Mark a Best Answer
Fortinet Community
Recently active
Good evening, I'm doing a Fortimanger lab and I'm having trouble adopting a Fortigate VM, of course they all have free licenses and it's a lab to get to know the equipment. Can you guys give me some guidance?Photos attached
Hello everybodyWe have topology in bleow:Topology: FG-VM 112 <----- 3rd party Router -----> FG-VM 212we want to apply HA between 2 remotes fortigate we use the doc https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/346301/layer-3-unicast-standalone-configuration-synchronizationWe configured this correctly as per the documentation for L3 standalone unicast but it did not workcan you help us thanks for all
Hello everybody,I have a problem with ZTNA, I performed the various configuration steps that I found in the official guide, but I can't get the remote access in https of my Vcenter and my Firewall to work. It gives me this error for my fortigate :403 Forbidden: Wrong proxy service was requestedThe web server reported that an error occurred while trying to access the website. Please go back to the previous page.URL https//:33.33.45.66:4556while for the VCenter:ZTNA Access DeniedThe page you requested has been blocked by a ZTNA restriction.Details: API Gateway Denied.can you give me a hand?Thanks so much
My Fortiswitches connect Fortigate with fortilink and I add my fortigate to FortiNAC when I plug new pc to fortswitch port it set to register vlan but when i login with active directory user it not maping to role based vlan
I'm trying to find documentation that would answer the following PCI requirement, specifically the last line:Products I'm looking to cover is FortiGate, FortiAP and FortiSwitchPCI-DSS Requirement 5.2.3:All system components not at risk for malware are evaluated periodically to include:A documented list of all system components not at risk for malware.Identification and evaluation of evolving malware threats for those system components.Confirmation that such systems continue to not require anti-malware protection. I have not been able to find anything in the admin guides. As much as I would love to say "because I said so", it's not acceptable. I need either an industry doc or a vendor doc for firewalls, APs, switches.Can someone point me to a document either by Fortinet or from "recognized" industry/experts?
Hello everyone,I am currently configuring a SIEM solution (Wazuh) and have successfully set up log forwarding from FortiEMS via syslog. However, the logs I am currently receiving on the SIEM are as follows:Status change of FortiClient to onlineFortiClient status marked as offline by EMSFortiClient IP address changesI would like to capture additional logs, such as those generated by the vulnerability scanner, antivirus, web filter, and other security features. Could you advise on how to configure FortiEMS to send these additional logs to Wazuh?
Hello Team, Would it be possible to change the pseudonym of the profile which is “Kayzz3rS” by this one: “SupportIT_Bils” please !Thank you in advance, have a nice day !
I have abit of a dumb question doesn't forticlient update on its own?i had the latest version at the moment that was 7.4.0.1658 now there is 7.4.1 there is no button on forticlient to update directly the client
Is it possible to apply traffic shaping on tranperant vdom base on user groups ? BackgroupFortiOS 7.4.5 runung as a explic proxyUser authenticate with LDAP user account
Can i configure wan static ip from my modem ip's ?????
There are so many policies and profiles that can result in traffic being blocked, it can be difficult to analyze all the logs to determine why. I would suggest adding a "Block Report" to a FortiGate and/or FortiAnalyzer that focuses on giving an administrator a quick diagnosis of why a packet, application or connection it's being blocked. It might be similar to the "Local Traffic" log, but provides more details about why traffic was dropped.
Hello everyone,I have a FortiSandbox 2000E appliance with VM license, below is the SKU:(FSA-2000E-UPG-LIC-BYOL) can you confirm me that this license only handles the number of clones up to 20 ?On board the machine I have only Windows 7, 8 and 10 keys after the upgrade in 4.4.6 I can download a WIN 11 but if I wanted to buy the license which SKU should I refer to ? Unfortunately I can find information referenced only for the new Sandbox F and G series
Hello,I was wondering if it's possible to lock down a local admin account for console access only? I know that you can do it in the global settings, but I only want to lock down one admin account with no mfa to console access only. I attempted to create an admin account and have it's trusted host as 127.0.0.1/32 but got an error. I would like to do this in the trusted host if possible and avoid using a local in policy. In the back of my mind I am thinking about cloud based FortiGate's that have been orphaned from internet access and can only access them through the cloud native console session. FortiGate firmware version 7.2.10
I'm setting up my first webapp on a brand new FortiWeb Cloud.The webapp is going to use the automatic certificates from Let's Encrypt; I also need to setup a very strict Geo IP Block.Turns out that Let's Enrypt is not going to work with that setup, as HTTP requests from blocked countries will be dropped.However, on the Let's Encrypt community someone got a solution:https://community.letsencrypt.org/t/whitelist-letsencrypt-server-ips/215833 How can I implement a whitelist for incoming HTTP request to /.well-known/acme-challenge? Thanks!Marco
I have a forgate 100DI am trying to use the API to create firewall addresses and update a policyI am on firmware 6.2.16 the latest for the 100DI have triedhttp://<IP>/api/v2/cmdb/firewall/address?access_token=<KEY> I get a 200 result but it never adds the address to the firewall body example{'name': "test_IP_JP",'subnet': "1.1.1.1/32"''associated-interface': "Untrust"} but I get back a GET listing all the addressesfrom the api debug It looks right any suggestions?
Hello,FortiMail We're using FortiMail in Gateway mode.We want to limit number of emails an user can send.All of the email traffic which gets into FortiMail goes from mail servers.As far I've seen there are only Session limits which I m afraid might block the mail servers instead of users.Any ideas? Thanks in advance.
is the FW fortinet 800D a
What are the tips and shortcuts that has made the operation on fortinet devices easier for you and you thought “oh how didnt i know that before this”For me it was the ability to delete bulk objects on fortigate using shift key to select them on the browserand also adding bulk objects with the help of notepad++
Hi,I am trying to enable diagnostic cli. when i enable "permit usage of cli diagnostic commands" and click ok it automatically gets disabled upon revisiting this setting. the membership of the account from which this is done has Read write access to all. What could be the reason ? how to enable it ?regards
I am trying to register a permanent test licence for a fortigate - I did this once, but am unable to do it a second time. I know that only one licence is available per Forticare account, but I have decommissioned the previous licence in the Assets screen. When I try to register the licence it does not reboot the Fortigate VM. When I debug what happens, I see this: [httpsd 4215 - 1730202905 info] fweb_debug_init[605] -- User-Agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" [httpsd 4215 - 1730202905 info] fweb_debug_init[607] -- Handler "api_monitor_v2-handler" assigned to request [httpsd 4215 - 1730202905 info] is_vm_uri[1144] -- allowing VM URI '/api/v2/monitor/system/vmlicense' [httpsd 4215 - 1730202905 info] api_store_parameter[308] -- add API parameter 'vdom' (type=string) [httpsd 4215 - 1730202905 info] api_store_parameter[308] -- add API pa
Hey,HI if some can point where to configure scenerio where when someone will visit `somewebsite.com` then it will get an error page with information " soory this service isnt avaiable any more".Is it possible to achieve it on WAF without creating another web server where WAF will have to forward traffic?
I have 3 vpn connections:1. Azure - mainsite FG (ipsec)2. branchsite FG - mainsite FG (ipsec)3. clients - mainsite FG (ssl-vpn)With the new ike-port option is should be possible to move to ip-sec over port 443.config system settingsset ike-port 443end This sets the port globally though. I can get around this for tunnels 2 and 3, but Azure site-to-site VPN does not have an option to change port (or use tcp). Is it possible to change the port per tunnel? If not, is this on the roadmap?
I managed to manually install on a PC to test the Persistent Agent. Now I can register the PC but I still have a problem: when I open the browser I get the message that I have to register. Before reaching the registration page I am informed that the connection is not secure. (NET::ERR_CERT_AUTHORITY_INVALID).Once I accept the risk I can register. For authentication I use the domain user.I also find log messages in the Persistent Agent logs:2024-10-28 09:59:17 UTC :: peer CommonName = bradfordnetworks.com2024-10-28 09:59:17 UTC :: Checking Peer name fortinac.mydomain.com against Common or Subject-alternative-name entry bradfordnetworks.com2024-10-28 09:59:17 UTC :: Peer name "fortinac.mydomain.com" doesn't match "bradfordnetworks.com"2024-10-28 09:59:17 UTC :: Refusing to connect to trust_DISTRUSTED fortinac.it-present.com|bradfordnetworks.com|09:6e:cf:15:bd:ea:b9:1e:26:21:75:d5:86:9a:8e:37:15:f5:d4:a92024-10-28 09:59:17 UTC :: Connection failed! 1I installed the certificates as trusted
Running Fortinac software (FortiNac Persistant agent) and a Profile from Jamf but some users after a while the connection with the (hidden) Wifi network is gone. It is also not visible anymore only solution is to pullback the (Wifi) profile and push the (same) profile again and then the (hidden) Wifi network is visible (again) and you can select it and the Macbook has a working wifi connection. Any idea were to look?
We are in the process of updating our FortiGates from version 7.0.12 to 7.2.7. We are using the Firmware template in FortiManager, which is running version v7.2.8-build1634 241018. Every time we attempt to update our FortiGates using FortiManager, we encounter errors. The update progresses to version 7.2.6, but then fails during the second job. Has anyone experienced a similar issue and possibly found a solution?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.