Mark a Best Answer
Fortinet Community
Recently active
We have FortiManager 7.6.7 and two FortiGates running FortiOS 7.4.11.Under Security Profiles > SSL/SSH Inspection, we have an object named “SSL-EXCEPT” with set cert-probe-failure allow, and this profile is used in several firewall policies.In FortiManager, the same object also has allow configured. However, whenever we make any change in FortiManager, it applies unset cert-probe-failure, which is preventing us from managing changes on these FortiGates through FortiManager.How can we fix this?
We are currently facing an issue with log forwarding between our FortiGate 1100E and FortiAnalyzer device. The FortiGate is configured to send logs to the FortiAnalyzer; however, we are experiencing issues with the logs not being received/displayed correctly on the FortiAnalyzer. Issue details: FortiGate Model: 1100E FortiAnalyzer Model: FortiAnalyzer-150G We have already verified the basic connectivity between the FortiGate and FortiAnalyzer and confirmed that the logging configuration is in place. However, the issue is still occurring. FG11E-PPCL-DC-ACT $ diagnose debug application fgtlogd 255Debug messages will be on for 18 minutes.FG11E-PPCL-DC-ACT $ diagnose debug application miglogd 255Debug messages will be on for 18 minutes.FG11E-PPCL-DC-ACT $ diagnose debug application oftpd 8 10.61.9.1command parse error before 'oftpd'Command fail. Return code -61FG11E-PPCL-DC-ACT $ diagnose sniffer migsock filter name=global-fazFG11E-PPCL-DC-ACT $ diagnose sniffer migsock ssl-trace enabl
Hello Fortinet Community,I have a customer requirement regarding remote access VPN connectivity.My understanding is that FortiGate supports both SSL VPN and IPsec VPN for client-to-site connections. However, I have also seen recommendations to move away from SSL VPN in newer releases, and I am planning to deploy this solution on FortiOS 7.6.The customer's requirement is very specific: they want to ensure that only one concurrent VPN session is allowed per user account. For example, if a user connects through FortiClient using their username and password, a second person should not be able to use the same credentials simultaneously from another PC and establish another VPN session.Is this behavior supported natively by FortiGate/FortiClient? If so:Is there a specific setting to limit concurrent logins per user? Does it work for both IPsec and SSL VPN? Are there any best practices or recommended approaches to enforce this requirement?I would appreciate any guidance or configuration recom
We have become aware of the following security advisories regarding a vulnerability in FortiClient:https://fortiguard.fortinet.com/psirt/FG-IR-26-156https://advisories.ncsc.nl/2026/ncsc-2026-0296.htmlWithin our organization, we exclusively use FortiClient VPN-only for Windows. We do not use the full FortiClient client or FortiClient EMS.Therefore, we would like to know whether the vulnerability described in FG-IR-26-156 also affects the FortiClient VPN-only client.Additionally, we would appreciate clarification on the following:* Is FortiClient VPN-only affected by this vulnerability?* If so, which versions are affected?* Which version does Fortinet recommend installing to address the vulnerability?* Is an updated version of FortiClient VPN-only currently available?* Does the VPN-only client update automatically, or do we need to manually deploy the updated version to all our laptops?We would appreciate your clarification so that we can take the appropriate measures if necessary.Kind r
Hello,i am running Forticlient 7.4.3 on Ubuntu. Sometimes my client works, then when i shut down my laptop and turn it back on i keep getting this error. No restart can help in any ways. Some time passes (it generally feels random: sometimes it's like 5 mins, sometimes more than one hour passes by and the problem persists.Then suddenly i manage to log in my vpn again...Any suggestions on what to do?I have this script that i run often after i restart my computer: this helps me out altering my connections and enabling the DNS again, because it seems the forticlient enters some DNS in my wifi connections, so i need to remove these entries:#!/bin/bash # List current running connections and allow user to select one using fzf connection_drop_name=$(nmcli c show --active | awk 'NR>1 {print $1}' | fzf --prompt="Select a connection to drop: ") # Check if a connection was selected if [ -z "$connection_drop_name" ]; then echo "No connection selected. Exiting." # exit 1 fi # Bring down th
So umm my college has blacklisted quite a few websites and apps so as to promote productivity and a studious environment. They are using fortinet for this task.Unfortunately this also includes steam, epic games and even the riot client. I cannot access any of them and cant play any games on my dorm wifi. I was hoping to gain help for bypassing this even if its just for steam epic and riot. I can always use my mobile data connection to access the other websites but playing valorant on mobile data hotspot leads to ridiculously high ping in the neighborhood of like 150-250 ms. Can anyone help with this??keep in mind I am not an expert or even well versed in networking so please treat me like your parents when trying to explain how things work or how to go about trying to bypass this.
Hi everyone, I'm Sarah, just joined this community. We've been running a site-to-site VPN on FortiGate and occasionally notice intermittent drops, especially during peak traffic hours. Has anyone tuned specific settings (dead peer detection, keepalive intervals) to make tunnels more stable? Would appreciate any troubleshooting tips before opening a support ticket.
Hello Community,I am configuring an IPsec VPN for remote users on FortiGate 7.2.13 and would like to use DDNS (Dynamic DNS) instead of a static public IP address.Has anyone successfully deployed this configuration? I would appreciate guidance on.
Good morning, everyone.I'm having an issue configuring FortiClient on Linux.My company uses VPN through the IPsec protocol. So far, I have tested it on different Linux distributions, including Linux Mint, Zorin OS, and Fedora.I'm using the official package provided by Fortinet. However, after installing and launching FortiClient, the option to configure an IPsec VPN simply does not appear in the interface.At first, I thought it might be an issue related to the graphical interface or a specific Linux distribution, but I tested it on three different distributions and the same behavior continues.I also tried importing the XML configuration file for the VPN. FortiClient reports that the import was successful, but the configuration is not actually loaded. If I try importing it again, the same thing happens, creating a loop where the VPN profile is never created or displayed.Has anyone experienced this issue with FortiClient on Linux while using an IPsec VPN?If anyone can share their experie
Hey everyone,I am now a Junior Network Engineer, and my company recently advised me to gain the Fortinet NSE 4: FortiOS Certification. As such, I have been preparing to take the Fortinet NSE 4 - FortiOS 7.6 Administrator exam.Like many newcomers, I began my preparation with the book, starting with the official Fortinet documentation and study guide. Although everything made sense from the theoretical point of view, there were certain difficulties in applying these concepts in practice. It is one thing to know what is supposed to happen to your network feature, and quite another to be able to fix it when something goes wrong.I faced certain obstacles in the form of a lack of practical knowledge on how to troubleshoot certain problems described in the documentation. Therefore, I had to change my approach to learning. In order to find solutions to practical issues, I began looking for FortiOS 7.6 Administrator questions and scenarios on the web. I also started digging into scenario-based
I need to deploy a FortiGate cluster A-P in different location each FW. It will be an Active-Passive cluster. The WAN interface IP (ISP) ranges provided by the ISPs will differ at each site. So NATs, routes, WAN interfaces are differents. The plan is to set up the A-P cluster and then manage the units using FortiManager. What would be the best way to do this? Site A - FGT1 PrimarySite B FGT2 SecondaryI'm thinking about the potential issues with setting up the cluster first, applying the configuration, and then migrating it to FMG. Any ideas or recommendations?
I have always worked in a Cisco shop and I am new to Fortinet. I do not know what this is. Do I need this? I did not ask for it. It just showed up on my quote.
Hi!Next week I'll have to update 2 Fortigate to the 7.6.7 version.The system is in HA and the cluster is " in sync " status ( Primary / Secondary )how can I upgrade it in the best way to avoid downtimes ? what things should i verify before upgrade ?Thanks
as i have done the sdwan configuration for the redundency purpose and i am unable to access the internet through the wan 2 so help me
I have set up a site to site VPN on the fortigate 90G with 4 selectors. On the other end is a Cisco ASA device. After all configurations are done and I try to bring up the VPN, the tunnel is coming up but only one selector out of the 4 phase 2 are coming up. I have 2 servers on the local side and there are two servers on the remote side. Each device on my local network is supposed to talk to the each device on the remote side. I have tried to use named addresses, grouped addresses, and the actual IP addresses for the selectors but I’m still getting the same result. I also tried to set the initiator-ts to enabled but this also seems to not help. What seems to be happening is that tunnel is only bringing up the first match of the selector and ignoring the rest leaving them in a down state. I would really appreciate any assistance. It’s been giving a headache for a few days now and I can’t get it to work as it should. I would also like to point out that I do not have access to the cisco d
I am able to connect IPsec remote VPN on my laptop. When I try with my own mobile hotspot I am able to connect but Internet is not working.VPN is working fine on another mobile hotspot.Already troubleshooted steps:Disabled IPv6 address from mobile, in laptop Wi-Fi adapter and VPN adapter Changing MTU value 1500, ,1380, 1280, 1300, 1420 still issue happens From my mobile hotspot changed Maximum compatibility on and off both still same Try 5 different network and connect VPN, working fine only issue with single mobile hotspot Change forti-client different versions, re-configure VPN but issue is still the same
I am fail to assign FortiToken. I already check DNS settings and license but no findings. Is there any thing wrong currently on FortiCloud?
After successfully log in via web. The browser gets redirected to login screen and it keep doing this forever. When asked for a license i chose evaluation license and fill the Form with my Fortinet account. Different commands gives me different outputs, i.e get system status shows:FGxxxxx # get system statusVersion: FortiGate-VM64-KVM v8.0.0,build0167,260420 (GA.F)First GA patch build date: 260420Current Security Level: HighFirmware Signature: certifiedVirus-DB: 1.00001(2026-04-02 13:48)Extended DB: 1.00001(2026-04-02 13:48)Extreme DB: 1.00001(2026-04-02 13:48)OCR DB: 0.00000(2001-01-01 00:00)AV AI/ML Model: 0.00000(2001-01-01 00:00)IPS-DB: 6.00741(2015-12-01 02:30)IPS-ETDB: 6.00741(2015-12-01 02:30)IPS-MLDB: 0.00000(2001-01-01 00:00)APP-DB: 6.00741(2015-12-01 02:30)AIAP-DB: 0.00000(2001-01-01 00:00)Proxy-IPS-DB: 6.00741(2015-12-01 02:30)Proxy-IPS-ETDB: 6.00741(2015-12-01 02:30)Proxy-APP-DB: 6.00741(2015-12-01 02:30)Proxy-AIAP-DB: 0.00000(2001-01-01 00:00)FMWP-DB: 0.00000(2001-01-01 00
Hello,We are testing a FortiGate-VM trial setup, but the GUI still logs out immediately after login.We have already verified the following: GUI certificate is set correctly. Admin idle timeout has been increased. https is enabled on the management interface. NTP time sync is correct. httpsd process is running normally. We also tested: different browser, incognito mode, cleared cache and cookies, login from the correct trusted host / source IP. Even after all of the above, the GUI still kicks us out after login, while SSH access remains stable.Has anyone seen this behavior on FortiGate-VM trial or evaluation mode? Is there any other VM-specific GUI setting or known issue we should check?Thank you.
Hi,I am experiencing a FortiToken Mobile activation failure on Android 16 with FortiToken Mobile 6.5.0.0030.The error shown during activation is: "Invalid server certificate - FortiToken Mobile cannot validate the server certificate."I found an older Fortinet Community discussion describing a very similar problem after upgrading to Android 13:FortiToken Mobile cert error on Android 13https://community.fortinet.com/support-forum-92/fortitoken-mobile-cert-error-on-android-13-115185In that thread, the original poster later reported: "Fortinet support said this is bug 765700."Fortinet also documented bug 765700 in the FortiToken Mobile Android 5.2.3 release notes:FTM Android 5.2.3 Known issueshttps://docs.fortinet.com/document/fortitoken/5.2.3/ftm-android-5-2-3-release-notes/999611/known-issuesBug 765700 is described there as: "'Untrusted Certificate' popup throws when activating/completing token transferring or approving/denying Login Requests"Fortinet later listed bug 765700 in the FTM A
Hi, I want to make ipip and gre tunnel to mikrotik. on mikrotik side mtu 1420 is set for ipip and 1400 for gre.I have fortios 7.6.7 and can not set mtu on ipip and gre interface directly. how can i do that?
We have a strange scenario popping up in the lab for the new EDR deployments we were consulted to explore.Everything works normally except for when a USB dock is or SD card reader as it immediately crashes the computerRebooting the with the dock plugged in will trigger a Bitlocker recovery screenReboot without the dock and the computer comes up normallyRemoving EDR and leaving EMS resolves the issue, but the computer is unprotected by compliance standardsI suspect the card readers showing up as empty unwritable disks with a mounted drive letter is part of the problem, but not sure how to tell EDR to calm down about it.The crash:Your PC has run into a problemStop code: System_Thread_Exception_Not_Handled (0x7eE)What failed: partmgr.sysHas anyone seen an issue like this before?
Setting up an IPSec VPN Tunnel between a Fortigate 90g and another device. On the Fortigate, I setup the tunnel, settings are good.Setup the firewall policies, I see the created network names (local_subnet_1 and remote_subnet_2) that the Fortigate creates.When I go to Static Routes, I cannot select, nor can I even see, the remote_subnet_2 as a selection when I set Destination to Named Address.I CAN see names of other remote networks named with the creation of previous tunnels. Previous tunnels setup, uses the named network, without issue. Does the Fortigate create the name automatically? and If so, why isn’t this one showing up in the list? I can manually add the subnet, but for consistency in setup with the other tunnels on the device (2), I’d like to use the same method.
Hi,Looking for a guide to deploy Forticlient VPN with Intune for MacOS,Did anyone succeed? I haven't found an official guide for this
Not working FortiClient 7.4.6.0218 android 17 with fortios 7.6.7 =( When update in google play store? PC/Mac works good
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.