Mark a Best Answer
Fortinet Community
Recently active
I managed to manually install on a PC to test the Persistent Agent. Now I can register the PC but I still have a problem: when I open the browser I get the message that I have to register. Before reaching the registration page I am informed that the connection is not secure. (NET::ERR_CERT_AUTHORITY_INVALID).Once I accept the risk I can register. For authentication I use the domain user.I also find log messages in the Persistent Agent logs:2024-10-28 09:59:17 UTC :: peer CommonName = bradfordnetworks.com2024-10-28 09:59:17 UTC :: Checking Peer name fortinac.mydomain.com against Common or Subject-alternative-name entry bradfordnetworks.com2024-10-28 09:59:17 UTC :: Peer name "fortinac.mydomain.com" doesn't match "bradfordnetworks.com"2024-10-28 09:59:17 UTC :: Refusing to connect to trust_DISTRUSTED fortinac.it-present.com|bradfordnetworks.com|09:6e:cf:15:bd:ea:b9:1e:26:21:75:d5:86:9a:8e:37:15:f5:d4:a92024-10-28 09:59:17 UTC :: Connection failed! 1I installed the certificates as trusted
Running Fortinac software (FortiNac Persistant agent) and a Profile from Jamf but some users after a while the connection with the (hidden) Wifi network is gone. It is also not visible anymore only solution is to pullback the (Wifi) profile and push the (same) profile again and then the (hidden) Wifi network is visible (again) and you can select it and the Macbook has a working wifi connection. Any idea were to look?
We are in the process of updating our FortiGates from version 7.0.12 to 7.2.7. We are using the Firmware template in FortiManager, which is running version v7.2.8-build1634 241018. Every time we attempt to update our FortiGates using FortiManager, we encounter errors. The update progresses to version 7.2.6, but then fails during the second job. Has anyone experienced a similar issue and possibly found a solution?
Hi GuysCan we change password on targets that accessed via Web based secrets using fortipam, like fortigate GUI, ESXi Web ?
Hello, I'm working in a security company. We have an integration with FortiWeb API. And, we figured that out that we need to update the API links as/api/v2.0 But we have a problem with these API link. For creating a custom rule : /cmdb/waf/custom-access.rule We already changed the authentication method. And it works for GET requests. But, when we try to create a custom rule, we are always getting 500 responses like below. And, there is no documentation about this. Internal Server ErrorThe server encountered an internal error ormisconfiguration and was unable to completeyour request. Can you help us with this issue? Can you send us the API document for v2 please?Regards,Ceren Senak
I want to forward logs from FortiNAC to the SIEM server, but it only offers the option to select a single facility, and I'm not sure which one to choose. I want to view both when switches go down and authentication events. I'm attaching the details.
Hello, I’d like to seek some advice. I currently have a functioning VPN with 2FA through the Azure app. The VPN operates normally, and authorization goes through without issues. However, I’m facing a problem when the Microsoft window “Remember this sign-in” appears after logging in. If we select YES, the VPN closes and displays “inactive VPN.” When we log in again and choose NO, the VPN connects successfully. Sometimes it happens the other way around: when we click YES to remember the sign-in, the VPN becomes inactive, and we have to select NO. It seems like a cookie issue because when I clear the cookies from the browser history, the login works perfectly right away. Has anyone else encountered this issue? It seems like it would be helpful to bypass the browser's use of cookies altogether. Theoretically, that could work, but I’m not sure how to achieve that. I’d also like to clarify that I’m using FortiClient version 7.4.0.1658 and have Microsoft Edge set as my default browser. A
Does anyone knows the proper way to setup Hub-to-Spoke while firewalls are located on Huawei cloud.
So we currently have some IPsec tunnels that initate both on the inside and on the outside using our outside interface.We want to move this to a loopback instead, so that our ISP is more free to make changes on our outside interface.We're using 1800F version 7.2.9.I'm struggling to understand if I have to do anything after we moved the tunnels to the loopback, so that they can both be initiated from the inside aswell as the outside.I was thinking if I put the loopback interface in the same zone as outside interface and allow intra-zone traffic, is that a good sulotion that will work?My other idea would be to create a firewall policy, that allows traffic coming from the outside interface, going into the loopback. Allowing remote VPN address as source.If so, is it enough to allow IKE traffic on this rule, or do we need ESP aswell?Thanks you!
Hi folks, I noticed in some general testing of the web filtering that childrens games are not filtered - only " non-children" games are. Such examples of this would be Barbie, Disney, etc. Do any of you know a workaround to filter for all games? Thanks a bunch, Mark
Hi,A few months ago we acquired a new customer that we have to manageTheir current Forti EMS version is 6.4.7I have read the necessary articles regarding upgrading from version 6.4.7 to 7.4.0It is a challenge to upgrade de EMS server, and all clients(workstations and servers) to version 7.0.11, then 7.2.4 and then 7.4.0.Wouldn't it be more convenient in this case to install/configure a new EMS 7.4.0 server?Then uninstall the old client and install the new clients.I am not (yet) familiar with the EMS tooling, so I do not know what the (im)possibilities are.And what about the license for temporarily having 2 EMS servers?I look forward to receiving advice.RegardsSteve
I want to check the IP address of the sender so that it is not blocked by the policy of the security device up to the proxy server.The following settings are included in order to use a proxy server when updating signatures or renewing licenses.At this time, which source IP address should be used for packets originating from Fortigate?Is it the Mgmt port? Or is it an interface for data communication close to the proxy server?config system autoupdate tunnelingset status enableset address “10.**. **. **” ⇒ IP address of the proxy serverset port 8080
Hi,We are trying to implement a monitoring solution for our firewall that indicates which ISP link is currently being used.The firewall is connected to a single router provided by the ISP and there are 3 links connected to the router. Which link though, adversities a different BGP community information which is the way we know what is the current internet link being used.To do so, I currently connect to our firewall and then run the command:get router info bgp community-info or;get router info bgp network 0.0.0.0Both tells me the community like below:# get router info bgp community-infAddress Refcnt Community[0x555be4ac] (1300) 65507:1001Now, I was looking for a way to implement an automated to query this information and report when the community information changes.My monitoring system supports SNMP and REST API, but I don't know what OID or API call to use.Would able to provide this information please? Appreciate your feedbacks. TIA :)
Myntra , refund money you should immediately contact Myntra's customer support: O-972-573-0058 and (available 24/7) report …
To Refund money from Ph0nepe for a wrong transaction, you should (immediately) contact customer support:081- 278√O2 259 (&) (available 24x7)call me..
Issue Description- A single launcher in FortiPAM can utilize multiple ports simultaneously- This launcher does not accept any additional parameters during executionConfiguration QuestionWhen a single executable (e.g., A.exe) needs to use multiple TCP/IP ports simultaneously (such as ports 2002 and 2007), how should the launcher and template be properly configured in Technical ContextThis scenario involves:One launcher executable file (A.exe)Multiple TCP/IP ports (2002, 2007)No parameter input functionalityNeed for proper FortiPAM configuration settingsPlease provide guidance on the correct configuration approach for this multi-port launcher scenario in FortiPAM.
Hello Expert,I enabled two factor authentication on my remote ssl vpn configuration (firmwave 7.2.9 build 1688 (mature) When I simulate test with a user gmail account, i am not receiving and activation code . I humble request some help with this issue. Thank you Regards Please attachment for user setup and errors message gather from FortiGate logs
I've added LDAP server under User's and Authentication it says connected when I am trying to add external connection "Poll Active Directory Server" My added LDAP do not show up, although it says connected screenshot:
GreetingsI got this scenario where on the Headquarter office i got, 1 internet service, 1 MPLS p2p link to Data Center and 1 satellite link for DRS. Through the MPLS, I also route Internet access using the internet service on the Data Center. All this link are member of a SD-WAN zone. I create 2 IPSec VPN using the main internet service and the DRS internet to reach the Data Center in case that my MPLS link fail. The VPN link are also member in the SD-WAN zone. On the Data Center I got direct routing to AWS and HQ can reach AWS through the MPLS link and the 2 VPNs. On my first lab I use static route between HQ and DC and everything works fine. I got fail over to Internet working perfectly and the traffic going to AWS fail over between MPLS and VPN just fine, Almost 0% packet lost (Lab environment).Then i try using OSPF between HQ and DC using the MPLS and the 2 VPN link. Reachability works fine, OSPF neighborship are all up/full. But when I try fail over to DC, wh
I'm having an odd issue with Application Control (Blocking Spotify) on an outgoing client policy on 6.2. Wondering if anyone would have any insight to what I may be missing? The application control profile has Spotify added as an override with Block as the action. When I check the logs and filter Spotify it appears with pass as the action. I've confirmed through these records that it is the correct policy which has the profile with the override in it that is being applied to that traffic. Is there anything else in the app control profile that needs to be done other than adding the override block in order for that to work? Screenshots linked below. Thanks. https://www.dropbox.com/s/nomrodlithgsvnf/spotify1.PNG?dl=0https://www.dropbox.com/s/1mlqf5g15kddmgi/spotify2.PNG?dl=0https://www.dropbox.com/s/d0s0arkt5e4qeod/spotify3.PNG?dl=0https://www.dropbox.com/s/hjgz9ml98ipzerb/spotify4.PNG?dl=0
I wonder in what order the configuration is restored in the HA cluster. From what I found in the documentation "When restoring the configuration of a cluster, cluster unity reboot to install the new configuration. This may result in a brief traffic interruption as all cluster units map restart at the same time." Is it true that both nodes can restart at the same time, or is there a gradual: first on the master, then on the slave, or in reverse?
hello I have created a Virtual IP to map to an inside private IP Addressthe Virtual IP is spare IP address from the RIPE subnet allocated x.x.x.84 --I have configured a security rule to allow traffic to this IPthere are no matches in the packet capture & I cannot see the .84 in the arp address of the vdomQ has anyone come across this issue before ?
When trying to connect to FortiClient on Windows 11, we get the following error: "SSL VPN Connection is Down" We have tried connecting on all of our work PC which are Windows 11 but as soon as we click connect, it pops up this message. Testing it on non-work PC's and other non work computers, it connects just fine. Why is this even an issue with Windows 11? Get it together Fortinet.....fix this. This should not be happening, warning sslvpn CSslvpnAgent::InitPipeHandle() 137 CreateFile() failed.. LastError=231error sslvpn Failed to connect to SslvpnDaemon, LastError=0error sslvpn CSslvpnAgent::Initialize() 178 InitPipeHandle() failed.error sslvpn date=2024-11-03 time=18:35:31 logver=1 id=96603 type=securityevent subtype=sslvpn eventtype=error level=error uid=9382745410D24560B69384D310C7323C devid=FCT8003581394472
Hello, I just want to ask if it is possible to override Fortimanager sdwan template. Network connection changed and I have to change healt-check IP for one device. In device group is multiple devices so I have to make change only for one device. If it is not possible what is the best way to deal with this situation ? Thank you RegardsPeter
Hi,I am trying to use API call to configure the HA on FortiGate VM on OCI cloud with following payload and getting error. Looks like current API does not either recognize "hadev" field value or expecting in certain format. I have tried using "hbdev": "\"port4\" 50" or "hbdev": "port4 50" or "hbdev": " port4" but nothing worked. Also error message output showing "No permisson to change HA setting" , I wonder if this API doesnt work with access_token?I also tried to use Ansible module "“fortios_system_ha” on https://galaxy.ansible.com/fortinet/fortiosbut it also gives almost the same issue related to "hvdev". Has anyone encounter this issue or any suggestions? following is code excerpt:api_url = "https://192.13.154.13/api/v2/cmdb/system/ha/?access_token=fj7pwG93nxz6xxxxxxxx"data_api = {"group-id": 30,"group-name": "ha-cluster","mode": "a-p","hbdev": "port4 50","session-pickup": "enable","sessi
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.