Your feedback drives change, make your voice count
Fortinet Community
Recently active
● Prerequisites・ FortiOS version: v7.6.7・ Inspection mode: Flow-based・ SSL inspection: certificate-inspection・ Browser: Google Chrome, (Firefox), (Microsoft Edge)・ Client certificate installed on the endpoint ● IssueWhen accessing a site categorized for "Block" or "Warning" actions, the FortiGate is expected to display replacement messages;however, a browser error (ERR_SSL_PROTOCOL_ERROR, or occasionally ERR_CONNECTION_RESET) appears instead of the replacement message.Switching the inspection mode to proxy-based resolves the issue, and replacement messages are displayed correctly.Note that this issue occurs on some endpoints but not others. ● Troubleshooting results・ Endpoints experiencing the issue produced the same results when inspected via a different FortiGate.・ Changing the FortiOS version (to 7.6.6 or 7.4.12) yielded the same results.・ Updating the browser to the latest version yielded the same results. ● QuestionBased on the troubleshooting results, I suspect the issue lies wit
I setup 1VM (FMG V8.0.0) and FW(V8.0.0) and trying to onboard fortigate firewall to manager but getting below error , is there any bug or do i need to make further changes in the configuration considering both VM Mgt subnet are in same subnet. Error “The FortiManager's access to the FortiGate will be authenticated by the FortiManager certificate. The serial number from the certificate must match the serial number observed on the FortiManager.Could not connect to the FortiManager to retrieve its serial number.”
Hi, how do you set up a VXLAN when you have two locations? We're using FortiSwitches at both locations, and VLANs are also in use there.But we now have another location, and I'd like to know if it's possible to set up a VXLAN using the FortiLink VLAN as well?
Hi all,I am looking for FAZ resources which cover real world use cases or lab based scenario, I have checked on YouTube but not much available, checked their Fortinet Video Lib as well, I would appreciate you recommend some resources, thanksNote : I am focusing on FAZ, FSM
vpn ssl stop working but internet is reachable,my topology is a sdwan connection to internet from two wan sub interfaces joined as sdwan members into a sdwan-zone, we are using the fortigate lower models and firmware are 7.4.0 and 7.2.4, internet connection are asymmetric, home-residential massive internet. SLA health check is active but ramdonly after a couple of days internet connection is up but vpn ssl sub interface is down, no echo-ping goes back and sniffer also doesn´t show anything, only remote solution is to reset port and after that sub interface goes up again. Following current sdwan config edit 3 set interface "subinterface-primary-vpn" set zone "sdwan-to-remote-hub" next edit 4 set interface "subinterface-backup-vpn" set zone "sdwan-to-remote-hub" next... edit "vpn-health-check" set server <remote-looback-ip> set interval 1000 set failtime 10 set recoverytime 10 set source <local-lan-ip-all
I try to send CoA to the endpoint but we can see from below picture the CoA is failed, and from tcpdump there is no traffic to port 1700. Also in the cisco switch i already enable CoA debug but not receive any message. This mean the fortinac not send the CoA message?
Hi everyone,I have the topology below using Fortigate HA Active -Active Cluster Everything works normally until SW1 (the current STP root) is rebooted or powered off.After SW1 comes back (or after the topology reconverges), the topology does not recover correctly. One or more FortiSwitches may randomly become Offline, even though the physical links are up.The only workaround is to disable and enable FortiLink Split Interface, after which all FortiSwitches immediately come back online and the topology is rebuilt correctly.FortiOS 7.6.7 / FortiSwitchOS 8.0.0
We have 2 internet connections terminated to our firewall with spare IPs, and SD-WAN is already configured outbound for load-balance/failover.We have a specific outbound service (SMTP) that we want to attach to a dedicated outbound IP address.Setting an outbound NAT policy with an IP Pool was easy enough, and that's working, but we only have it setup for one of the internet connections at the moment.How can we set this up with a dedicated outbound IP for each internet connection and have it failover if the main internet connection goes offline? (active/passive)
Hi everyone,I'm looking for the FortiAnalyzer 7.2.11 JSON-RPC API documentation. Does anyone have a copy or know where I can find the complete documentation?I'm currently integrating FortiAnalyzer with an external system and need information on the available JSON-RPC methods and objects.Any documentation, examples, or links would be greatly appreciated.Thanks in advance!
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
Hi everyone,I'm trying to integrate FortiWLC 8.6-5 build-8 (FortiWLC-500D) with Aruba ClearPass Guest (ClearPass Policy Manager 6.12.7.308288 on C3010 platform) as an external captive portal.Current setupFortiWLC 8.6-5 build-8 External captive portal: Aruba ClearPass Guest Authentication type: RADIUS Captive Portal External Server Type: Fortinet-Presence External URL: https://<clearpass fqdn>/guest/guest_register_3.phpThe captive portal profile is configured as:Authentication Type: radiusCaptive Portal External Server Type: Fortinet-PresenceSuccess Redirect URL: https://<default redirect url>Login flowClient connects to SSID.FortiWLC redirects the client to the ClearPass Guest portal.The login page receives all FortiWLC parameters correctly, including:magicusermacuseripserveripapmacapidapnodeidssidpost=https://<controllerip>:8081/vpn/loginUser? User enters username/password.ClearPass successfully authenticates the user against the authentication source.After successf
Hello team, I have interesting situation. there are 4xFg900G in cluster. there is FTP server in vlan 100.L3 DG address for that vlan 100 is on Fortigate.When secondary 900G FGs from cluster want to reach ftp they can not.We also have cluster of 4xFG 400F for additional services, and they can all reach ftp server , no matter primary or one of 3 secondary FGs How to solve this situation?My final aim is to upgrade one of secondary FGs regarding MVC (Multi-version cluster) option, set upgrade-mode local-only, and upgrade one of secondaries and then reset ha uptime so that upgraded one become primary. Reason for that is because we must not have any downtime, and we want to take test after upgrade if all services are ok
Had multiple issues when adding a FortiGate using discover device. It always said device serial number does not match Only once I updated to 7.4.11 did it finally add First post here and its the end of my day so I’ll add more later, just don’t want someone to lose an entire day to this like I did.
hi,i’d like to setup a remote syslog server to collect NAT 5 tuple logs (source/dest IP, source/dest port and service/app).i have a multi VDOM FGT and would like to setup syslog server config in a non root/MGMT VDOM.my VDOM setup is i have an upstream ‘internet-gw’ VDOM and several downstream ‘nat-client’ VDOMs.goal is to setup syslog in ‘internet-gw’ VDOM and ‘nat-client-a’, ‘nat-client’b’ VDOM to send NAT log that’s filtered based on 5 tuple info.can someone advise on this? my google search only points to non VDOM FGT syslog and i already configured/enabled syslog in ‘global’ VDOM.
Hi Community, As per title “How to get Fortinet higher up to review related TAC Manager ticket”In ticket (11996986), we had factually proven the issue and the TAC Manager do acknowledge on it.Suddenly the TAC Manager (Jonathan) twist the fact on what discussed.Luckily we had video call recorded. How can we further submit to Fortinet higher up to review this TAC Manager whether these action is being approved? Thank You Best Regards,YK
After correct configuration ddns for DynDNS (not Forti-DDNS) is there any CLI-command to check the status for this service ? My firmware version = 5.0.1.
Dear All, Anybody can explain in laymon term what is under lay and over lay in SDWAN concept and how does it work. Why under lay and over lay need. Thank you in advanced for sharing the knowledge.
For FortiEdge Cloud, how do you assign different user accounts to have access to different networks?I believe this used to be accomplished using the Multi Tenancy license and sub accounts, correct?Since this can’t be ordered anymore and is going away, how do you do it using the new organization method?
Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.Am I missing something in t
Private by Design: Security That Comes to Your Data, Not the Other Way Around Most cloud security tools that inspect your workloads and your data have a dependency baked into their architecture: to analyze your information, they first make a copy of it in their cloud. Disk snapshots get exported to the vendor's account. Objects from your storage buckets are copied out and classified somewhere else. This works, but it means the most sensitive data you own now lives in two places instead of one, and the second place is outside your control.That tradeoff is exactly what FortiCNAPP was built to avoid. Two of our major product capabilities, Agentless Workload Scanning and Data Security Posture Management (DSPM), are Private by Design. The scanner comes to your data; your data never comes to the scanner. Analysis happens inside your own cloud account, and only the results ever leave. What "Private by Design" MeansPrivate by Design is a simple architectural commitment:Scanning runs inside you
Previously, with FortiClient version 7.2.13, when users initiated the VPN connection using SSO, FortiClient automatically detected the existing sign-in sessions for the customer's corporate accounts. When the authentication window was displayed, the available accounts were presented for selection, allowing users to authenticate without re-entering their credentials.However, after upgrading FortiClient to version 7.4.3, this behavior has changed. When using FortiClient's embedded browser for SSO authentication, users are always prompted to enter their username and password. The embedded browser no longer detects existing Microsoft Entra ID (Azure) sessions or displays the available signed-in accounts.On the other hand, we have verified that when FortiClient is configured to use an external browser for SSO authentication, the expected behavior is observed. The external browser correctly detects the existing Microsoft Entra ID (Azure) sessions, displays the available corporate accounts,
Dear Community, We have this case where we want to configure two different IP Addresses as destination for our fortigate to be monitored as part of our link health monitoring. Our Cariteria is like this:First Destination is the next hop ISP IP AddressSecond Destination is our Server on the Internet Now we want the link to monitor both IP Addresses and if any of these two IP Addresses are not reachable then the link should be detected as down. Can anyone help me how to do this one.I have also read this on the internet can you all confirm if this is true?Someone suggested using the OR logic and configure two separate SDWAN performance SLA one for each Destination Server and if an interface participates in multiple Performance SLA (health-check) probes, it's only considered "up" if it passes ALL of them. So failing even one the interface marked down = SD-WAN swings traffic to the Backup. This is exactly the OR-failure logic you want. Best Regards,Shah.
We recently started investigating roaming behaviour on a customer environment using FortiAPs with WPA3-Enterprise and an external RADIUS server.The initial observation was that roaming did not appear to behave like a Fast Transition (802.11r) roam. During movement between access points, clients seemed to perform a complete authentication process again instead of using a fast handoff. This resulted in noticeable delays compared to what we would normally expect from an 802.11r-enabled deployment.To validate this, we captured both beacon frames and association traffic on the customer environment. In the captures, we noticed that clients were performing normal WPA3-Enterprise authentication exchanges after roaming. When we examined the beacon frames more closely, we found that the WPA3-Enterprise SSID advertised only the standard WPA3 Enterprise AKM. We could not find any indication of FT over IEEE 802.1X or a Mobility Domain (Tag 54) element.To rule out environmental factors, we rebuilt t
Hello, Trying to understand what happened and how to prevent it in the future: - Running FortiGate-VM in an Azure VM.- This FG has a custom site-to-site IPSec tunnel to on-prem. This effectively connects the virtual data centre to the on-premises data centre. Tunnel is initiated from Azure.- Suddenly, the tunnel no longer works. Phase 2 will not go up.- The first sign of trouble is this: Unavailable : Live Migration (Unplanned)At Thursday, October 13, 2022 at 7:29:19 PM EDT, the Azure monitoring system received the following information regarding your Virtual machine:This virtual machine was paused for 0.675000 seconds due to a memory-preserving Live Migration operation. No additional action is required from you at this time. Recommended StepsNo action is required - A couple of minutes after this, alerts start going off that connectivity has been lost.- After some trouble shooting, pinging, checking routes, connectivity, rebooting, firmware upgrade,
Hello, installation of FortiClient VPN ends in an error "FortiClient VPN Wizard ended prematurely because of an error." I am running Windows 11 home on my new surface 11 pro. I executed Installation .exe as Administrator, i disabled Windows Defender temporarily. Any further ideas?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.