my FortiAnalyzer https certicate expired. got a wildcard ssl for my domain from sectigo. when i import it in analyzer it fails with its already imported but i cannot see it on the list of certificates. my analyzer vm was on version 7.4.5, updated to 7.6.1 and its the same behaviour
Installed new version of Forticlient (vers 7.2.4.0972).we setup up Azure SSO on fortigate v7.when running connect on client .. getting pop up "Script Error"(review screenshot)script error (error has occurred in the script on this page).Error: Access denied.code: 0URL: about blank  I have uninstalled and reinstalled application, on 2 different devices and same issue. Can anyone assist? Anthony Abela
Hi people,I just updated a firewall from 7.0.15 to 16 and lost the standard SSL-VPN on forticlient. So we migrated the vpn remote access config on IPSEC restoring user groups, policies etc etc. The only issue I still have is to have the Forticlient (now connected by ipsec) use the dns suffix I'm passing to the clients. I did all the standard config steps I've seen on other posts: set mode-cfg enable set dns mode manual set ipv4-dns-server set unity-support enable set domain <domain> but the client is still ignoring it. On the ipconfig /all of the vpn client I can see it gets the parameters (internal dns, domain suffix, routes) but if I try to resolve a domain host without the suffix it simply fails. I can still ping it and resolve it with the full domain name. Rules have been checked and I can r
Greetings, I have a fortivoice 200F8 and I am in the process of updating to version 6.4.9. I would like to know if anyone has had problems with this process.
Hoping for some real world use cases for the following setup where we are protecting a hardened front end web server that sort of proxies connections into our Horizon VDI environment.. We currently have a VIP on TCP.443 that publishes the previously mentioned web server into our VDI environment (Horizon) and we're currently restricting traffic on that corresponding rule by allowing only IP's in the United States and only the users WAN IP address given to them by their ISP but in some cases we're allowing some /16's that would encompass some of the more widely used ISP's within our footprint. We also use FortiAuthenticator so every VDI user must participate with MFA which is typically done off of FortiToken Mobile App and we run AV Scanning/IPS/etc. on that same rule, but the management of it all is becoming too cumbersome considering we'll have some 500 virtual desktops by the end of 2022 and even more into the coming years. What are some other viable way to restrict the traf
Anyone have this issue? I need follow the in progress case....
Hello everyone,In our environment we do have BYOD and Domain devices. For the BYOD the connection of Zero Trust Fabric Agent with EMS is perfectly fine. But we do have problems with the domain devices. Is there a way to tell the Zero Trust Fabric Agent to bypass dhe proxy that the endpoints have on their regedit ? #FortiClient EMS #ZeroTrustFabricAgent
Dear All, Can someone help me about my FortiGate-40F and Ubiquity Switch and Routers when Windows is want to connect to WiFi ubiquity WIFI in FortiGate this device is being remove all Windows devices except to smartphone only smartphone can use this the WiFi. Set up is i created a VLAN on LAN1 range of 192.168.8.5 - 192.168.9.254 and the on the Ubiquity Controller i created the same name and VLAN number Sorry for the English :D Please see attached Pictures. Thank you,
hi,the DNAT uses VIP for inbound traffic, i.e. internet to private LAN/host.is the outbound traffic stateful, meaning it uses the same VIP public IP for outbound?or do i still need to configure a separate outbound FW policy and use the same VIP?
On new computers, with Windows 11, if you install new versions of Forticlient, it does not check the C++ dependency for .NET/Visual Studio and cannot connect if the company uses Azure SAML authentication, the popup to enter email never appears. Symptoms and behaviors of the problem:1- After installing Forticlient on Windows 11, the icon does not appear in the toolbar near the Windows clock. However, the Windows service remains running.2- If the company uses Azure SAML cloud authentication, the popup to enter email and password never appears, it gets stuck on the "connecting" screen. 3- Still not work if trying to change to display popups via browser, nor delete cookies, nor bypass certificate warnings, trying all combinations of options, nothing works, neither the browser nor the pop-up appears without C++. Solution: Manually install C++ redistributable. Tested in Forticlient v7.2.x v7.4.x Screen with "connecting" error forever:
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.