Mark a Best Answer
Fortinet Community
Recently active
Hi, I'm using fortianlyzer and have a question during dataset creation for report output.I wrote the query below to create a forticlient uuid for the logged-in vpn user and it works fine.Below is an example of a table made of query statements and queries. - select user, fctuid from $log where $filter and ( ( ( lower(logid) = lower('0107045124')))) Here, the user name is different, and I want to put a condition so that only the same line with the fctuid value is output, but it doesn't work well GROUP BY fctuidHAVING COUNT (DISTINCT user) > 1 I tried adding this section but it doesn't work well.
Does anyone know if there is a way to fix this error and can help me? FortiClientVPN 7.4.0.1645Network Extensions Full disk access The error I am getting is: Network error. The request timed out.
Anyone know how to make Microsoft Entra ID as source identity in the firewall policies?
Dear Team,We are experiencing a recurring issue with over 7 Fortigate 30 E devices, all of which have failed within a year's time span. The LAN connections on these devices are notably slow, and upon investigation, we have identified a significant amount of packet loss.Unfortunately, we do not currently hold a support license, which limits our ability to seek assistance for these devices. Additionally, we have several more devices in operation, but given the pattern of failure, we anticipate they may encounter similar issues in the future. This poses a significant financial burden, as replacing these devices is costly.We kindly request any assistance or guidance you can provide to address this situation effectively.Thank you for your attention to this matter.
I just wonder how one would or could implement a WAF URL filter (?) with Fortigate board utilities for Let's Encrypt renewals? That is, how would a policy have be setup to allow Let's Encrypt to access an internal webserver to get the renewal token as per HTTP-01 challenge? Sometime ago, I played around with a Web Profile that would only allow the regex .*\/.well-known\/acme-challenge\/.* I never got it working reliably, so I basically turned to Fortigate's own LetsEncrypt method. However, I still have some cases where a policy that would allow port 80 for renewals, with proper restrictions, would help. For example, my (not really working) example policy is allowing HTTP access to an internal machine for that renewal, but only allowing it from "acme-v02.api.letsencrypt.org" and with a webfilter that allows only .*\/.well-known\/acme-challenge\/.* Does not really work. If someone has (for educational purposes) a complete example that works.,
I am trying to use FortiClient VPN 7.4 on Ubuntu 22.04LTS OS. IPSEC connection gives an error and does not work. I tried to search for the error but could not find solution. Error is: On CLI: Error occurred in handler for 'keytar.setPassword': [Error: Unknown or unsupported transport “disabled” for address “disabled:”] On GUI: Failed to connect to VPN tunnel. Please try again. Details - Error: Error invoking remote method 'keytar.setPassword': Error: Unknown or unsupported transport “disabled” for address “disabled:” errorSS
I recently required a factory reset on my cell phone. Soon after I realized I could no longer login to my Fortigate. The problem was both of my logins were protected by Fortitokens. I contacted support and they informed me all I could do was a factory reset of my Fortigate. I did not want to rebuild the Fortigate config from scratch. After some thought I started to look at my backup config files. I was fortunate to have a current backup of the config file of my active Fortigate, which I could just use, but I would be back in the same boat. Fortunately, I have a second Fortigate that is inactive. Using it and looking at an older backup that still had the default admin user info, I copied that information and pasted it into the current backup. This took a couple of attempts to restore the modified config file to the inactive Fortigate. Once I completed it successfully, I was then able to login using the old admin user. Once login I was able to remove both Fortitokens from the active user
Dear team, our office has an issue with the Secure corporate WiFi in one of the Access points.It appeared right after a power outage.So basically anyone who tries to connect gets APIPA.Mind that the Guest which is Running Fine - WPA Personal.Here are some screen shots of the logs - FortiAP Logs The AP is connected to a Switch which has proper config on the interface, in-fact the rest of the AP's are on the same switch and have the same config on the interface and they are all working fine. *Two weeks ago I have encountered the same issue in a different office with the same FortiAP model and Firmware - Mind that firmware update did not fix it.
I configured the SSL VPN and the clients can ping and access all the internal LAN but the internal LAN cannot ping, controls the VPN Clientsmy FortiGate is 100F with firmware version of FortiOS v6.4.15 build2095i do policy like the following screenshot:
Hi, We are trying to connect sslvpn web mode and accessing website using https.After opening that website it redirects to other url which uses some custom port and website is not opening.We checked network logs in the browser and observed that it shows some other port and error "WebSocket is closed before the connection is established."Same thing is working fine if using forticlient.It looks like websocket is not supported in sslvpn web mode.Can some one please guide. Regards,Ganesh
Hello everyone,I need your help. As shown in the attached photo, there are some devices in which the automatically collected device information is not displayed properly. Question : Q1) For some devices, the product family and model are not displayed. What could be the cause?Q2) Is there a way to manually register this device? Thank you again to everyone who helps.
Hello. I’ve been receiving some spam lately, and I’ve noticed that during the SMTP connection, the sender's "from" domain does not resolve via DNS but the DNS resolvers are working properly. Additionally, since the domain is not resolvable aka. it does not exist , both SPF and DKIM checks fail. Shouldn't FortiMail block these emails during the SMTP session since I have the "Check Sender Domain" option enabled within the "Unauthenticated Session" settings? Any ideas or help its much appreciated. Thank you.
Hi there,I'm getting the errors "-5052" and after updating from 7.0.x to 7.2.x it's "-5053" when trying to connect using the FortiClient VPN on a Windows 11 machine. I verified login data, deactivated 2FA temporarily. Other machines / clients (even on Win11) do not have this problem.It is, however, possible to connect from the same client using the local admin account, so maybe something in the profile is broken. I tried as suggested in this thread:Steps to troubleshoot the FortiClient VPN connection issue:Verify network connectivity.Check VPN server settings in FortiClient.Disable firewall and antivirus temporarily.Update FortiClient to the latest version.Flush DNS cache using the command "ipconfig /flushdns".Remove any conflicting VPN or networking software.Contact Fortinet support for further assistance (couldn't provide a solution either).In addition I tried removing %localappdata%\Forticlient\ as suggested by a user, but this didn't affect anything. I did record logs, se
I am logged in with a super_admin_readonly profile, would it be possible to create an account and make it admin or otherwise switch it to admin ?Thanks in advance
Hello, I'm facing a trouble with setting up the LDAP authentication: my LDAP server seems to be well configured, Connectivity and User Credentials works from the GUI.From console, I try: diagnose test authserver ldap "LDAP TEST" ldapreader password diagnose test authserver ldap "LDAP TEST" myaccount password ldapreader is the username setted for the connection to LDAP, myaccount is my username.Each time I get : authenticate 'account' against 'LDAP TEST' failed! (account is the account I test) I'd tried many settings for the User group, adding my user (from ldap) or adding a remote group in which I am, it doesn't work. Product: Fortigate v7.4.4
Hi, Can someone help me on resolving the alert I encounter in my FortiManager? It says 'fortiguard service: disk usage is near disk quota limit' but when I get the system status, it shows that there's 769.75 GB free Disk Usage. I am new in FortiManager that's why I don't know whats going on. Thanks for helping. Br,Marlon
How do i set a IP Pool address in FortiOS 7.2.10 as a local address in a 120G?120G considers them as a external address. Thanks in advance
Hi all, We have some old logs stored at Fortigate SSD, and we want to export those logs to FAZ to generate a report. We found the KB and try to do the same: https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-Transferring-historical-logs-from-a-FortiGate/ta-p/193850?externalID=FD40716 We have used "lz4_reader.tar.gz" to convert the log to readable format and change to .txt extension. And we got this error when imported the log to the FAZ via Gui. ---- Update on 7th Nov, 2024. After checking this issue with Fortinet TAC about the FAZ built-it log format, the FAZ log format is now required as : [FirrwallSN].[VdomName].[tlog].[Date].[not sure what is it, just a random last Five numbers generated by Firewall?].log If you follow that KB and try to import something from Fortigate, you might use a " ReNamer " program to change all log naming formats. I would like to share my script h
Hi Fellows,I have configured a simple ipsec tunnel hub to 1x spoke hoping to add more spokes later on.the ipsec tunnel is dial up based with peertyp any . the tunnel is up and can ping the local subnet behind the hub from the remote subnet behind the spoke but not the opposite direction .I assigned IP to the tunnel interfaces and I can ping only direction [spoke to hub but not hub to spoke]I triple checked the static routes and firewall policies and all look fine. am I missing anything ? SPOKE TO HUB PING# execute ping 192.168.2.11PING 192.168.2.11 (192.168.2.11): 56 data bytes64 bytes from 192.168.2.11: icmp_seq=0 ttl=255 time=4.6 ms64 bytes from 192.168.2.11: icmp_seq=1 ttl=255 time=4.4 ms64 bytes from 192.168.2.11: icmp_seq=2 ttl=255 time=4.4 ms^C--- 192.168.2.11 ping statistics ---3 packets transmitted, 3 packets received, 0% packet lossround-trip min/avg/max = 4.4/4.4/4.6 ms =====================HUB TO SPOKE PING====================# execute ping 192.168.3.25PING 19
Good evening, I'm doing a Fortimanger lab and I'm having trouble adopting a Fortigate VM, of course they all have free licenses and it's a lab to get to know the equipment. Can you guys give me some guidance?Photos attached
Hello everybodyWe have topology in bleow:Topology: FG-VM 112 <----- 3rd party Router -----> FG-VM 212we want to apply HA between 2 remotes fortigate we use the doc https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/346301/layer-3-unicast-standalone-configuration-synchronizationWe configured this correctly as per the documentation for L3 standalone unicast but it did not workcan you help us thanks for all
Hello everybody,I have a problem with ZTNA, I performed the various configuration steps that I found in the official guide, but I can't get the remote access in https of my Vcenter and my Firewall to work. It gives me this error for my fortigate :403 Forbidden: Wrong proxy service was requestedThe web server reported that an error occurred while trying to access the website. Please go back to the previous page.URL https//:33.33.45.66:4556while for the VCenter:ZTNA Access DeniedThe page you requested has been blocked by a ZTNA restriction.Details: API Gateway Denied.can you give me a hand?Thanks so much
My Fortiswitches connect Fortigate with fortilink and I add my fortigate to FortiNAC when I plug new pc to fortswitch port it set to register vlan but when i login with active directory user it not maping to role based vlan
I'm trying to find documentation that would answer the following PCI requirement, specifically the last line:Products I'm looking to cover is FortiGate, FortiAP and FortiSwitchPCI-DSS Requirement 5.2.3:All system components not at risk for malware are evaluated periodically to include:A documented list of all system components not at risk for malware.Identification and evaluation of evolving malware threats for those system components.Confirmation that such systems continue to not require anti-malware protection. I have not been able to find anything in the admin guides. As much as I would love to say "because I said so", it's not acceptable. I need either an industry doc or a vendor doc for firewalls, APs, switches.Can someone point me to a document either by Fortinet or from "recognized" industry/experts?
Hello everyone,I am currently configuring a SIEM solution (Wazuh) and have successfully set up log forwarding from FortiEMS via syslog. However, the logs I am currently receiving on the SIEM are as follows:Status change of FortiClient to onlineFortiClient status marked as offline by EMSFortiClient IP address changesI would like to capture additional logs, such as those generated by the vulnerability scanner, antivirus, web filter, and other security features. Could you advise on how to configure FortiEMS to send these additional logs to Wazuh?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.