Mark a Best Answer
Fortinet Community
Recently active
Recentemente estou sofrendo com usuário conectado no EMS estando dentro do setor, dessa forma utilizando uma licença e atrapalhando o fluxo de licenças, fiz a trativa de bloquear a conexão ems desses usuários. Porem não foi uma tratativa prática visto que sempre que o colaborador for trabalhar remoto irei ter que realizar a liberação, a alguma forma de aplicar uma configuração para não permitir que o EMS seja inicializado junto do sistema operacional ou bloquear a conexão do EMS dentro da Rede interna?
After updating to FortiMail v7.6.1 the quarantine email behavior has changed. When clicking on the "release" icon, it use to just release it. This was convenient since I could long press in Apple Mail and have it realize. Now it asks " Are you sure you want to release this quarantined message?" which then takes me to Safari to confirm. How can we disable this useless confirmation?
We expanded a subnet at a remote site and traffic from our main site to addresses in the new part of the remote subnet does not work. I have the correct subnet mask on the routes and on the IPSec VPN tunnel. I see the traffic in Forward Traffic being accepted and destined for the VPN interface, but if I do a traceroute the next hop after our firewall is 10.10.10.1 which is not on any network, route, or interface that we have at any site. Traceroutes from a workstation show the firewall as the first hop and 10.10.10.1 as the second. Traceroutes from the firewall show that address as the first hop. I'm sure more info is needed, please let me know what I can provide.
Some weird behavior I saw today. I'm doing NAT for two VLANs on a branch FGT with two VPN tunnels, so four VIPs in total. Two VIPs for the primary tunnel and two for the backup tunnel. In noticed that only the VIPs that reference the backup tunnel have a hit count (which has always been down so far). I attached a screenshot of that: Only when I reference the backup VIP in a policy, ping to the VIP works, even though it clearly uses a tunnel that isn't even up! How can that be? When I use the primary VIP in the policy, ping doesn't work bc of implicit deny.In grouped both IPsec interfaces shown here into a zone, maybe that has something to do with that?
Hello,I have a question about kerberos authentication. Seeing this doc:https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-explicit-proxy-authentication-with/ta-p/206219 Why do I need the kerberos authentcation? I mean what would be the difference if I do not configure the kerberos part and I do configure the rest (LDAP,groups, and add group to proxy policy)?If I do not configure the kerberos part I would still have the active authentication (autentication windows popup on browser) the a user tries to go to internet,right?I do not the benefit added with kerberos. Is it to just add SSO like authentication (passive authentication) ??I am new to kerberos protocol... thank you in advance.Regars!
Ive been trying at this for awhile and cant wrap my head around the problem. Im trying to go from ssl vpn to vlan100Fortigate sees vlan100 in the routing table. It has a firewall policy allowing it. yet the policy match tool and debug shows it going to the implicit deny policy What else am I missing?
Hi, I’m new on Fortigate. I create a new Application Control security profile to block multimedia (video, youtube, Netflix, Spotify, etc.) and I want to apply It to one of my Explicit Proxy Policy. I want to block that’s programs if some of that client were installed on my user’s desktop.When I edit Explicit Proxy Policy and choose my new application control I get a an error in GUI, but if I choose the default application control it’s apply ok and save ok. Any idea, why? Thanks.
Hi All, Managed to get outbound firewall authentication using Entra ID as SAML IdP to work. My issue is this. I do not want to stay installing the Fortigate CA SSL cert on each endpoint that needs internet access, as instructed in the Fortigate's how-to site. Was wondering if I could use Let's Encrypt SSL cert for this? Anyone know the way forward, or perhaps managed to get it working like this? I already tried using a Let's Encrypt cert pointing to my public IP in FGT and configured this in my EntraID config, but doesn't work. At a certain point, the local computer gets re-directed to the local internal IP address of the fortigate and seems to ignore the FQDN configured in EntraID and in FGT SP. Any ideas? Much appreciated.
Cisco IP phone is in unregistered state after calling. Checked the forward traffic logs all the packets are accepted by firewall. what is the possible cause of IP phone getting unregistered after calls.
Our firewall (FortiGate-500E v7.0.14, build0601) is currently experiencing issues with upgrading to newer firmware versions. There are two options available: versions 7.2.7 and 7.2.8. However, the release notes for version 7.2.7 indicate a bug affecting IPsec tunnels, while version 7.2.8 has a known issue with routing and SD-WAN How should I determine the most suitable version for the upgrade?known issues: 7.2.7 -->> https://docs.fortinet.com/document/fortigate/7.2.7/fortios-release-notes/236526/known-issues known issues: 7.2.8 --> https://docs.fortinet.com/document/fortigate/7.2.8/fortios-release-notes/236526/known-issues
I'm trying to install FortiGate in gns3 on Ubuntu (physical machine) but showing this error, please help
For more than a decade, digital transformation has been the talk within businesses. One of the core elements in this journey is the migration to the public cloud, which adopts new ways of thinking and working the infrastructure and applications. This journey centers on automating infrastructure and application provisioning, rapidly detecting and responding in operations, containerizing applications, and leveraging serverless technology or other services from cloud providers for rapid prototyping, innovation, and adoption. Executives prioritize this initiative to expedite the pace of innovation, save on capital costs and time to set up infrastructure and realize new ways of delivering services. In the urgency to be part of the wave, some companies rush to adopt an “all-in” approach too quickly without sufficient due diligence. This presents a risk of failure, beyond a technical point of view which is the financial viewpoint. One of the elements that customers must realize is that they n
QuestionHow is it possible to export packages from FortiManager FortiGuard in a format that they can then be imported into FortiGate manually (using the: "execute restore <av | ips>" tftp command)? BackgroundIt is possible to apply AV and IPS packages to a FortiGate by downloading the current packages from FortiCloud and then applying them using the "execute restore <av | ips> tftp commands.It is also possible to downgrade a FortiGate to a previous AV or IPS package by contacting the TAC and requesting a previous version. TAC will provide the previous package. Before using the execute restore command, you must apply: "diagnose autoupdate downgrade enable". Then, use the "execute restore ..." command to tftp the TAC provided package to the FortiGate. See article: Technical-Tip-How-to-downgrade-or-rollback-IPS-engine FortiManager FortiGuard ServiceFortiManager FortiGuard downloads packages from Fortinet (FDN) and decompresses the package components and then ins
We are using Forticlient EMS 7.2.4 and Forticlient 7.2.4 on Windows 10 22 H2 Enterprise. Our web filter rules have a mix of Simple, Wildcard and RegEx based rules. Reading the documentation here it not clear to me how the match is performed. It states it matches against a URL and strictly speaking a URL has 10 parts as per https://www.w3.org/Addressing/URL/url-spec.txt. So is the entire URL considered for each matching type ? For example consider this URL:- https://example.com/path?name=Branch&products=[Highs,Lows,Journeys,Email,Universal%20Ad - Would a simple match for H match https://example.com/path?name=Branch&products=[Highs,Lows,Journeys,Email,Universal%20Ad- Would a wildcard match for p*a match the https://example.com/path?name=Branch&products=[Highs,Lows,Journeys,Email,Universal%20Ad
Hi. FortiClient VPN that I use at work keeps crashing/freezing my computer, forcing me to hold down the power button and restart. If I click SAML Login to connect to the VPN via FortiClient GUI, it will work for 3-4 minutes before my whole system freezes. When i'm back in the PC doesn't recognize any networks (even though I use an ethernet cable), and I'll have to manually delete all connections before I restart again and everything works like normal.I get no error logs. I am using Ubuntu 24.04 LTS, even though FortiNet doesn't officially support this. The workaround: remove two dependencies (libappindicator1 and libayatana-appindicator1) in the .deb when installing using apt. My FortiClient VPN version is 7.4.0.1636. Any ideas/solutions? Thanks in advance :)
To a Virtual Server is it possible in Load balancing method selecting "HTTP Host" and "Round Robin" at the same time?As it is now with "HTTP Host" it looks like it uses Static with the 2 Real Servers.
Hi everyone, I was reading proxy based and flow based inspection. When i read the proxy based inspection mechanism it explains that the Fortigate deeply inspect the packet and flow based just check the pattern and packet is not decrypted in both cases unless we choose the SSL decryption profile.Now if the packet is not decrypted then in that case the only thing that can be checked is the certificate or packet headers or may be some initial TCP packets. In this case, what is the purpose of having two different mechanism proxy based and flow based if only thing you can check is headers and content is all encrypted ? even the antivirus cant check all the attachments because every packet is encrypted ? so how does this work ?
Hello All,In Fotigate firewall, can someone guide how can we allow a specific full/exact URL as below only,https://code.ionicframework.com/ionicons/2.0.1/css/ionicons.min.cssThanks,
My company was testing out FortiClient and we installed it on a bunch of workstations, not knowing we only needed the free version for VPN. Obviously found this out when we started getting the unlicensed prompt. We uninstalled that version and installed the free version. It's been a few weeks now and we seem to have a few workstations that seem to be reverting back to the unlicensed as the users keep getting that prompt? Does anyone know what's going on or experienced this one? We have installed, again, the licensed one on these workstations and installed the free version, and it happened again. Not happening to all the workstations, just a few. Any help is appreciated. Thanks,JT
Hello Guys, I find something weird in my fortimanager but there is no user "admin" in my fortimanager, anyone have ever faced this before?
I want to turn off Lockdown ISL on Fortigate firewall, but it automatically turns back on. How can I turn it off?I found this in the Fortigate library, but I didn't have much success.https://docs.fortinet.com/document/fortiswitch/7.2.6/fortilink-guide/173260/configuring-fortilink
Estimados, tengo una política de navegación que esta aplicando una inspección ssl "certificate-inspection" con el metodo "inspeccion de certificados ssl" y en el navegador de un cliente que esta bajo esta politica me sale el siguiente error al abrir un enlace de unidad .google.com "Fortinet" no se ha instalado correctamente en tu ordenador o red. Póngase en contacto con el administrador de TI para resolver el problema. net::ERR_CERT_AUTHORITY_INVALID Asunto: *.google.comEmisor: FG200FT920905021Fecha de caducidad: 30 de diciembre de 2024Fecha actual: 29 de octubre de 2024como solución me indica que instale directamente el certificado en la máquina, lo cual ya realiza, pero sigue el mismo evento.Que mas podria realizar para solucionar este inconveniente
dears,i need to do implementation of forti authenticator and that is my first time to do it i need some help and advices to do Implementation scop1- Install Forti authenticator at VM or share the OVA file to configure it 2- Apply license 3- Migrate the current token FortiGate license to the authenticator4- Integration with LDAP5- Apply token to access Linux, Ubuntu Windows server, and Windows 10&11 system VMs 6- Access switches SSH using the token7- Apply 802.1x at switches using the token 8- Push token notification on mobile to approve 9- Others during the implementation
Dear,Following the guide (https://docs.fortinet.com/document/forticlient/7.4.0/ems-administration-guide/701440/configuring-a-profile-to-allow-or-block-endpoint-from-vpn-tunnel-connection-based-on-the-applied-security-posture-tag) i'm trying to create rules in order to block for i.e:endpoint with critical vulnerabilities to connect vpn. But in my console i do not have the option like showing in the link: Link console: My console:
Hello I hope someone can help. We have set up application control and web control to block tik tok on 30E ( 6.2.10 firmware). After setup all looked ok ( around half a year ago) . Now it is not working properly. When you try to access tik tok from Imac safari , it blocks it , but on the phone and ipad App and safari open tik tok. We made sure that 4G is off on devices and only WiFi is on. Now have tested problem in my office ( thou here we have Fortigate 40F, 7.0.5 firmware) , but if all is set up earlier, there is no problem. But if you turn off the application control and turn it on if you have safari on ( even without tik tok on) tik tok works . Even thou application control logs show tik tok was blocked. . Same problem with application. Similar issue is with coming off the 4G and getting only to wifi , if you had app on it keeps working.Tried to block IP’s but tik tok uses local ranges , and if you block
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.