Mark a Best Answer
Fortinet Community
Recently active
Hello,we have a problem when the captive portal load over android device and the user accepts the terms the browser closes automatically without going to the forwarded address on the other hand when you do that on an IOS device the browser stays open and forward the user to the site we have set.
Hi,I got isssue with access to fortisiem from web browser, is said that the service is unavailable.below is the result when i run phstatus command on server.and i not sure how to start AppSvr and other processes which are down. [style="background-color: #ffffff;"]PROCESS UPTIME CPU% VIRT_MEM RES_MEM[/style] [style="background-color: #ffffff;"]phParser DOWN[/style] [style="background-color: #ffffff;"]phQueryMaster DOWN[/style] [style="background-color: #ffffff;"]phRuleMaster DOWN[/style] [style="backgrou
Hi community, I'm connecting a fiber connection to the firewall with speeds between 350 and 450 Mbps, but I'm only getting 10 Mbps in return. I understand that there will be some speed reduction, but is this normal??? I have disabled all security features in the firewall policy and the "threat-weight" configuration, but I am still experiencing the same speed issues. Here is my configuration. Please, if you have any advice on how to increase my internet speed, I would appreciate it.
Fortinet Firewall 200FI want to allow each and every page before and after of manageengine.com I add an entry *.manageengine.com/* with Wildcard, Exempt and Enable but I am not able to allow all websites
my FortiAnalyzer https certicate expired. got a wildcard ssl for my domain from sectigo. when i import it in analyzer it fails with its already imported but i cannot see it on the list of certificates. my analyzer vm was on version 7.4.5, updated to 7.6.1 and its the same behaviour
Installed new version of Forticlient (vers 7.2.4.0972).we setup up Azure SSO on fortigate v7.when running connect on client .. getting pop up "Script Error"(review screenshot)script error (error has occurred in the script on this page).Error: Access denied.code: 0URL: about blank I have uninstalled and reinstalled application, on 2 different devices and same issue. Can anyone assist? Anthony Abela
Hi people,I just updated a firewall from 7.0.15 to 16 and lost the standard SSL-VPN on forticlient. So we migrated the vpn remote access config on IPSEC restoring user groups, policies etc etc. The only issue I still have is to have the Forticlient (now connected by ipsec) use the dns suffix I'm passing to the clients. I did all the standard config steps I've seen on other posts: set mode-cfg enable set dns mode manual set ipv4-dns-server set unity-support enable set domain <domain> but the client is still ignoring it. On the ipconfig /all of the vpn client I can see it gets the parameters (internal dns, domain suffix, routes) but if I try to resolve a domain host without the suffix it simply fails. I can still ping it and resolve it with the full domain name. Rules have been checked and I can r
Greetings, I have a fortivoice 200F8 and I am in the process of updating to version 6.4.9. I would like to know if anyone has had problems with this process.
Hoping for some real world use cases for the following setup where we are protecting a hardened front end web server that sort of proxies connections into our Horizon VDI environment.. We currently have a VIP on TCP.443 that publishes the previously mentioned web server into our VDI environment (Horizon) and we're currently restricting traffic on that corresponding rule by allowing only IP's in the United States and only the users WAN IP address given to them by their ISP but in some cases we're allowing some /16's that would encompass some of the more widely used ISP's within our footprint. We also use FortiAuthenticator so every VDI user must participate with MFA which is typically done off of FortiToken Mobile App and we run AV Scanning/IPS/etc. on that same rule, but the management of it all is becoming too cumbersome considering we'll have some 500 virtual desktops by the end of 2022 and even more into the coming years. What are some other viable way to restrict the traf
Anyone have this issue? I need follow the in progress case....
Hello everyone,In our environment we do have BYOD and Domain devices. For the BYOD the connection of Zero Trust Fabric Agent with EMS is perfectly fine. But we do have problems with the domain devices. Is there a way to tell the Zero Trust Fabric Agent to bypass dhe proxy that the endpoints have on their regedit ? #FortiClient EMS #ZeroTrustFabricAgent
Dear All, Can someone help me about my FortiGate-40F and Ubiquity Switch and Routers when Windows is want to connect to WiFi ubiquity WIFI in FortiGate this device is being remove all Windows devices except to smartphone only smartphone can use this the WiFi. Set up is i created a VLAN on LAN1 range of 192.168.8.5 - 192.168.9.254 and the on the Ubiquity Controller i created the same name and VLAN number Sorry for the English :D Please see attached Pictures. Thank you,
hi,the DNAT uses VIP for inbound traffic, i.e. internet to private LAN/host.is the outbound traffic stateful, meaning it uses the same VIP public IP for outbound?or do i still need to configure a separate outbound FW policy and use the same VIP?
On new computers, with Windows 11, if you install new versions of Forticlient, it does not check the C++ dependency for .NET/Visual Studio and cannot connect if the company uses Azure SAML authentication, the popup to enter email never appears. Symptoms and behaviors of the problem:1- After installing Forticlient on Windows 11, the icon does not appear in the toolbar near the Windows clock. However, the Windows service remains running.2- If the company uses Azure SAML cloud authentication, the popup to enter email and password never appears, it gets stuck on the "connecting" screen. 3- Still not work if trying to change to display popups via browser, nor delete cookies, nor bypass certificate warnings, trying all combinations of options, nothing works, neither the browser nor the pop-up appears without C++. Solution: Manually install C++ redistributable. Tested in Forticlient v7.2.x v7.4.x Screen with "connecting" error forever:
What are settings ADOM-level database ?
Hi everyone,I'm at my wit's end trying to configure SD-WAN with BGP on loopback with segmentation over a single overlay (no ADVPN). Here's the situation:Problem:Hub and Spoke tunnel connectivity is established.Pinging from Spoke's loopback to Hub's loopback fails (packets are dropped on the Hub side).Pinging from Hub's loopback to Spoke's loopback works fine.I’ve triple-checked the following:Firewall policies. (overlay -> Loopback: any any)Local-in policies.Routing.Interface configurations.The Hub's local traffic log shows the packets arriving, but there are no replies. Application ControlApplication NameBGPProtocol6ServiceBGPDataReceived Bytes0 BReceived Packets0Sent Bytes0 BSent Packets0VPN TypeipsecvpnMessageConnection FailedActionActiondenyThreat262,144Policy TypeFirewall Packet Sniffer:Confirms the packets are entering the Hub but vanishing with no response.Configuration Details:Here’s the relevant config for both Hub and Spoke:## Hub ##config system interface edit "L
Hello In cisco switches you are able to "show" mac address by port with "show mac address-table interface gigabitEthernet0/1" it is possible to do the same in a Fortigate appliance? Thanks
Howdy all,I am trying to view Deny traffic logs on a Fortigate 30E(FortiGate 30Ev6.2.15 build1378 (GA)and they are not showing up.Via the CLI - log severity level set to WarningLocal logging Here is the details:CMB-FL01 # show full-configuration log memory filterconfig log memory filterset severity warningset forward-traffic enableset local-traffic enableset multicast-traffic enableset sniffer-traffic enableset anomaly enableset voip enableset filter ‘’set filter-type include The Fortigate is getting hammered, with alerts coming in thusly: (Sanitized) Message meets Alert conditiondate=2024-11-14 time=15:04:05 devname=CMB-FL01 devid=FGT30E5777885133 logid=“0000000013” type=“traffic” subtype=“forward” level=“notice” vd=“root” eventtime=1731621845329636171 tz=“-0700” srcip=194.264.22.254 srcport=56676 srcintf=“wan” srcintfrole=“wan” dstip=93.22.3.19 dstport=10443 dstintf=“lan” dstintfrole=“lan” sessionid=3808968 proto=6 action=“deny” policyid=0 policytype=“policy” service=“
I pressured my FortiNet rep into giving me a more fully functional trial license with some VDOMs so I could figure out how to configure VDOMs. I've got the basic stuff configured. I've figured out how to make the connections between the Root and the 2 VDOMs under the root. I've figured out how to create a VIP from the root to 1 of the VDOMs for web hosing. Now I'm trying to figure out SSLVPN. One of my VDOMs will run SSLVPN (let's say VDOM-B). I've followed the directions here https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-access-to-multiple-VDOMs/ta-p/223709 to tell that VDOM it's going to run on port 6443 as well as created all the rules shown in the link. This is all being done within EVE-NG, it's a purely secluded network, no real traffic gets in or out. On a system that I'm trying to 'vpn' with into FortiGate, If I try to browse to https://40.64.58.147:6443 (purely made up IP one of the great thi
Hello, I can't access forticloud. It shows as shown in this picture. I have 2fa using forti token mobileOn the mobile app, it pops up to approve, but after approve, it says login validation failed token code is invalid I tried to do lost Fortitoken and when I got to this page, no sms code was sent to my number. Please help me.
Hello team! Is there a way to create VPN ipsec which could use domain users (AD) and use 2FA for each user?In this case, is there a way to use 2FA through email?I think, to configure a different 2FA for each user, these users should be in Fortigate, but I ask just in case that there is anything else that I cant see.If not, do you know any other VPN which would allow this? Is this possible with ZTNA? (I am still very noob with ZTNA), in this case I will need to learn more Thanks in advance.Regards,Damián
Hello: I have a Fortinet 60F, I changed the wan1 connection to Starlink, addressing mode dhcp and static route with dhcp too. If I enable wan1, the PCs can have internet with Starlink and with the other connection but the VPN drops, I have to disable wan1 for the VPN to work. I don't know if I have something else to configure or if the VPN is configured incorrectly, I have virtual IPs that point to one connection or another, I don't know if it is that, I attached one with the Starlink connection.We use forticlient for vpn connection.I hope you can guide me to solve these problems.Greetings
After upgrading my 248DF to 3.6.12, the unit is online and active, but shows offline and I cannot connect to it through fabric. I removed power for 15 sec and plugged back in and still shows offline. Suggestions?
What is the difference between Addresses vs Wildcard FQDN Addresses on Fortimanager?
Heya,Is there an official list or table to tell me what color is tied to what integer in the 'set color' command under the 'config firewall address'?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.