Mark a Best Answer
Fortinet Community
Recently active
Good morning, we purchased 2 FortiGateVM-2 licenses On the first machine we purchased the FortiCare / FortiGuard subscription while on the second one we did not.When we put the two VMs in active/passive HA we lose the FortiCare subscription also on VM1 Why?
Hi,I want to generate a specific FortiAnalyzer report as a PDF file, which contains all policy changes of my in total 10 fortigates. Each fortigate has in total 5-10 policies. My ambition is to get an monthly automatic generated PDF report of all policy changes from all policies and fortgates I've done during this time. The report should list the following issues: Policy ID, Device ID, Device Name, Source IP, Destination IP, Source Interface, Destination Interface, Action, Log ID & the Timestamp of the change. So I've seen in the FortiAnalyzer, that there is no pre-generated report like that.I know this report is possible with SQL code/ dataset only. So I've started a small and non finish SQL code because I'm a SQL beginner. This ist my SQL code currently: My question is, can anybody complete my SQL code so that all issues are included and the validation without any warnings?And can anybody explain me the nessecary steps and settings I've to do in FortiAnalyzer
Hello When my Fortimail 200E device boots, I only have an option to press F2 or F10 and nothing else.Seems like the HDD and Cache was formatted. How do I go about reloading the .out file if no TFTP menu option is available? Thanks
need to change the password policy on some FortiGates. That part is pretty straight forward. Am curious as to what occurs after. Are existing passwords still accepted, or is the user forced to change their password on the next login? Mainly curious as to how this affects the local admin account.
Hi,I have configured an Application Control profile and applied on a firewall policy. The application control profile have "block applications detected on non-default ports" enabled. However, when I run Telnet on other ports than 23 the traffic is allowed and it's also detected as application Telnet according to the logs on FortiGate.I have verified that the traffic is hitting the correct firewall policy.I am running FortiOS 7.4.5.Please see my configuration on attached pictures.What am I doing wrong? Shouldn't this traffic be blocked?
Hi all, I have a requirement to connect multiple VRFs using PPPoE credentials on different vrfs. The issue is that the PPPoE all need to be in the same VLAN and VDOM if possible. How can this be done as I've come against duplicate VLAN ID errors when trying to set it up?
Hello Fortinet Community!We’re experiencing some intermittent and location-specific issues with FortiClient EMS (v7.2.4 build 0983) and FortiGate 60F (v7.2.10 build 1706) after upgrading our FortiClient licenses from the free to the paid version with EMS implementation. All endpoints are macOS devices running different OS versions. I’m hoping to get insights or solutions from anyone who has encountered similar issues.Current Setup:Implemented FortiClient EMS with endpoint profiles configured for Remote Access, Web Filtering, Malware Protection, and Vulnerability Scanning.Both On-Fabric and Off-Fabric rules are configured, primarily distinguishing internal subnet access (10.10.X.X/24 for internal users).All endpoints are Mac devices and are not connected to an AD or DC; endpoint management is done solely through FortiClient EMS.Issues:Google Chrome Profile Logouts & Missing Bookmarks: Some remote users report that, when the issue occurs, they’re logged out of their Google profile in
hi we are using 2 600E in ha cluster, and today lot of complaint were received from end users that services got stop working. when i login on firewall the error was displayed as per subject and memory graph was in between 82-85%. We never faced this issue before so after few googling we tried to disable IPS but this did not help out (may be take some time to get memory down), so finally firewall was rebooted and secondary firewall becomes primary, memory goes at 67%.and everything start working fine. can somebody please suggest1) how can we prevent this in future as our env is a very critical and cant afford any downtime due to this issue2) how can we generate an email alert if conserve memory threshold value exceeds 75% or is there any way to prevent this error occurring again?2) can we add more memory to device?
Dear all, Is there any option to configure in order to automatically fill the field for the Zero Trust Telemetry after installing FortiClient EMS Agent without entering it manually ? Thank You#FortiClientEMS
Hi allI have a problem with the FortiAP 221EI have a fleet of 50 FortiAPs on different networks interconnected in MPLS.FortiAP management is done via a FortiGate 600E and a FortiManagerThe FortiAps are all in 7.0.6The FortiGate is in 7.0.11The FortiManager is in 7.0.7Here is the problem :For some reason that I cannot identify, from time to time (on average one to two terminals per week), the terminal no longer responds to a ping with a packet size > 1500. Example ping –l 1800When the problem occurs, I test the ping from the terminal's LAN, to rule out any MPLS fragmentation problem.This makes the terminal unusable for customers (out of service captive portal, out of service PC authentication, etc.) anything that uses SSL no longer works. They therefore become unusable. On the other hand, a normal ping (< 1500) continues to work.When this happens, I reboot the terminal (via the FortiManager or via the web interface of the terminal) and after restarting, the terminal is OK, the fra
Hello, I have a FortiAP 431F. I would like to use 5Ghz for both radios but it doesn't appear to be possible. I tried to create a new profile with the same and a different platform to see if that would work but then I can't apply the different platform profile to the 431F. Any ideas?
Hi All, I've noticed a difference between FortiManager and FortiGate that I want to understand, and I'm hoping someone can help.We have a group of FortiGates (v7.4.5 build2702) that were recently added to a FortiManager (v7.4.5 build2553). If I log into one of the FortiGates, I can see that we have an SSL-VPN setup that limits access to specific hosts and then has two groups of hosts - but the negate switch is turned on, which means anyone can try to connect EXCEPT someone in one of those groups: When I look at the same config in the FortiManager, there is no negate switch, meaning only those groups can try to connect - the opposite of what we want: My concern is that if I push the config from the FortiManager, it will not push the negate switch, and I'll lose access to the firewall as I'm coming through the SSL-VPN.If you're building a VPN from scratch, how do you configure the negate switch in FortiManager? Thanks
How to do we restrict SSL VPN connections from active directory domain joined machines only? Plan is other devices should not be able to connect SSL VPN. Thank you!
Hi All,Been searching through docs but haven't found a clear answer...What TCP / UDP ports are required for FortiClient to comm with a cloud hosted EMS? Is it all just over TCP 443?And then - with all the individual services (exe's) installed with FortiClient, which specifically will comm with EMS?If there is a doc published somewhere please share;Thank you!FortiClient FortiCloud Products
Hi there, I need a little help, everything was working well yesterday, I was able to create and deploy phishing campaigns normally, but today when I tried to deploy new campaigns suddenly all my new fortiphish campaigns are stuck on processing and not sending e-mail anymore. When creating a new camaign, sending the test e-mail works normally, looking my licenses everything is ok, anyone had this issue before? best regards
Hi FGT/FAP adminsI have a SSID in tunnel mode where I enabled "block intra-SSID traffic".Now I need to allow intra-SSID traffic only between some specific clients on some specific ports. Is there a way to do that? I mean just the same way we do with zones (deny intra-zone traffic then enable exceptions with firewall rules).
Hello, i got problem when cant upgrade firmware,there is pop up "No available firmware From Fortiguard", i have try this method https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-No-firmware-available-from-FortiGuard-under/ta-p/198619 this the result FortiGate
Hello Fortinet Community,I am currently working with a FortiGate firewall 61F v7.2.6 setup where I have a VLAN switch interface named bgroup0 with a physical connection to internal3. The IP address assigned to bgroup0 is 192.168.1.1/24, and it is connected to an Aruba switch.The goal is to have new devices that connect via LAN cable to the Aruba switch send DHCP requests to the bgroup0 interface. However, for security purposes, I would like these devices to receive IP addresses from a different subnet, such as 192.168.2.0/24. I initially tried using a secondary IP, but due to subnet conflicts, this did not work as intended.I am considering configuring DHCP Relay on the bgroup0 interface to forward these DHCP requests to another DHCP server(internal2 or internal5) that is configured to assign IP addresses in the 192.168.2.0/24 range. However, I am uncertain about the exact configuration steps required to achieve this.Could anyone provide guidance or confirm if this approach is feas
Hello,- We use "Forticlient VPN" software to connect to our organization network from external sources (e.g. computer at home) through our Fortigate firewall.- We use "Forticlient" (Zero Trust Fabric Agent) as the antivirus solution in our organization PCs (they connect to our "FortiClient Endpoint Management Server").What are the steps to run both VPN client and antimalware client on the same computer? We need to connect to our VPN from a laptop which has got "Forticlient" (as antivirus) installed, but it looks like it's not possible to have both that and "Forticlient VPN" installed ad the same time, and the Forticlient doesn't show any VPN-related option, so we are at a dead end. I guess there is some way to enable the VPN features in the Forticlient software, but I have no idea how.Any help would be very appreciated, thanks!
HelloFortiWeb 6.3.9 and FortiAuthenticator 6.4.9.My FWB is configured to authenticate admins (for admin access) via RADIUS authentication with FAC and it works just fine.This issue comes when I want to use HTTP authentication, for users when they want to access some protected Web servers.I configured like explained here:https://docs.fortinet.com/index.php/document/fortiweb/6.3.9/administration-guide/467409Now when a user tries to access a protected server, it shows HTTP authentication window, but when user enters correct username and password, FWB still returns error 401 (unauthorized), even if my FAC logs show the related authentication was successful.For info on FWB's RADIUS config, when I test the authentication with the same credentials it works fine.
I need to use Azure Front Door as a WAF up front to on-premis Fortigateand with the FrontDoor_Header_Check - used to Application Control function block whole traffic except FrontDoor ID and i'm not sure how to create/which parameters to used to custom app signature for this traffici have only X-Azure-FDID number, i can't find anythink corrent in to Azure documentation https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-apply-and-validate-a-custom-applica... is not really legibledoes someone have any experience with this and can give me any direction?
Hi Forum,I have recently tried to upload a number of large zip files (500MB - 2GB) onto FortiSandbox for analysis.I have checked the settings, even 2GB should still be allowed.However, I am stuck on 100% on the uploading process until timeout (increased to 60mins) kicks in.I have also tried to change the prescan-config time but it does not allow somehow,https://docs.fortinet.com/document/fortisandbox/latest/cli-reference/707722/prescan-config I then split the files into multiple smaller files with 7zip.But somehow only zip.001 has promising file count (e.g., 1001) and the rest (zip.002, zip.003, etc) only have 1 file count. Here are my questions,How to change the prescan-config if it is why my uploading process got stuck?How does the scanning mechanism work? Would the analysis still be accurate for multiple split zipped files?If multiple file anaylsis is feasible, how do I consolidate the multiple reports into one?Thank you!
Hello, Our user need access to 3rd party application via VPN, they use Sophos VPN for VPN client.This traffic is blocked by fortinet because of the application control, then i make 'application and filter overrides' for OpenVPN and the user is able to connect to the VPN now.With this condition the user can access to any OpenVPN address. Now can we restrict to only allowing use OpenVPN if the destination set to 'vpn.mycomain.com' and block the rest?
We are thinking about making the jump to it and getting off the 7.0.x branch (mainly for missing features).The upgrade path tool seems to indicate it would be a two step process- we'd have to go to 7.2.10 and then 7.4.5Any big surprises / issues we should be wary of, either during the upgrade process or with daily use of 7.4.5?
Hi , I am preparing for the NSE 6 Security specialist exam. Is this mandatory to write the 4 specialist exams to clear the NSE 6 certification? Certificate Name: NSE 6 - Security Specialist Requirements: Complete 4 Fortinet Specialist tracks Exam: Specialist Exams[style="background-color: #ffff00;"] (or coursework where no exam exists)[/style] Recommended coursework: Fortinet Specialist courses In this what it is mean by (or coursework where no exam exists) . Instead of writing the exam can we complete the NSE 6 certification while going those self placed courses? [ul][style="background-color: #ffff00;"]FortiWeb Self-Paced Course[/style] + FortiWeb Facilitated LabFortiWeb Instructor-led Course + Lab .FortiMail Instructor-Led Course .FortiWireless Course .[style="background-color: #ffff00;"]FortiAuthenticator Self-paced course[/style] + FortiAuthenticator Instructor-led LabFortiAuthenticator Instructor-led course and lab.FortiDDo
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.