Mark a Best Answer
Fortinet Community
Recently active
Dear All, We have recently transitioned to a VLAN segmentation configuration from our previous flat VLAN design. FortiGate 201F is in Version 7.2.10.Currently, we have printers located in VLAN 20 and users in VLAN 40. Our network architecture consists of an Internet connection leading to a FortiGate firewall, which then connects to a switch that serves both printers and user PCs. Detailed information:We have an inter-VLAN policy that permits all services between VLAN 20 and VLAN 40, and no security profiles are applied. While devices in these VLANs can successfully ping each other and users can print without issues. The Issue we facing,We are encountering a problem with scanning documents from the printer to the PC using SMB. The strange thing is we don't see any logs at all. We tested within the same VLAN, where both the printer and PC are located within the same VLAN, shows that scanning functions correctly without routing through the FortiGate. Does an
If you have a source that explains every section in the policies and objects section, please share it with me. The fortinet source should not be shared as the source. I comprehend, but I don't understand.
Hello,How is it possible that I enable this:Enabled Based on Policy DestinationAnd I still get the IP of the office and not my home WIFI?gameie_Primary # config vdomgameie_Primary (vdom) # edit rootcurrent vf=root:0gameie_Primary (root) # config vpn ssl web portalgameie_Primary (portal) # edit "vpn-rnd"gameie_Primary (vpn-rnd) # showconfig vpn ssl web portaledit "vpn-rnd"set tunnel-mode enableset ip-pools "vpn-rnd-new"nextendgameie_Primary (vpn-rnd) # show full-configurationconfig vpn ssl web portaledit "vpn-rnd"set tunnel-mode enableset ipv6-tunnel-mode disableset web-mode disableset allow-user-access web ftp smb sftp telnet ssh vnc rdp pingset limit-user-logins disableset forticlient-download enableset ip-mode rangeset auto-connect disableset keep-alive disableset save-password disableset ip-pools "vpn-rnd-new"set split-tunneling enableset split-tunneling-routing-negate disableset dns-server1 0.0.0.0set dns-server2 0.0.0.0set dns-suffix ''set wins-server1 0.0.0.0set wins-server2 0.0.
HelloHas anyone tried integrate FreeIPA with FSSO, like by sending syslog from the LDAP to FSSO agent or FortiAuthenticator, or any other method?
Hi,i have these firewall in a test setup (for production) and each has a basic setup.Internal LAN with DHCP, two WAN interfaces, a SD-WAN setup, a single firewall rule for internet traffic.A simple 0.0.0.0/0.0.0.0 static route using SD-WAN and a IP Pool address.IP Pool address 172.17.5.1 with overload and ARP enabled. If i do this on a FG 80F with 7.2.9 i am able to ping this IP from CLI.ICMP is sent from root interface FortiGate-80F # diagnose sniffer packet any 'host 172.17.5.1' 4 filters=[host 172.17.5.1] 13.410881 root out 172.17.5.1 -> 172.17.5.1: icmp: echo request 13.410891 root in 172.17.5.1 -> 172.17.5.1: icmp: echo request How would i solve this in a 120G with 7.2.9 FortiGate-120G # diagnose sniffer packet any 'host 172.17.5.1' 4 filters=[host 172.17.5.1] 2.693988 port2 out 85.132.211.22 -> 172.17.5.1: icmp: echo request 3.694028 port2 out 85.132.211.22 -> 172.17.5.1: icmp: echo request Both, 120G
Hello,I try to configure SAML SSO for WiFi SSID over Captive Portal with Azure AD as IdP.after connecting to the SSID I'm manage to get pup up browser with Azure Login page, after login I received in my Firefox web browser the message "Firewall Authentication Failed" I'm using follow article:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-SAML-SSO-for-WiFi-SSID-over-Captive/ta-p/216020/ What I'm doing wrong ? Please advice. Thanks!
Hi Team, I am applying Secure communication between FortiManger and FortiGate. The certificates are good and tested properly. Here are the errors and debugs: FortiManager: 2024-10-28 22:07:06 { "client": "dmserver:907", "id": 30, "method": "exec", "params": [{ "data": { "device": 164, "force": 0, "sn": "FGT70FTK220----9", "sn list": []}, "target start": 3, "url": "start\/tunnel"}], "root": "fgfm"}2024-10-28 22:07:06 FGFMs(FGT70FTK220----9-164-172.16.1.1): server:send:2024-10-28 22:07:06 put authuser=adminpasswd=****** 2024-10-28 22:07:06 FGFMs(FGT70FTK220----9-164-172.16.1.1): server:2024-10-28 22:07:06 reply 501request=auth 2024-10-28 22:07:06 Response:2024-10-28 22:07:06 { "id": 30, "result": [{ "status": { "code": 2, "message": "no permission"}, "url": "start\/tunnel"}]}2024-10-28 22:07:06 Response [unknown]:2024-10-28 22:07:06 { "id": 30, "result": [{ "status": { "code": 2, "message": "no permission"}, "url": "start\/tunnel"}]}2024-10-28 22:07:06 Request:2
Hi i want to know that how can i configure url redirection mean for example if my any client open in we browser www.continentalbisucits.com so he should redirect to www.continentalbisucits.com.pk i have configured Dns server in fortinet but its not working any suggestion what should i do?
Hi Guys, i am have a hard time with looking up specific logs for network events. recently we had few minutes of ISP outage, i can see that in the bandwidth widget (graph showed 0 mbps) but i can't see it in logs. i need something more than a widget screenshot to take it up with our ISP provider. same issue with VPN logs. i can't see clear logs for why user got disconnected, is it drop in internet connection at my end or user's internet? user disconnected? among other such logsis there any way to see this information?thanks,Taimur
it is possible with my u231f access point to use the lan1 and lan2 port in aggregate mode. and take advantage of 2 gbits of bandwidth?? what do I have to do on the Access point side and what do I have to do on the fortiswitch side to do this???
Dear, Is there an option to configure Web Filter Profile and Video Filter so it cannot be always on for BYOD or off fabric devices ? I want to be enabled only while the user is connected to VPN.
Dear all,I'm following the guide in order to setup for the first time the FortiClient EMS with my existing architecture ( FortiGate + FortiAuth). In the docs (https://docs.fortinet.com/document/fortigate/7.2.5/ztna-deployment/374384/connect-the-fortigate-to-ems) is telling that: 1- I need to generate a cert. By i do have already EMS Server Certificates (FortiCare). Do i need to generate again using a third party such as godaddy since i do not have an CA ? Or this are the defaults one ? 2- How i can publish in the DMZ the FortiEMS ? Thank You in advance#FortiClientEMS
Hello, I have a problem with simple setup i think it could be a limitation of evaluation license but i wanted to confirm it. Goal was to monitor and add some polices to home network with forti in Vm Network Setup and Topology Forti 7.4.5 • ISP Router: This is the primary internet gateway provided by the ISP, operating on its own subnet with DHCP enabled. The ISP router is connected to an ASUS Access Point.i can’t change config of this device • ASUS Access Point (AP): Connected to the ISP router, the ASUS AP has local network (LAN) on subnet 192.168.50.0/24. It broadcasts Wi-Fi for local devices and is directly connected via Ethernet to a machine with VMware server • FortiGate Firewall (VM): Running as a virtual machine on the server, FortiGate is configured with port1 as the primary interface, acting as both LAN and WAN within the 192.168.50.0/24 subnet. It has the IP address 192.168.50.10 and provides DHCP services, assigning itself as the default gateway fo
We have a site localcounciljobs.gov.uk When going through the web profile for the LAN it doesn't work.When we attempt this on the guest web profile it works. I have allowed this through the web filter - added to custom categories (even though its not a blocked site through the rating anyway) if we access localcounciljobs.co.uk (which is the same site) it works fineBut we need this gov site accessible The error is net::ERR_CERT_AUTHORITY_INVALIDand we cannot advance - it just reloads the page. Any ideas what im missing here?works fine OFF the web profile Thanks
In principal, who should be in charge of PKI infrastructure / CA server? The customer, the MSSP, or some third party providing PKI as a service?The customer (1000 employees) has an IT department, and has until now managed their own CA server for issuing client certificates used for client VPN and WiFi authentication. As part of downscaling their IT department, they're planning to get rid of their CA server. They want WiFi with EAP-TLS authentication delivered by our company, but they don't want to handle the PKI infrastructure themselves.Should we as an MSSP provide PKI as a service to the customer, or should we tell the customer to get PKI as a service from a third party? We are currently testing FortiAuthenticator, but as far as I can tell, FAC cannot be used as a CA server in a multi-tenant environment. There are PKIaaS providers online that could be used, but we currently don't have the resources to handle PKI for customers, even if utilizing PKIaaS on the customer's behalf.Does an
HI, I am planning to move my FortiGate SSL VPN to an external DHCP Server and have the following plan using a loopback interface following the FortiGate document link below. I am unsure if my plan will work and if I have the correct Firewall Policies etc, does it look good? https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-external-DHCP-Server/ta-p/215644
Hello I would like to know how does the FortiNDR VM respond after it detects malware ? Can the FortiNDR clean the malware files on its own ? or it just detects the malware Thank You
Let me start by saying I'm not the network guy, I'm more of the endpoint guy. But I'm also kind of the security guy (IT department is, well... lean). With that being said, on more than one occasion now, I've noticed that we were exposing things we shouldn't via Shodan. We own a block of public IP's. One was the login page to a critical internal service. Another was a recursive DNS server and port 53. The former was an accidental misconfiguration that I brought up and was fixed (looking at the logs it was getting hammered with brute force attempts, as you would expect). The latter, the network guy just didn't know it wasn't a good idea. I don't pretend to know everything, so I'm just hoping for a reality check on what we still have exposed across multiple public IP's. We have a FortiGate. We have VPN setup. It requires MFA. I believe it's L2TP with IPsec. Ports 1701 UDP and 179 are exposed across multiple public IP's that we are using. On Shodan, for 1701, it says so
Hi, I am trying to configure SD-WAN but not sure why I am getting a disabled status on the SD-WAN zones as below: Interface: virtual-wan-linkLink: *greyed arrow pointing down* (disabled)Type: SD-WAN Zone Interface: TestLink: *greyed arrow pointing down* (disabled)Type: SD-WAN ZoneMembers:wanport_1 (green icon)wanport_2 (red icon) Any reason why this is happening? How do I enable the sdwan zone? Thanks!
Hi I'm looking how to obtain the current/updates to the AP model numbers in for Fortiplanner lite v2.6.5 build 0403? thankjfk
Recentemente estou sofrendo com usuário conectado no EMS estando dentro do setor, dessa forma utilizando uma licença e atrapalhando o fluxo de licenças, fiz a trativa de bloquear a conexão ems desses usuários. Porem não foi uma tratativa prática visto que sempre que o colaborador for trabalhar remoto irei ter que realizar a liberação, a alguma forma de aplicar uma configuração para não permitir que o EMS seja inicializado junto do sistema operacional ou bloquear a conexão do EMS dentro da Rede interna?
After updating to FortiMail v7.6.1 the quarantine email behavior has changed. When clicking on the "release" icon, it use to just release it. This was convenient since I could long press in Apple Mail and have it realize. Now it asks " Are you sure you want to release this quarantined message?" which then takes me to Safari to confirm. How can we disable this useless confirmation?
We expanded a subnet at a remote site and traffic from our main site to addresses in the new part of the remote subnet does not work. I have the correct subnet mask on the routes and on the IPSec VPN tunnel. I see the traffic in Forward Traffic being accepted and destined for the VPN interface, but if I do a traceroute the next hop after our firewall is 10.10.10.1 which is not on any network, route, or interface that we have at any site. Traceroutes from a workstation show the firewall as the first hop and 10.10.10.1 as the second. Traceroutes from the firewall show that address as the first hop. I'm sure more info is needed, please let me know what I can provide.
Some weird behavior I saw today. I'm doing NAT for two VLANs on a branch FGT with two VPN tunnels, so four VIPs in total. Two VIPs for the primary tunnel and two for the backup tunnel. In noticed that only the VIPs that reference the backup tunnel have a hit count (which has always been down so far). I attached a screenshot of that: Only when I reference the backup VIP in a policy, ping to the VIP works, even though it clearly uses a tunnel that isn't even up! How can that be? When I use the primary VIP in the policy, ping doesn't work bc of implicit deny.In grouped both IPsec interfaces shown here into a zone, maybe that has something to do with that?
Hello,I have a question about kerberos authentication. Seeing this doc:https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-explicit-proxy-authentication-with/ta-p/206219 Why do I need the kerberos authentcation? I mean what would be the difference if I do not configure the kerberos part and I do configure the rest (LDAP,groups, and add group to proxy policy)?If I do not configure the kerberos part I would still have the active authentication (autentication windows popup on browser) the a user tries to go to internet,right?I do not the benefit added with kerberos. Is it to just add SSO like authentication (passive authentication) ??I am new to kerberos protocol... thank you in advance.Regars!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.