Mark a Best Answer
Fortinet Community
Recently active
Hi , I am preparing for the NSE 6 Security specialist exam. Is this mandatory to write the 4 specialist exams to clear the NSE 6 certification? Certificate Name: NSE 6 - Security Specialist Requirements: Complete 4 Fortinet Specialist tracks Exam: Specialist Exams[style="background-color: #ffff00;"] (or coursework where no exam exists)[/style] Recommended coursework: Fortinet Specialist courses In this what it is mean by (or coursework where no exam exists) . Instead of writing the exam can we complete the NSE 6 certification while going those self placed courses? [ul][style="background-color: #ffff00;"]FortiWeb Self-Paced Course[/style] + FortiWeb Facilitated LabFortiWeb Instructor-led Course + Lab .FortiMail Instructor-Led Course .FortiWireless Course .[style="background-color: #ffff00;"]FortiAuthenticator Self-paced course[/style] + FortiAuthenticator Instructor-led LabFortiAuthenticator Instructor-led course and lab.FortiDDo
A prominent US-based specialty engineering and construction company faced challenges centralizing security controls, gaining visibility into traffic patterns and intrusion attempts, and applying policies at the application level within their cloud infrastructure. They turned to Fortinet Cloud Consulting Services to develop a comprehensive cloud network security design tailored to their unique requirements to ensure top-tier security and operational efficiency on AWS. Guided Expertise in Selecting the Right Cloud Architecture The Fortinet Cloud Consulting Services team worked closely with the customer to create an architecture that emphasized scalability, reliability, and robustness. The Fortinet consultants outlined multiple options, highlighting their unique benefits and potential challenges. This in-depth analysis enabled the customer to make informed decisions, ensuring their infrastructure not only satisfied current needs but was also adaptable for future advancements
Hello everybody, I have a Fortigate F60 device (v 7.2.10).this Fortigate is implementing a conditional DNS for the Wi-Fi interface.For some internal domain, I registered some DNS records:192.168.1.1 is the router address.Normally, everithing works, fine. If I try to ping one of the registered names (for example vpn.xxx.com):   10.1.0.1 replies to the echo request. 10.1.0.1 is the Fortigate address.These are my network settings:  So far, so good. Now I try to connect via Cisco Secure Client to a VPN.Regarding network settings, nothing has changed. My address is the same, Router address is the same, DNS address is the same. The interface is the same, so, if I ping the same address as before, I expect 10.1.0.1 to answer (as before), but now: 79.9.x.x is replying. Who is 79.9.x.x? Is the Fortigate WAN interface:And the domain vpn.xxxx.com, if I put it into the browser, is not reacheable anymore, because I think DNS is not functioning correctly. What am I missing?Thank you fo
I'm using a Fortigate 4200 running firmware 7.4. Most of our rules use FQDNs like www.microsoft.com but this seems very permissive. Ideally we'd like to examine the actual URLs being used and restrict i.e. allow things like http://www.microsoft.com/crl or https://www.microsoft.com/crl. We have many applications/systems that don't support explicit proxying so explicit proxy is not an option. So in the absence of using an explicit proxy is this possible?
I am using FortiClient VPN Version 7.4 on Windows 11 24H2. When I connect to the VPN using FortiClient VPN, an IP address is not assigned, and I am unable to access the internet after connecting to the VPN. If I uninstall and then reinstall FortiClient VPN, it connects without any issues the first time, but from the second attempt onward, an IP address is not assigned, and I cannot connect to the internet. This issue occurs on two identical PCs. Of course, when using the VPN, the Wi-Fi is set to DHCP. If anyone knows the cause of this issue or has experienced the same problem, I would appreciate your help.
Hello guys, in our Fortigate we have list of few hundreds dynamically assigned IPs in Quarantine.And I found this topic, where is some Quarantined MAC addresses are automaticaly filled into Address Group list named Quarantine Devices. https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/900942/quarantine So I am courious is there some way to do similiar thing with our list of IP addresses? We want to create deny rule in firewall with this address group.
Hello, Can you recommend some basic/advance tests to apply on the Firewall after configuring it, to ensure that everything is working properly. Thank you,
HI, i am trying to configure authentication with LDAP in my fortiweb just for admin user I configured: https://docs.fortinet.com/document/fortiweb/7.4.5/administration-guide/410257/grouping-remote-authentication-queries-and-certificates-for-administrators#Configuring_tacacs https://docs.fortinet.com/document/fortiweb/7.4.5/administration-guide/286471/administratorsFortiWeb #ldap if i do a test user in the remote server configuration i get succeful, but if i want to loggin with the ldap user i am not able.
Hello everyone!I am experiencing some weird behaviour with login on Fortigate device with os 7.4.4 and 7.4.5.I can successfully login on the device with whatever username (but no one local username, try for example username: qwerfdsa) as long as the password is correct (the password of a local user or from a tacacs+ server).I discovered this by mistakeThere is anyone who also discovered this problem?And also, there is a way to solve this problem?
Hello,In the NSE guides Fortinet says that at a minimun you need 2 FortiGates and a Fortianalyzer.We are deploying 1 Fortigate,1 Fortiproxy and 1 Fortianalyzer.Being that fortiproxy is VERY similar to Fortigate in many aspects, Can I set up the Security Fabric with these 3 devices? Maybe selecting the Fortigate as the root device,and the proxy as a downstream device?All verisions: 7.4 Thank you in advance.Regards.
Hello everyone,I am pretty new to Fortinet community and I need some help regarding the activation of MFA SMS functionality on Fortigate 60F 7.2.9. :)If I understood correctly, we have 2 options: getting a FortiGuard Messaging license or getting a 3rd party provider SMS gateway. Either way, the documentation says I need to configure SMTP server.Is it necessary to go through SMTP server, that is to go through email2sms or can I just go directly and define my custom sms-server (provider's domain) and sms-phone to which I want the OTP to be sent and if it is necessary why is that if it's not too much of a trouble explaining?
HI All, Have a setup where I have a pair of Fortigate FW cluster (A-P) connected into ACI Fabric under a VRF1. Have BGP configured to learn routes dynamically . There is a new requirement to create a new VRF2 on the Fabric and move this BGP connection onto that .While configuring this on the firewall we plan to create a new interface in the same zone and plan to move traffic from Link 1 to Link 2. Now it is understood that when we do this we will end up breaking existing connections which are in the session table ( with successful 3 way handshakes) . Trying to find a solution where by we can move the traffic from the primary link to secondary link without impacting existing connections. Any ideas ?
Hello,we are using FortiAnalyzer together with the Outbreak Detection module. To make our work as easy as possible, we want to work with playbook We know how to create a playbook for a handler and also for a report. The problem with the Outbreak Detection module, however, is the large number of handlers, each of which has its own report. We want to save ourselves the work and do not want to create a separate playbook for each handler. So the question here is whether and how a playbook can be configured for all handlers? FYI: We already know this community contribution, but it is no help to us.https://community.fortinet.com/t5/Support-Forum/Custom-Playbook-to-notify-for-any-Outbreak-Alert-FAZ/td-p/289890 Thank you
Hello All, The Microsoft Defender Endpoint vulnerability scanner is detecting the following vulnerable files created as part of the Forticlient 7.4 VPN Installer, all with the version number 3.1.5.0:c:\program files\fortinet\forticlient\libcrypto-3-x64.dllc:\program files\fortinet\forticlient\libssl-3-x64.dllc:\program files\fortinet\forticlient\x86\libcrypto-3.dllc:\program files\fortinet\forticlient\x86\libssl-3.dllThe listed CVE's against these files from MDE Show as:CVE-2024-2511CVE-2024-4603CVE-2024-4741CVE-2024-5535CVE-2024-6119Is the Forticlient 7.4 VPN software vulnerable to these CVE's because of the libcrypto/libssl dlls present in it's install directorys?
Hi,On FortiGate 100F I create vlan50, vlan60, vlan70 and make port1, port2 as trunk(vlan50, vlan60, vlan70), how can I make port3 access vlan50?
Hello everyone, I am in the process of building a short report for firewall policy usage and I am having a bit of a time trying to retrieve the firewall policy usage from any "diag" commands. Unfortunately, I don't have API access to the devices that I will need to run this against. Any thoughts appreciated!
Hello, I use the forticlient vpn an android 8.1 for sslvpn. I would like to use client certificates and username/password to authenticate. I need to use the certificate store from my android device to select the client certificate. At the moment only an import of a PKCS12 is possible.Is there any chance to use the certificate store from android? I know other vpn clients like openvpn can use this, but these client can not connect to my fortigate 101E. Thanks Markus
Dear Support Team,I am writing to seek assistance with an issue I encountered on your platform.Under https://fortiphish.com/users all Azure AD Users wer added, I can see them.Under https://fortiphish.com/user_groups I see all Azure AD groups.But when I create a campaign https://fortiphish.com/campaigns/create in step 3 Select a target I only see the Azure AD groups.Why?I look forward to your response.
Hello everybody, some days ago I received this error on my Fortigate F60 (v 7.2.10):msg="User shutdown the device from forticron. The reason is 'System file integrity check failed'"I searched for this error and I found the following guide: https://docs.fortinet.com/document/fortigate/7.2.5/administration-guide/249947From this guide, I didn't understand very well. I'll try to explain:what I understood is that this error appears beacause BIOS security level is 2 (I confirm) and, because the firmware (as well as the AV engine etc.) is signed by the Fortinet CA and a third-part CA, this integrity check fails.Now, I have two question:1) Who is this third-part CA?2) If there is an integrity check error, how is it possible that the solution can simply be setting the security level to 1? How can we simply ignore this error?I think I'm missing the point. Can someone explain to me this concept in a simple way?Thank you so much!
Dear community, we have laptop users whom which are connected with VPN's based on US. but on the same laptops softphones are installed. which are connected with local SDWAN interface, calls works smoothly but if we bring local interface down and we switch to VPN for the backup. calls still established but one way audio occurs while switching.
Hello everyone, I'm trying to create a small VM lab based on a FMG and a few FGT. I did set up every VM correctly but I'm facing an issue whenever I add a Fortigate to the FortiManager and try to push a new policy package to the FGT. Looks like it's a problem about certificates. Install History:HUB-1 80% 2020-07-02 05:12:34:fgfm install state: prepare to post-checksum HUB-1 90% 2020-07-02 05:12:40:post-checksum state: start verification HUB-1 95% 2020-07-02 05:12:44:verify state: install OK/verify FAIL Install Logs: Starting log (Run on device) Start installing FortiGate-VM $ config vpn certificate ca FortiGate-VM (ca) $ edit "root_CA2" FortiGate-VM (root_CA2) $ set ca "-----BEGIN CERTIFICATE----- FortiGate-VM (root_CA2) $ MIIDADCCAeigAwIBAgIgRTk2MjE0OTk5NDk3QkM3NUREQTQyRURBMTg4NEExQ0Qw ... FortiGate-VM (root_CA2) $ iXJK2fIdzPWUqEHExeVawvcCZBxzpw7dwB5fdKCyZ6Zj+FVVY+Q+TrPNyIfiirRc FortiGate-VM (root_CA2) $ vi5lVQ== FortiGate-VM (root_CA2) $ -----END CERTIFICA
Hi Team, Is there a Windows11 Pre-Configured VMs for Customized Virtual Machine in FortiSandbox ? In the below help.fortinet.com, it only has till Window 10 https://help.fortinet.com/fsandbox/olh/2-5-1/Document/D00_Create%20Custom%20VM%20Image/Appendix%20D%20-%20Custom%20Pre-Configured%20VMs.htm #Fortisandbox
Hi Team, I have Head office and multiple branches around 30, want to configure Ipsec vpn so that all branchces communicate to each with head office. Can anyone suggest perfect method to achieve this task. Thank you.
Hi All,We have issue to start LVM on Fortimanager OS (see below pictures). Do you know what could be missing? System InformationHost NameFMG-VM64-XEN Serial NumberFMG-VM0000000000Platform TypeFMG-VM64-XENHA StatusStandaloneSystem Time Mon Sep 02 01:57:15 2019 PDT Firmware Versionv6.2.1-build1121 190718 (GA) For any further information, do not hesitate to contact us.Thanks in advance.Anargyros
Hey, We have 4 locations that we use Aruba APs and works well. Now we have 1 more location and have 4 AP's in the location. AP02 is the VC that assigned by Aruba Central and we cloned the working location's configs in this location. After that, we created VIP .20 and added to the FortiNAC. Credentials are working but in this location we can't see the ports or SSIDs. How can we solve that? Thanks in advance. This is the new location; Working location;
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.