Mark a Best Answer
Fortinet Community
Recently active
Hi all, I have a setup with Fortiauthenticator (v6.6.0) and Fortigate 401F (v7.2.9), where FAC is fed by an openLDAP, and I use remote user sync rules to add users to groups created of FAC. The thing is, I have several groups created on FAC, however the users can only connect to VPN if they are in a specific group (regardless of which group they belong on openLDAP). I don't have any filters on the FAC policy.This happens with, and without token.I know that the problem is not related with the password. Logs of the user connecting succefuly: ESEnfC-1 # [3592:root:1c23e]allocSSLConn:310 sconn 0x7f201b4e7000 (0:root) [3592:root:1c23e]SSL state:before SSL initialization (*.*.*.*) [3592:root:1c23e]SSL state:fatal decode error (*.*.*.*) [3592:root:1c23e]SSL state:error:(null)(*.*.*.*) [3592:root:1c23e]SSL_accept failed, 1:unexpected eof while reading [3592:root:1c23e]Destroy sconn 0x7f201b4e7000, connSize=1. (root) [3593:root:1c23e]allocSSLConn:310 sconn 0x7f201b4e780
I'm finding mixed opinions on this searching online, so I thought I would ask here for advice.I have a FMG recently upgraded from firmware 7.0.13 to v7.2.8. Circumstance forces me to add a new device to the FMG running on FortiOS 7.2 but I can't upgrade the other managed Fortigates to 7.2 at this time. I can't import the policy packages from this new FGT because the ADOM is still on v7.0.So my question: can I safely upgrade the ADOM to 7.2 so I can manage this new FGT now and revisit upgrading the other gates to FortiOS 7.2 when I get the OK from the powers that be?
I am studying for the NSE5 FMG exam. In the Guide when the FMG-Access protocol is disabled on the Fortigate device, Fortimanager does not manage the device.In the enterprise, the device, even with FMG-ACCESS disabled, is still managed in Fortimanager. Can someone explain to me why even with the FMG-Access protocol disabled it is managed in Fortimanager.
I purchased a 100F firewall and three 248E-FPOE switches.How can I connect the devices together giving 2Gbits of bandwidth to each switch.I can aggregate the ports but how can I separate three FortiLink interfaces for the three switches. ??I'm missing this step. Why does it seem to me that the FortiLink interface is always and only one?? Or am I misunderstanding something??
Fortigate60E (v7.4.5)There are 9 FortiAPs (v6.4.0 v7.4.4 mixed) hanging.Currently, the SSID settings are set as follows and restricted by Mac address. config wireless-controller vapedit "AAAA"set ssid "XXXXX"set intra-vap-privacy enableset schedule "always"set address-group "WiFi_Allow_Mac"set address-group-policy allownextend WiFi_Allow_Mac There are many Mac addresses registered in the address group.Recently, there have been more than 256 cases, but there has been an event that causes an error in the Wi-Fi connection. Action: client-denialMessage: Client cc:d9:ac:xx:xx:xx denied (denied 4 times in one second).STA denied on WTP due to VAP ACL If you remove a few devices from the address group and reduce the number of devices, the connection will be successful.Are there any restrictions that are not mentioned in the specification?
My setup is that of your traditional legacy WAN hub (data center) and spoke (branch sites). Currently, my only Internet access is at my data center. Even though they are on private WAN connections, the branch locations' connection to the WAN is via FortiGate (for traffic inspection purposes away from the data center). I am in the process of adding Internet connectivity to each of these branch sites (will also add secondary Internet connectivity at the data center as well in the near future). I have a fair grasp of what needs to be done and following the hub/spoke guidelines in the SD-WAN Branch Deployment Guide documentation; however, what I am missing is process/procedures or caveats in migrating an existing used interface over to a new zone. So what I mean is, if I have my existing interface in a WAN zone and policies are applied to that zone, will I be able to easily move that interface to the new SD-WAN zone? I know I cannot do anything with the interface while it references s
Hello, I have consulted Fortinet's documentation and upgrading the Fortimanager seems straightforward.What are the recommendations and important points to check when upgrading the forti analyzer ( before and after)? Thanks
our user have several email adress that are aliases of the same inbox. but on the fortimail box theses aliases are seen as different account as the fortimail has no clue that it s the same person who use these different adress.but when the quarantine report is sent there s no clue about which adress is concerned by the report.i wouldl ike to modify the template to include the adress but i don't any variable concerning the email. does someone know if they exist one?
Hi, I want to connect to my Fortigate using its hostname via SSH with PuTTY. However, the documentation only mentions establishing a session via IP address and whenever I try to connect by writing the hostname in the Hostname (or IP address) field, it gives me the error host does not exist. Session is established successfully without any errors if I use the the MGMT port's IP address instead.
Hi,I'm still learning my way around Fortinet products. My FortiAP-231G intermittently goes offline. It has happened 3 times now. The first 2 times I left it (I had to go away) and it came back. This time it went offline on Friday and has yet to come back. I have found and run diagnose wireless-controller wlac -c wtp and can see the last failure : 10 -- Wait Join timer expired. Not sure what this means or how to fix it. The power light goes from solid amber to flashing amber. It have tried restarting the AP but no good. Any help is greatly appreciated. My set up: Fortigate 40F (v7.4.5 build2702 (Mature)), FortiSwitch 108F-POE (v7.4.2 build0801), FortiAP-231G (v7.4.3 build068). Fortigate and FortiSwitch are connected via Fortilink Below is the full out of the diagnose command: -------------------------------WTP 1----------------------------WTP vd : root, 0-FP231GTF23035041 MP00uuid : 2f582606-e4e5-51ee-94bb-c83fee894696mgmt_vlanid : 0region code :
Hello, the content on the fortigate management interface doesn't load because fortinet's cdn certificate seems to have expired.For example the browser doesn't load the content at https://fos-cdn.fortinet.com/artifacts/fos/7.2.10/b1706/3655.js, if I try to open the url directly in the browser I see that the domain SSL expired one Oct 30thAnd the cert Is indeed expired
Hi,I've set the Data Policy for my root ADOM to 120 days for Analytic logs. All my Fortigates are in that ADOM. However, when I view the logs, there are only logs available for the last 61 days. It never exceeds 61 days plus a few hours, even though the ADOM root has 40 % of unused storage. The analytic / archive ratio is set to 75 / 25. Do you know what I'm doing wrong? I'd expect it to fill the storage until it's full or the data policy is met but it doesn't do any of that.I also tried rebuilding the SQL DB. It seemed to be working at first, since logs for analytics reached 61 and 20 hours but after 00:00, it reset itself to 61 days and 0 hours. After the rebuild it freed up some space and ADOM root now even has 55 % of unused storage but is stil not logging according to the policy. Thanks in advance
My issue is that if I have 2 dialup tunnels on a remote gate, each dialup is connected to a seperate ISP, if I lose the primary ISP that is connected to dialup tunnel 1 and dialup tunnel 2 (seperate ISP) picks up the routing, then some routes are discovered on the correct dialup interface, but others show as being discovered via the wan interface.I am not sure what the problem is. See below:  This is in a test environment. The gates are on 7.2.8 Remote Gateconfig vpn ipsec phase1-interfaceedit "advpn_1"set interface "wan1"set peertype anyset net-device disableset proposal aes256-sha256set add-route disableset auto-discovery-receiver enableset remote-gw x.x.x.xnextend config vpn ipsec phase2-interfaceedit "advpn_1_p2"set phase1name "advpn_1"set proposal aes256-sha256set auto-negotiate enablenextend config vpn ipsec phase1-interfaceedit "advpn_2"set interface "wan2"set peertype anyset net-device disableset proposal aes256-sha256set add-route disableset auto
Hello, I am currently attempting a deployment for new Windows 11 PCs; these machines are equipped with Sierra Wireless EM7511 WWAN cards / modems using AT&T physical SIMs. Our deployment requires a split tunnel, using both Netmotion NetMobility Client and Forticlient VPN simultaneously. Over the past weeks we have had nothing but issues, both Windows 11 and Windows 10 based machines (same physical hardware) BSOD / BugCheck a short time after connecting via FortiClient. Initially we were concerned that this could be a Sierra Wireless issue, so as a temporary solution we tested USB modems. These modems perform well until the machines are connected to Forticlient; Once connected within 30s - 5 minutes the USB modem will restart / disconnect albeit no BSOD. This behavior is repeatable and occurs only when Forticlient is connected regardless if NetMobility is connected or disabled. It appears that for some reason when Forticlient is active it causes modems, whether USB or inte
Hi,When SSL-decrypted HTTPS traffic is sent to a mirror port and analyzed using Wireshark on a server connectedto that port, unusual packet patterns are observed. wan port IP : 1.235.10.153destination IP : 54.84.14.5source IP : 172.30.0.162 It seems like there is wrong with hand shake process, and when I monitor this traffic with Zeek, either the request body or the response body always shows 0. Is there something wrong with my FortiGate configurations, or is this expected situation for mirrored traffic?I need your assist. Thanks.
Im using Fortigate 50E with Firmware FortiOS 6.2.16.FortiOS 6.2 is EOS but Fortigate 50E still supported until 2027 march, what's the reccomendation, should i upgrade my hardware? or it's secure enough?
We are starting to role out Aruba 6300s and are having issues with NAC integration. Currently a switch/port is configured as follows. vlan 50 tagged voice vlan 100 data vlan 210 IOT then each access port will configured as followsint x/x/xvlan trunk allowed 50,100 This works PC and Voice are connected. Now when we enforce this port and connected a rogue PC to that phone. That port configuration is changed from trunk to access and the vlan changes to our isolation vlan. This kills the tagged trunk voice vlan on this port needing us to then reconfig the port manually. This also happens when say I connected a IOT device the NAC changes the vlan but will change the port to 'access' which then kills the tagged trunk voice vlan. What is the fix for this on Aruba Switches? I have read FortiNAC cant manage trunk ports and to use access only, but Aruba switch's require trunk port when allowing more than one vlan on port.&nb
Dear All, We have recently transitioned to a VLAN segmentation configuration from our previous flat VLAN design. FortiGate 201F is in Version 7.2.10.Currently, we have printers located in VLAN 20 and users in VLAN 40. Our network architecture consists of an Internet connection leading to a FortiGate firewall, which then connects to a switch that serves both printers and user PCs. Detailed information:We have an inter-VLAN policy that permits all services between VLAN 20 and VLAN 40, and no security profiles are applied. While devices in these VLANs can successfully ping each other and users can print without issues. The Issue we facing,We are encountering a problem with scanning documents from the printer to the PC using SMB. The strange thing is we don't see any logs at all. We tested within the same VLAN, where both the printer and PC are located within the same VLAN, shows that scanning functions correctly without routing through the FortiGate. Does an
If you have a source that explains every section in the policies and objects section, please share it with me. The fortinet source should not be shared as the source. I comprehend, but I don't understand.
Hello,How is it possible that I enable this:Enabled Based on Policy DestinationAnd I still get the IP of the office and not my home WIFI?gameie_Primary # config vdomgameie_Primary (vdom) # edit rootcurrent vf=root:0gameie_Primary (root) # config vpn ssl web portalgameie_Primary (portal) # edit "vpn-rnd"gameie_Primary (vpn-rnd) # showconfig vpn ssl web portaledit "vpn-rnd"set tunnel-mode enableset ip-pools "vpn-rnd-new"nextendgameie_Primary (vpn-rnd) # show full-configurationconfig vpn ssl web portaledit "vpn-rnd"set tunnel-mode enableset ipv6-tunnel-mode disableset web-mode disableset allow-user-access web ftp smb sftp telnet ssh vnc rdp pingset limit-user-logins disableset forticlient-download enableset ip-mode rangeset auto-connect disableset keep-alive disableset save-password disableset ip-pools "vpn-rnd-new"set split-tunneling enableset split-tunneling-routing-negate disableset dns-server1 0.0.0.0set dns-server2 0.0.0.0set dns-suffix ''set wins-server1 0.0.0.0set wins-server2 0.0.
HelloHas anyone tried integrate FreeIPA with FSSO, like by sending syslog from the LDAP to FSSO agent or FortiAuthenticator, or any other method?
Hi,i have these firewall in a test setup (for production) and each has a basic setup.Internal LAN with DHCP, two WAN interfaces, a SD-WAN setup, a single firewall rule for internet traffic.A simple 0.0.0.0/0.0.0.0 static route using SD-WAN and a IP Pool address.IP Pool address 172.17.5.1 with overload and ARP enabled. If i do this on a FG 80F with 7.2.9 i am able to ping this IP from CLI.ICMP is sent from root interface FortiGate-80F # diagnose sniffer packet any 'host 172.17.5.1' 4 filters=[host 172.17.5.1] 13.410881 root out 172.17.5.1 -> 172.17.5.1: icmp: echo request 13.410891 root in 172.17.5.1 -> 172.17.5.1: icmp: echo request How would i solve this in a 120G with 7.2.9 FortiGate-120G # diagnose sniffer packet any 'host 172.17.5.1' 4 filters=[host 172.17.5.1] 2.693988 port2 out 85.132.211.22 -> 172.17.5.1: icmp: echo request 3.694028 port2 out 85.132.211.22 -> 172.17.5.1: icmp: echo request Both, 120G
Hello,I try to configure SAML SSO for WiFi SSID over Captive Portal with Azure AD as IdP.after connecting to the SSID I'm manage to get pup up browser with Azure Login page, after login I received in my Firefox web browser the message "Firewall Authentication Failed" I'm using follow article:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-SAML-SSO-for-WiFi-SSID-over-Captive/ta-p/216020/ What I'm doing wrong ? Please advice. Thanks!
Hi Team, I am applying Secure communication between FortiManger and FortiGate. The certificates are good and tested properly. Here are the errors and debugs: FortiManager: 2024-10-28 22:07:06 { "client": "dmserver:907", "id": 30, "method": "exec", "params": [{ "data": { "device": 164, "force": 0, "sn": "FGT70FTK220----9", "sn list": []}, "target start": 3, "url": "start\/tunnel"}], "root": "fgfm"}2024-10-28 22:07:06 FGFMs(FGT70FTK220----9-164-172.16.1.1): server:send:2024-10-28 22:07:06 put authuser=adminpasswd=****** 2024-10-28 22:07:06 FGFMs(FGT70FTK220----9-164-172.16.1.1): server:2024-10-28 22:07:06 reply 501request=auth 2024-10-28 22:07:06 Response:2024-10-28 22:07:06 { "id": 30, "result": [{ "status": { "code": 2, "message": "no permission"}, "url": "start\/tunnel"}]}2024-10-28 22:07:06 Response [unknown]:2024-10-28 22:07:06 { "id": 30, "result": [{ "status": { "code": 2, "message": "no permission"}, "url": "start\/tunnel"}]}2024-10-28 22:07:06 Request:2
Hi i want to know that how can i configure url redirection mean for example if my any client open in we browser www.continentalbisucits.com so he should redirect to www.continentalbisucits.com.pk i have configured Dns server in fortinet but its not working any suggestion what should i do?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.