Mark a Best Answer
Fortinet Community
Recently active
Dear,Following the guide (https://docs.fortinet.com/document/forticlient/7.4.0/ems-administration-guide/701440/configuring-a-profile-to-allow-or-block-endpoint-from-vpn-tunnel-connection-based-on-the-applied-security-posture-tag) i'm trying to create rules in order to block for i.e:endpoint with critical vulnerabilities to connect vpn. But in my console i do not have the option like showing in the link: Link console: My console:
Hello I hope someone can help. We have set up application control and web control to block tik tok on 30E ( 6.2.10 firmware). After setup all looked ok ( around half a year ago) . Now it is not working properly. When you try to access tik tok from Imac safari , it blocks it , but on the phone and ipad App and safari open tik tok. We made sure that 4G is off on devices and only WiFi is on. Now have tested problem in my office ( thou here we have Fortigate 40F, 7.0.5 firmware) , but if all is set up earlier, there is no problem. But if you turn off the application control and turn it on if you have safari on ( even without tik tok on) tik tok works . Even thou application control logs show tik tok was blocked. . Same problem with application. Similar issue is with coming off the 4G and getting only to wifi , if you had app on it keeps working.Tried to block IP’s but tik tok uses local ranges , and if you block
If my proxy gateway is listening on port 9443 and the destination host is listening on 443, do I need to point my browser at https://example.com:9443 ? When I simply do https://example.com it doesn't work - I need to add 9443. I thought that FCT would append the 9443 to make it easier for the user... Thoughts ?
Same IP Address, same rule and same port, but why does it go through one and hang in the other?
Hi, I am looking to enhance our security measures and ensure we meet the necessary standards. In addition to FortiToken and FortiAuthenticator, I am exploring other methods, such as email-based MFA, that we can deploy. Could you please advise on the best approach to implement this? many thanks.
Hi all, I have an environment setup in GNS to learn about HA. I have the units bonded together and I can confirm that the HA is working as expected, if i drop a link, then the HA activates, and traffic passes over the other. And if i restore the link, and reset the uptime counter, traffic is restored. However, When its in HA mode, and i simulate the failure by removing the WAN link on the 'primary' unit, i cant access the UI at all using the MGMT ip (which i now expect to be the original 'passive' unit). until i restore the link i have broken, and revert the HA uptime timer using the CLI I have the interfaces so that port 5 is wan for each, connected to an upstream switch which is the wan.I have port 10 configured as my 'mgmt' interfaceand port 9 is the HA Heart beat cable and i can access the GUI normally under normal circumstances using port 10 on 192.168.100.41. however, when i remove the link, then this breaks, and i cant access it at all.
Dear Concern, Can I define multiple IP addresses under 'Syslog Logging' in the 'Log Settings' of FortiGate-201F firmware v7.4.4 build2662 (Feature)? . I need to send logs to both FortiAnalyzer and my SIEM (Log Rhythm). However, the GUI only shows an option to define a single IP address. I've attached a capture for your understanding. If it's not possible to define multiple IP addresses in the GUI, can I do it through the CLI? Waiting for your appreciable response.
We have four firewalls in our network. Two are core firewalls in HA, and another two are production firewalls in HA. As of now, the prodcution firewall acts like a hub. The core firewall is the DHCP IP release interface to the prdoction firewal. what im asking how can i use the production firewall to secure the network from external network? cctv or office network.please share you configurate details on the both the firewall
Hello From few days I'm in company where they build network on fortigate devices, before I work only with mikrotik solution, so i need to understand little bit the "fortios idea" So is good time becouse from saturday we notice strange sitauation. In this company they have two localization from one to second is some 25 kilometers, they have direct fiber connection between. This fiber cable are connected to Fortiswitch on site A port 51, on site B port 52.To both Fortiswitch to port1 is connected ISP also with SD-WAN configurationSite A, Fortiswitch Port1 IPS X1 (vlan_X1 -> Fortilink)Site B, Fortiswitch Port1 IPS X2 (vlan_X2 -> Fortilink) On fortigate devices the DMZ port is used for HB, so from both Fortigates DMZ port is connected to port 20 in both Fortiswitch. HA type is A-P, Also SD-WAN This is small picture how this looks with physical connection, and this issiue we have On saturday fiber between Site and Site was broken, SD-WAN showed on both f
Where can I found EOO, LSED, and EOS of fortigate 201F, fortigate 60F, and fortigate 201E? I just downloaded the list of hardware EOO from fortinet support, but i can't find this three on the list.
DearsI have fortiGate SSL and IPSEC RAVPN, i need to force user to change password.any guide please
hi,would it be possible or does it make sense to have a multi VDOM FG managed in FMG to be in separate ADOM?for example, the "core or critical" VDOM such as the "root" and "internet access" are added in the "root" ADOM, then the rest of the "customer" VDOMs would be provisioned/managed in a separate ADOM. we'll deploy an "internet access" VDOM deployment. refer to sample diagram/scenario.the root VDOM in the diagram will be our "internet access" VDOM, like an internet edge device. the rest of the customer VDOM will connect (vlink) to the root/internet access VDOM.
Please help me, FortiClient installation always tuck on Installing drivers state.I've been trying to installing FortiClient 5.6.0.1075, 6.4.10.1821 and 7.4.0.1658 and it always stuck on Installing drivers state and sometime on rollback I've using FCRemover.exe too and it the installation still stuck on Installing drivers
Hi, I have BGP neighbor that advertise me big network range (51.16.0.0/15) and I would to filter this range and get only smaller range from it (51.17.72.0/22); I want that all the rest of this range continue to go through the default route like as always.How can I do it? I tried with prefixlist but it not working because its not the specific range that advertise to me. This BGP neighbor can't split the bigger range that it advertise me and therefor I should filter it by my self. I have Fortigate 500E v 6.4.15. BR,Sefi
Hi,we have a colleague that wasn't able to connect to our VPN due to a unrequested route added by 7.4.0.1645 version of FortiVPN VPN-ONLY client. default via 192.168.1.254 dev en6 default via 192.168.1.254 dev en0 default dev utun13 scope link #this is wrong Could this be a bug or a misconfiguration? Regards,Dimitri
Hello,I can't connect via the Android or IOS APP to VPN with IPV6. No IPV6 support for mobile devices? How do you have the Dual-Stack option for the operating system?
May I know can i connect Fortinet Client VPN which laptop in Singapore but connect in China?How about remote dekstop?
hi,i received a new FG-1800F and saw there's 2x ha and 2x mgmt ports.my question is, can i just utilize/configure only one of these? i.e. use ha1 and mgmt1 onlyor is there a config guide/design to follow wherein i have to use both? seems it will use a lot of switch ports since we're using A/P HA.what are some common design/scenarios for using two ha and mgmt? # show system interface name Name.fortilink static 0.0.0.0 0.0.0.0 10.255.1.1 255.255.255.0 up disable aggregate disable ha1 static 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 up disable physical disable ha2 static 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 up disable physical disable l2t.root static 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 up
Hi All, I have a FortiSwitch which managed via a Fortigate controller. Does anyone know how to create an automate task to automatically shut a switch interface when a cable is disconnected and then only can be then enable again by an administrator? Thanks regardsJimmy
Hi everyone, Looking if there is any way to get Azure AD joined devices to authenticate with FSSO which we have installed in our on prem infrastructure. As we are education based we have different filtering policies for Staff and Students. We have explored the possibility of 802.1x over WiFi however some InTune joined devices will be using Ethernet so not the easiest to configure. Is there any easy way to authenticate with FSSO and/or directly authenticate from Azure to the Fortigate? We currently have multiple Fortigates but don’t have FortiAuthenticator or Forticlient.
This version of FMG was released last week and now CVE-2024-47575 is released as well.https://www.fortiguard.com/psirt/FG-IR-24-423However, the release notes doesn't have anything in the resolved issue section. Does this actually have the vulnerability fix in it?https://docs.fortinet.com/document/fortimanager/7.2.8/release-notes/972111/resolved-issuesToshi
When clients work remotely and connect VPN via FortiClient it takes too long to get the access to the shared drives after connecting with FortiClient, sometimes it takes more than 20 minutes show up the network drives. Any ideas?Thanks
I've been exploring ZTNA and for the most part I have it working as expected when off site with some test cases, accessing some web sites and RDP to a box or two. This is great but since we still use a VPN (And most likely always will use/have it for a while), I've noticed that when ZTNA routes are active on the client, pushed from EMS, I am unable to get to those resources when connected to the VPN. For example, I can ping the server but the RDP port in the ZTNA rule seems to prevent me from accessing it. I'm not sure if this is normal but since I know ZTNA is kind of a solution that should work both in and out of the network, I wasn't sure if anything is actually wrong and I just need to open firewall policies to allow the communication to work. My thought was to add rules to make the VPN connection treat the device on premise but that felt more like a trick than a solution, unless it is. Seeing what other people think about it and trying to get some thoughts on what would be so
Hello; Im planning to update an HA Active Passive.Does both Fortigate must be in the same OS? Or will it be possible to see if I have both on different OS and test the stability of one Fortigate update and later on give the other one the update? Or both must be executed the same day and they must be in the same FortiOS?
I have had two recent incidents where after installing the FortiClient VPN client, one on Windows and one on Ubuntu, where after entering the necessary IP address, port, username, and password the pop up window to accept the certificate never shows. Is there a way to get the cert from the Fortigate and manually install this or somehow force this pop up window to appear?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.