Mark a Best Answer
Fortinet Community
Recently active
I am trying to create software switch and bind the SSID to tunnel wireless traffic. As I read, it is required to have software switch to perform internally pass traffic between VLANs. However; I have uplink ports added to 803.ad as aggregate links to the switches where access points are plugged in. When I create an interface as software switch, I cannot add the ports that was already added to Fortlink as management therefore I cannot add the ports which already added to Fortilink to the software switch as member interfaces also to pass traffic to the SSID, do you know it is possible in any way to accomplish this add ports already in 803.ad aggregated link?
We found the issues about httpsd process. I can't to access gui process and I try to restart the httpsd process is not working. because when I entry command #diagnose sys top // It not show httpsd process. And I try to kill the httpsd process with command below, but It's not work. I can't access to the gui management of FortiGate
Hi.i'm doing a poc on forticlient ems for the purpos on using it as remote ipsec vpn and ztna.I'm having problems with the vpn part.right now iv don't the vpn before login (auto part) with the machine certificate and that works fine and when i log in the user certificate takes over, that's fine and working. But when i close the lid on my laptop the computer lock, and when i come back and open it again it's lock and the vpn before login starts and when i use my windows hello and log me in it's stuck with the machine certificate and the user dont takes over.Anyone of you having solved that? Morten
Hello, I aim to get all the traffic of my VPN users on the firewall, except meeting, YouTube, etc. traffic. I proceeded with the information I found on the internet, set my sslvpn portal settings to "Enabled for Trusted Destinations", and left the "routing address override" field blank. I created policies to manipulate the IPs through the policy for the traffic that I want users to not come to my firewall. I wrote youtube etc addresses with negate destination in the policies. When I did these, I expected it to work correctly, it worked but it worked with problems. When I ask for a route to any IP address on the client, it enters the tunnel. When I ask for YouTube, the client uses its own internet output. The problem is that clients are starting to hear our company's 10.0.0.0/8 network from their own internet output. When the "routing address override" section is left blank, do these IPs appear by default? Is there a field to reset this area? No matter what I did I couldn't fi
Hey everyone,I'm working with a FortiGate 40F setup, using an ADVPN with IPsec to connect 1 hub and 2 spokes. For routing internal traffic through the ADVPN tunnel, I'm relying on SD-WAN rules and SLA checks.Just to add some context, I'm using my ISP’s WAN interface as the ADVPN tunnel interface, and it’s set up to get an IPv6 address from FortiGuard. That part is working smoothly—no issues with IPv6 or IPv4 internet connectivity at all.The problem:I’m experiencing a consistent packet loss between 30% and 70% on the ADVPN tunnel interfaces, as indicated by the SD-WAN SLA ping checks. This packet loss is specific to the ADVPN tunnel interfaces, while other connections seem unaffected.What I have tried out:MTU adjustments (to 1380) ~~not workingEnabled FEC on one of the device ~~not workingAre there anything else i should try? I’d really appreciate any insights or advice!
Hi All, I have dual wan setup on my fortigate. Is there a way to set the "WAN IP" in the system information that always uses wan1 or wan2 ip? Thanks regardsJimmy
How can I see all IPs assigned by DHCP for all Firewall vLans? I used pfSense a lot and there is an option in the Menu with DHCP leases. Is there this option in Fortigate?
Hello everyone.I am encountering difficulties with our FortiGate 200E device at the company.We are utilizing the web filter to control content access, however, we are observing inconsistent blocking behavior.Specifically, when Proxy mode is enabled, certain categories of content are not being blocked as expected, despite being configured to do so. Conversely, when switching to Flow mode, the device is over-blocking content and miscategorizing websites. For instance, OneDrive is being classified as an abortion site, and YouTube is categorized as unknown.I have already attempted to resolve this issue by updating firmware, cleaning the cache and implementing new rules, but the problem persists.I would appreciate any insights or experiences that you may have regarding this matter. Thank you.
We’ll be upgrading two FortiGates configured in Active-Passive HA. Is it possible to have one FortiGate running on the upgraded version for testing while keeping the other on the previous version? Or is it necessary to upgrade both FortiGates to the same FortiOS version for HA to function properly? This is a production environment, so I'd like to know if I can upgrade one FortiGate first to test the stability of the upgrade and HA with the FortiGate running on the original version.
Is there a config parameter that I'm issuing that will shut down an existing traffic flow when a firewall policy is disabled? Disabling the policy stops any new connections but doesn't shut down traffic for an existing session which is what I'm trying to do. Thanks.
Hello,I'm having an issue where I'm unable to install both FortiClient VPN and FortiClient PAM on the same device if the customer does not have a FortiClient EMS Server. It seems like there is a conflict between the two installations. Has anyone else experienced this? Is there a way to have both running without needing an EMS Server, or is it a strict requirement for using both features together? Any guidance or workarounds would be greatly appreciated! Thanks.
Hi!In ACME certificate support see "It must not have any VIPs, or port forwarding on port 80 (HTTP) or 443 (HTTPS)". Since port-forwarding and Virtual Servers are a feature of VIP object, this text is unclear (to me).Does the requirement refer to ALL VIPs (ie. config firewall vip), or only those with portforward=enable?Does the requirement also include VIPs configured with realservers?Thanks!
Hello FortiPAM adminsIs there a way to hide passwords of users' secrets from being seen by the admin?
Recently upgraded our FAZ to 7.6.1 from 7.4 and finding that there are two prominent FortiAI buttons in the GUI. How can this be turned off/disabled at the system level? We are not planning on using it and don't want it showing up in the interface.
Hi, I have three mac airport express and they are in bridge mode connected to my switch, they are working like access point, and we want to use the guest network, is there a way to use it with a fortinet? We have a fortigate 60D. I will appreciate the help, thanks.
This post will help in estimation/adjustment of an important quantity Logs per second (LPS). Logs per second is a quantity which is required for calculating the storage size of Fortianalyzer during the deployment process. As mentioned in Fortianalyzer administration guide, generally, the traffic logs are equivalent to the sessions generated on the Firewall, therefore taking this as a base point, we can check the sessions generated on each firewall per day. This can be obtained from FortiGate statistics report We can fetch the report by navigating to Log & Report >> Reports On reports we can see the total number of sessions generated per day. Taking an average of 7 to 14 days will give us an idea of average sessions generated per day for that particular firewall, which can then be converted into the traffic logs generated per day. Dividing that number with 86400 will give us LPS. Each security service also contributes in overall log generation. An e
Hi All: Hoping someone can help. My internet service is 300 Down / 40 Up. Not sure why, but I am only getting 20 up behind the Fortigate. Here is what I observed / tried so far. 1. Getting 40 at the Modem in front of the Fortigate2. Tried a switch between the Modem and the Fortigate3. Tried hardcoding the Fortigate to 1000Full on the Wan Interface4. No security policies are running, straight up firewall NAT only Any other ideas? I saw the article below; it may apply but seems weird to have to put a traffic shaper on my WAN interface. How would I configure for WAN Interface 1? https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Issue-with-outbound-upload-traffic-speed/ta-p/192116 Any other ideas outside of what I tried and the article? Thanks!
Hi guys, my FortiGate has some BGP neighbors (Cisco) but in the routing table, it has only link-local address (of Cisco device) as the next hop, not the global one https://xender.vip/ . So have you ever seen this behavior? And how to fix it?Thank you,
Hello, everyone,Does FortiGate have the ability to remove duplicate security policies? Similar to the following functions of FortiManager:https://docs.fortinet.com/document/fortimanager/7.6.1/administration-guide/3034/viewing-unused-policies
greetings all,we have a performance SLA with active probe based on Ping, but Ping packet got lost intermittently along the path.So, we want to use a passive or Prefer Passive probe method with TCP Connect to the production service as the protocol, to see if Ping packet loss will come with TCP connect error. In short, we want to compare the two probing methods to figure it out.I just configured the performance SLA, but it is not used to any SD-WAN rule, as we do not want an unverified performance SLA to risk our production. And I got the performance as below, test_for_Prefer_passive_probe is the one, and it shows me packet loss forever (see the picture below). I completely doubt the packet loss is reflecting the truth as we do not have any reported issue from the production line.So, can any friend let me know how the packet loss is calculated in such scenario, what is the recommended way to configure prefer passive probe SLA monitor?Yes, we've enabled passive-wan-health-
How can I extract the existing logs from a fortianalyzer version 7.4.4 to CSV? They are asking me for the last 90 days for a particular analysis.Within the team there is an adom who receives the 4 fortigates and it is required to obtain this information from all of them.I tried to do it Through API but the documentation is limited,Has anyone achieved it?I don't know if the logs already existing on the computer could be converted to csv in any tool?
I need configure SO to FOrtigate 60F, i try reset with a button reset but i see the next menssage, i need know how charge a FOrtiOS by TFTP server Booting OS...No default firmware.Error: Default firmware boot failed!!!Switch to BACKUP after 58 seconds. Press any key to stop..FOS boot failed. You may try backup.Please power cycle. System halted.
Hello, i'm planning to upgrade my fortigate from 7.0.14M to 7.2.9 but at the same time i've also got some FAP-431F running on 7.2.0 in my deployment.My client is asking me if there would be some issues on the Aps that now are running on 7.2.0. From documentation their target version after the firewall upgrade should be 7.2.5. I'm not able to find any document regarding this question, only found the "FortiAP and FortiOS 7.x Compatibility Matrix" which is not answering the dubt.Did you face the same question?Any tips is accepted. Thank youRegards
Hi there,we manage our guest-wifi via REST-API from our intranet. Everything worked fine since we updated the Fortigate to FortiOS 7.4.5. Now we get an error "[httpsd 10151 - 1727870754 info] api_access_check_for_api_key[657] -- Wrong vdom." I was not able to find any REST-API documentation for this version to adapt my scripts. We communicate via cURL to the Fortigate.Is there someone who can assist me with a REST-API documentation for this version? Here are the informations from the debug-log:here is the info from the debug-log: \[httpsd 10151 - 1727870754 info\] api_access_check_for_api_key[657] -- Wrong vdom.[httpsd 10151 - 1727870754 warning] _lock_out_check_and_lock_out[416] -- Failed api-key login attempt from xxx.xxx.xxx.xxx. (1/3 attempts within 120s).[httpsd 10151 - 1727870754 info] fweb_debug_final[355] -- Completed GET request for "/api/v2/cmdb/wireless-controller/wtp/" (HTTP 403 Forbidden)[httpsd 10149 - 17
I connected a FortiGate 100F to a FortiSwitch 248E-FPOE using four cables to set up a 4-gigabit trunk.Then, I connected a U231F access point to ports 3 and 4 of this switch, with the network interfaces configured in uplink and LACP enabled to achieve an aggregated bandwidth of 2 gigabits.I also connected two desktop PCs to ports 29 and 30 on the switch, each with a Gigabit connection. On both PCs, I placed a 3-gigabyte file.If I start downloading the files simultaneously from two notebooks connected via Wi-Fi to the radio on the 5 GHz band, one of the PCs downloads at 300 Mbps, while the other downloads at nearly zero speed. Once the first download finishes, the second begins. I would expect both notebooks to download the file at the same speed of 300 Mbps.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.