Mark a Best Answer
Fortinet Community
Recently active
Hey, We have 4 locations that we use Aruba APs and works well. Now we have 1 more location and have 4 AP's in the location. AP02 is the VC that assigned by Aruba Central and we cloned the working location's configs in this location. After that, we created VIP .20 and added to the FortiNAC. Credentials are working but in this location we can't see the ports or SSIDs. How can we solve that? Thanks in advance. This is the new location; Working location;
Hi, I was trying to create dedicated HA management port for the firewall cluster but "mgmt" wasn't listed as option under HA config. Could you please advice if i have missed any configuration here.# showconfig system interfaceedit "mgmt"set vdom "root"set ip x.x.x.x x.x.x.xset allowaccess ping https ssh snmp fgfmset type physicalset dedicated-to managementset role lanset snmp-index 2nextendFW01 (mgmt) # endFW01 (global) # config system haFW01 (ha) # set ha-mgmt-status enableFW01 (ha) # config ha-mgmt-interfacesFW01 (ha-mgmt-interfaces) # edit 1new entry '1' added# set interface<string> please input string valueha interfacenpu0_vlink0 interfacenpu0_vlink1 interfaceport1 interfaceport2 interfaceport3 interfaceport4 interfaceport5 interfaceport6 interfaceport7 interfaceport8 interfaceport9 interfaceport10 interfaceport11 interfaceport12 interfacex1 interfacex2 interface# set interface mgmtnode_check_object fail! for interface mgmtAppreciate your response. TIA :)
We have a Fortigate 201F and its connected to the Internet and licensed for software updates, however, we noted that it is not showing the new firmware version 7.4 as available for download, the firewall is running version 7.2.10 and indicating that as up to date. We have another 201F installed at another location and that one has version 7.4.1 What could be the reason why this firewall is not showing the 7.4 version to be available for download? Regards.
Hi I did setup my ubuntu server to use SSH keys for authentication. I created a VIP to be able to access the server from outside and used proxy based mode. The connection fails when I trying to connect to the server. what would be the solution?
hi,i plan to configure SNAT in a FG with multiple VDOMs.i currently have the "internet VDOM" topology wherein "internet" VDOM act as our internet edge device and all downstream VDOMs will connect/flow through it to go to the public internet.my question, if i create a FW policy WITH SNAT in "VDOM-1", do i also create FW policy WITHOUT NAT in "internet VDOM" for traffic flow continuity?
Hello,We have deployed a Fortiproxy VM, and we already configured it and now we want to increase de size of de disk, wich is with the default of the OVF file wich is 32GB.Is there a guide to increase de size? I would assume we have to execute some command on the proxy after we increase the size in the ESXi side?Fortiproxy version: 7.4.x Any guidance please...Thank you in advance.Regards.
A IPSEC tunnel is already working from the main office to the Web App (3rd Party). What we need is traffic destined for the third party to pass through the main office from the remote office, which already is using an IPSEC tunnel for traffic to the main office. The company has only paid for 1 VPN tunnel, so I can't go directly from the remote office. I would appreciate any help. If more information/images are required, please let me know. Both the remote and main office firewalls are using Firmware v7.2.5 build1517 (Feature)
Hi,In one of our Interface (Explorer Data), the DNS Server was set as "Same as Interface IP".1. What DNS will the end device will be getting? We would like to know what DNS it was using if the end device uses FQDN, how it resolves its FQDN to IP Address. DNS Servers - SpecifyPrimary DNS server - 1.1.1.1Secondary DNS - 8.8.8.8 2. For the "dynamically obtained DNS server", what is its purpose? Is it the "same as interface IP", and would this be used to rely on the DNS server or FortiGuard?" Appreciate your comments and Thank you in advance.
hey, we are facing the access block issue on our website. it says you're not allowed to visit this. can anybody help me to fix this?
I have a customer in Canada reporting that he can’t access to our website and he got this alert from Fortiguard.It says "FortiGuard Intrusion Prevention - Access Blocked""You have tried to access a web page that is in violation of your Internet usage policy. Category : Phishing"Our website is https://www.wavepia.com . Apparently your system is defining us as a threat or something which is not. Please advise what we should do to regain our customer’s access to our website without your system blocking.
What is CVE-2018-11784? CVE-2018-11784 is an open redirect vulnerability impacting several versions of Apache Tomcat, specifically versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33, and 7.0.23 to 7.0.90. This vulnerability arises when the default servlet in Apache Tomcat incorrectly handles redirects to directories. For instance, if a user requests '/foo', the server might improperly redirect them to '/foo/' using a specially crafted URL, allowing an attacker to redirect to any URI. This could be exploited to redirect users to malicious websites without their knowledge. The Significance of Mitigating Open Redirect Vulnerabilities Open redirect vulnerabilities are crucial to mitigate because they can serve as a mechanism in phishing attacks, misleading users about the authenticity of a website. When exploited, these vulnerabilities allow attackers to redirect users from legitimate websites to malicious ones. This redirection can deceive users into believ
I am experiencing some strange issue when accessing sage on a server in the USA, that's only accessible via the GlobalProtect VPN platform. when on LAN using the cable, i can access sage but when on Wi-Fi via FortiAPs (221E) I cannot access sage. the policies for the cable and Wi-Fi are identical. I ones tested this on different network that has more or less the same setup as mine, with 221E fortiaps and 100F Fortigate fw and it works fine with no issues.
This is driving me mad.I have set up an IPSec VPN and want to limit it to a certain set of destinations.As I have two WAN links up, I'm connected on one and playing with the VPN settings of the other.I thought I understood how this works, but I'm now utterly baffled.I'm connecting with the FortiClient. I have my static routes pushed through OK so I can route to the destination network I want.Now when it comes to policies, I have set up a policy which has from the remote tunnel to the destination but this doesn't work.If I change the policy so the source interface is "any", it works.If I then change the policy so the source interface is the Remote Access WAN interface that's set up, it doesn't work, traffic gets dropped and is picked up by the default deny policy at the bottom.When I have the policy configured so that the source interface is "any" and it works, if I look at the policy logs, I can see the source interface is my RA WAN.So why doesn't it work when I set it to that interfac
I have two phones that are not registering with Fortivoice that are behind a site-to-site IPSEC VPN. The reason in Wireshark is. I can ping both sides with no problem and the DHCP option 66 is configured. There not much information about this in Google or any other documentation available. I hope anyone can help Spoiler (Highlight to read)NOTIFY sip:MACd476a0f758ce@xx.xx.xx.xx(Phone IP) SIP/2.0Via: SIP/2.0/UDP xx.xx.xx.xx:5656(FortiVoice IP);branch=z9hG4bKbK4f1731334589;rportRoute: <sip:MACd476a0f758ce@10.100.101.201>Max-Forwards: 20Contact: <sip:xx.xx.xx.xx;transport=UDP;handler=dum>To: <sip:MACd476a0f758ce@xx.xx.xx.xx>;tag=e9b466de-2d30-48e6-80c1-d33fc386c2adFrom: sip:MACd476a0f758ce@224.0.1.75:5060;tag=888888286Call-ID: 9c0ee096-b8a6-472a-ade1-66fa8cfb4affCSeq: 286 NOTIFYContent-Type: application/urlSubscription-State: terminated;reason=timeoutUser-Agent: FortiVoiceEvent: ua-profileContent-Length: 37NOTIFY sip:MACd476a0f758ce@xx.xx.xx.xx(Phone IP) S
Hello, we have a working tunnel (up) from one location to the other. From the remote location, the ping arrives our firewall, but it does not reply to them (they get timeout).Our ping seems to go through our firewall, but does not arrive the remote location (we also get timeout).Both traffic is visible in the logs.Policys from remote subnet to local subnet are there and vise versa. At least on our location, I'm waiting for response from the remote location. Also we have a (in my opinion) working static route for the remote subnet, pointing to the vpn-connection. Same interface / ip is also used for a second ipsec tunnel and this one is working fine (I get icmp: echo reply)Any ideas or troubleshooting hints?thanks
Hello, good evening from here. Please, for days now, I've been struggling to setup the FortiEMS license, and honestly I'm feeling like giving up. I don't know if anyone will be kind enough to assist me through, and I'll greatly appreciate it. Thanks
I have two ISPs, each one has two links feeding a pair of Fortigate 401 firewalls currenty set up in active-active HA.I've configured the SD-WAN and I believe it's working OK. Here is what I have in my SD-WAN:However, it appears that if I lose one connection from ISP, then the other connection from the same ISP is no longer used as all traffic goes to the other ISP.So a few questions:Is this normal ?Can I have it set up so that if one port is dropped, the other port is still used?Thanks.
Hi All,i need to connect two building with FortiAP outdoor (Distance = 100M).Which FortiAP model should I choose? Thanks
We are facing issue after upgrading the Fortimanager to version 7.6.1, where no data is visible in Fortiview of Fortimanager and showing error as below. Server Error:DB::Exception: Column 'XXX' is not under aggregate function and not in GROUP BY.if anyone know how to resolve this issue.
We are rolling out the IPSEC VPN delivered to Windows laptops using the EMS client. Right now, we have the LDAP authentication for the IPSEC VPN integrated with Duo MFA. Users receive a Duo push to their mobile phones at every VPN login or reconnect. Does anyone have a better MFA approach that would allow the device/user to be "trusted" for a period of time, so they don't get repetitive MFA prompts at every VPN login? I know there are lots of SSO/Integration options with the SSL VPN, but that appears to be going away, thanks to all the security issues. I can't find one that will integrate via LDAP/Radius with the IPSEC VPN. Thanks!
greetings all,we've being suffering from SD-WAN solution for a long time. Could someone please clarify some concepts in performance SLA under SD-WAN? 1.what is Probe Timeout under Link Status? how it is calculated exactly?the FortiManager says: Time to wait before a probe packet is considered lost (20 – 3600*1000 msec, default = 500)Is the time a round-trip time (RTT) as mentioned below, the RTT being addressed in a common network context? If it is RTT, then is the RTT in FortiGate the same RTT as being addressed in a common network context? Let's say:"The round-trip time is how long it takes for a request sent from a source to a destination, and for the response to get back to the original source. Basically, the latency in each direction, plus the processing time." 2. what is latency under SLA target? how it is calculated exactly?is Latency the same latency as being addressed in common network context? let's say:"Network latency is how long
since I've upgraded to 7.2.10 (7.2.9) before, my HA won't sync - since 14 days. Complained about the DNS-table and nothing helped, so I did a factoryreset on the secondary unit and configured the HA params only. Did a reboot and connected only the HA cables. This didn't help either, 30 tables out of sync (why???).Did another factoryreset and used the same config as on the primary unit and changed only the hostname and the HA priority before that. Restored the config - HA out of sync, this time "only" rule.fmwp and firewall.internet-service-name. Rebooted many times, executed "diag sys ha checksum recalculate" on both units, nothing!Fortinet, what have you done... Anybody else having such annoying sync-issues or and ideas how to get rid of it?BTW, "exec update-now" on the secondary unit failed with code -6, so I connected the device to the internet (isolated) and did a "exec update-now". No errors there but still the same result...
I have been testing the Forticlient EMS upgrade from 6.4. 7 -> 7.0. 11 -> 7.2. 5 for the past few days.I only want to perform the FortiClient upgrade on clients in the office (on-Fabric), and NOT the connected VPN clients.The only option I see is to temporarily remove the Off-Fabric VPN rule set from an existing Policy, and then use the relevant Endpoint group for Deployment.Please let me know if there is a better way to do thisThanks
Fortinet FortiGuard Threat Intelligence, specifically encountering an "Invalid URL" error. Please find the attachment with additional details. FortiSOAR
We have almost 195 switches in our domain and we need to migrate our switches to FortiLink Manager to continue to build out our network. The only information i can find online and when talking to consultants is that we need to manually migrate the switches. Any one know of a good way to do this without going in and manually migrating? This is a big project with plans for over 300 switches.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.