Mark a Best Answer
Fortinet Community
Recently active
Hi All: Hoping someone can help. My internet service is 300 Down / 40 Up. Not sure why, but I am only getting 20 up behind the Fortigate. Here is what I observed / tried so far. 1. Getting 40 at the Modem in front of the Fortigate2. Tried a switch between the Modem and the Fortigate3. Tried hardcoding the Fortigate to 1000Full on the Wan Interface4. No security policies are running, straight up firewall NAT only Any other ideas? I saw the article below; it may apply but seems weird to have to put a traffic shaper on my WAN interface. How would I configure for WAN Interface 1? https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Issue-with-outbound-upload-traffic-speed/ta-p/192116 Any other ideas outside of what I tried and the article? Thanks!
Hi guys, my FortiGate has some BGP neighbors (Cisco) but in the routing table, it has only link-local address (of Cisco device) as the next hop, not the global one https://xender.vip/ . So have you ever seen this behavior? And how to fix it?Thank you,
Hello, everyone,Does FortiGate have the ability to remove duplicate security policies? Similar to the following functions of FortiManager:https://docs.fortinet.com/document/fortimanager/7.6.1/administration-guide/3034/viewing-unused-policies
greetings all,we have a performance SLA with active probe based on Ping, but Ping packet got lost intermittently along the path.So, we want to use a passive or Prefer Passive probe method with TCP Connect to the production service as the protocol, to see if Ping packet loss will come with TCP connect error. In short, we want to compare the two probing methods to figure it out.I just configured the performance SLA, but it is not used to any SD-WAN rule, as we do not want an unverified performance SLA to risk our production. And I got the performance as below, test_for_Prefer_passive_probe is the one, and it shows me packet loss forever (see the picture below). I completely doubt the packet loss is reflecting the truth as we do not have any reported issue from the production line.So, can any friend let me know how the packet loss is calculated in such scenario, what is the recommended way to configure prefer passive probe SLA monitor?Yes, we've enabled passive-wan-health-
How can I extract the existing logs from a fortianalyzer version 7.4.4 to CSV? They are asking me for the last 90 days for a particular analysis.Within the team there is an adom who receives the 4 fortigates and it is required to obtain this information from all of them.I tried to do it Through API but the documentation is limited,Has anyone achieved it?I don't know if the logs already existing on the computer could be converted to csv in any tool?
I need configure SO to FOrtigate 60F, i try reset with a button reset but i see the next menssage, i need know how charge a FOrtiOS by TFTP server Booting OS...No default firmware.Error: Default firmware boot failed!!!Switch to BACKUP after 58 seconds. Press any key to stop..FOS boot failed. You may try backup.Please power cycle. System halted.
Hello, i'm planning to upgrade my fortigate from 7.0.14M to 7.2.9 but at the same time i've also got some FAP-431F running on 7.2.0 in my deployment.My client is asking me if there would be some issues on the Aps that now are running on 7.2.0. From documentation their target version after the firewall upgrade should be 7.2.5. I'm not able to find any document regarding this question, only found the "FortiAP and FortiOS 7.x Compatibility Matrix" which is not answering the dubt.Did you face the same question?Any tips is accepted. Thank youRegards
Hi there,we manage our guest-wifi via REST-API from our intranet. Everything worked fine since we updated the Fortigate to FortiOS 7.4.5. Now we get an error "[httpsd 10151 - 1727870754 info] api_access_check_for_api_key[657] -- Wrong vdom." I was not able to find any REST-API documentation for this version to adapt my scripts. We communicate via cURL to the Fortigate.Is there someone who can assist me with a REST-API documentation for this version? Here are the informations from the debug-log:here is the info from the debug-log: \[httpsd 10151 - 1727870754 info\] api_access_check_for_api_key[657] -- Wrong vdom.[httpsd 10151 - 1727870754 warning] _lock_out_check_and_lock_out[416] -- Failed api-key login attempt from xxx.xxx.xxx.xxx. (1/3 attempts within 120s).[httpsd 10151 - 1727870754 info] fweb_debug_final[355] -- Completed GET request for "/api/v2/cmdb/wireless-controller/wtp/" (HTTP 403 Forbidden)[httpsd 10149 - 17
I connected a FortiGate 100F to a FortiSwitch 248E-FPOE using four cables to set up a 4-gigabit trunk.Then, I connected a U231F access point to ports 3 and 4 of this switch, with the network interfaces configured in uplink and LACP enabled to achieve an aggregated bandwidth of 2 gigabits.I also connected two desktop PCs to ports 29 and 30 on the switch, each with a Gigabit connection. On both PCs, I placed a 3-gigabyte file.If I start downloading the files simultaneously from two notebooks connected via Wi-Fi to the radio on the 5 GHz band, one of the PCs downloads at 300 Mbps, while the other downloads at nearly zero speed. Once the first download finishes, the second begins. I would expect both notebooks to download the file at the same speed of 300 Mbps.
My FortiAP is plugged into a Dell Switch and the Power LED is solid orangeThe manual says 'reserved for customizations' - what does that mean?I cannot access my AP as still shows offline on FortigateMy AP is a 231FMy POE+ switch is an N3024EP-ON Thanks
Hello,We’ve been looking at Fortinet FortiGate Next-Generation Firewall on Amazon Marketplace ( https://aws.amazon.com/marketplace/pp/prodview-wory773oau6wq) We've a question on licencing but are struggling to get someone to speak to us so I thought I would try here! A years licence upfront is $2400 for the year which looks like its based on EC2 instance size. Now whilst we are setting up we’ll want to use a smaller EC2 instance and then when we go live move up to a larger EC2 instance. So my question is really if we buy a year licence at $2400 can we use say a T3.small and then move to a larger instance within the same price band say a C4.Large when we go live or is the licence fixed on that t3.small instance? If this isn't the place to get an answer like this would it be possible to get a pointer on where we can get the answer? I have tried via AWS Market place and request a call back but with no response, I have tried via our amazon
Hello, i purchased a Fortitoken Cloud license and i've been asked to configure MFA for all the user belonging to a radius server group and connecting via remote access with the forticlient.I haven't found any documentation about how to implement this configuration without using fortiauthenticator, is it possibile?If configuring a local user i've the option to select the fortitoken cloud license, when configuring the radius server group i'm not prompted for this option, i haven't seen any command neither via CLI.Do you have any idea? thank youBye
On FortiClient 7.2.4, SSLVPN will not connect if the local machine has no Internet connection.It appears that FortiClient checks Windows Network Level Awareness (NLA) to see if there is a working Internet connection. However, this breaks airgapped setups where:1. the endpoint is airgapped with no Internet connectivity (hence Windows NLA will report No Internet)2. the FortiGate is intranet-only (not exposed to the Internet)FortiClient will refuse to initiate a connection thinking that there is no working connection, but FGT is reachable.Previous versions of FC (7.0.11) seem to work alright, just not the 7.2.x branch.
Hello team, I'm new with the whole vpn topic. We have an already running ipsec vpn between two locations. Now I want a second ipsec vpn connection to another firewall. Is it possible to give them the same WAN IP and interface, as I used for the first location? Thanks for your help
i unistalled forticlient and now i'm trying to install it again and it says that the digtal signature on the istaller package is invalid. Installation aborted.
Hi All, We have Ho office and wants to connect multiple branches to head office. I am new to configure hub and spoke ipsec vpn. could please help us my query. HO office ------- multiple branch offices I have gone through docs.fortinet.com document. but could understand in details. Thanks
Hello team, We have 2 ISPs, connected to WAN1 and WAN2.These WANs are in a SD-WAN with just the implicit rule, as "Spillover", with WAN1 as primary.About 2 weeks ago, I took 2 of defaults "Performance SLAs", and added both WANs as participants:These Performance SLAs, are: "Default_DNS" and "Default_Gmail"Both performance SLA has:Check interval: 1000 msFailures before inactive: 5Restore link after: 10 IMHO, if WAN1 has a failure, after 5 seconds, everyone should use WAN2. In this case, what event should be logged in the Fortigate?How can I search for this? I see events like the following, but no one tells me that a WAN was failing, * Member status changed. Member in sla.* Number of pass member changed.Also, all the events, are for "Default_DNS", no events for "Default_Gmail" Thanks in advance.Regards,Damián
Dear Members,I work in a support team at our company, and we have been facing the following problem:Users must change their Active Directory passwords on a company computer when the password expires or if they forget it.After that, users work from home on their personal computers and must use the VPN with the FortiClient.In this situation, they cannot access the VPN because the Windows certificate has saved the old password.To resolve this, we need to update the certificate.Is there any way to minimize support efforts? For example, could FortiClient prompt the user for the new password, or could the certificate be deleted when this issue occurs?Thank you in advance.
Hi Guys, I am looking to setup access to our on-premise Vcenter and VMware ESXi hosts via ZTNA. I am looking to see if any of you have done this and what config you did to get it working on the FortiGate and the FortiEMS. We are using FortEMS Cloud. Thanks John
We got a team who manage the content of our corporate website. And everytime the push or publish their design/changes via wordpress. The fortiweb detected it as XSS.Is there a way to exempt the user ip source for any XSS detection or any better approach to fix this.FortiWeb
Bom dia,Desenvolvi um sistema para ser utilizado pela Paróquia Militar Cristo Rei e o sistema de vocês está bloqueando acesso ao domÃnio abaixo: https://cestabasicafloripa.com.br/ O domÃnio foi registrado há menos de 30 dias, talvez isso esteja causando algum conflito com o sistema de vocês. Portanto peço que reconsiderem o desbloqueio desse domÃnio pois está impedindo que o pessoal da igreja consiga acessar o endereço acima.Obrigado.
Hello everyone, Is there any configuration on FortiGate or on FortiClient EMS that allows SSL-VPN remote users connected via FortiClient to work with the files stored on the server but not copy or download it on their laptops? Thank You,
HiWe want to setup site to site vpn between our fgt(200f) and our branch fgt (200e) . Hq fgt version is 7.6 and branch version is 6. We want to connect to only one server from branch and they will connect to one of servers too. In HQ, we have subnet overlapping when i want to insert remote ip but on the branch side they do not have any overlapping problem. How can i solve that?
Hello,I haven't made any changes from fortigate for a while and it was working fine, but this morning I got a response from users saying they were getting an error saying they didn't have an internet connection when they tried to access youtube. When I checked, there was no error log in fortigate, but when I checked from chrome, I saw an ERR_CONNECTION_CLOSED error in some requests made to googlevideo and youtube domains. After a long effort, I saw that access was fixed when I allowed these domains in the web filter, but now the same thing is happening for yandex etc. What could be the reason? I can't see any deny log in FortiGate.
Hi, I have problem with reseting FGT 200F. FortiGate-200F login:username: maintainerpass: bcpbFG200FT*********not works, I receive message "Login incorrect" When I press button, it just goes reload.I don't have forticloud. How can I reset it?please help.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.